arXiv:2512.24665cs.LG2025-12

针对异构图的生成式后门攻击,让特定节点被错误分类。

HeteroHBA: A Generative Structure-Manipulating Backdoor Attack on Heterogeneous Graphs

  • 通过筛选关键邻居并生成多样触发特征与连接模式,实现精准攻击。
  • 攻击成功率显著高于现有方法,且对正常性能影响小。
  • 适合关注异构图安全性的研究人员和防御设计者。

异构图神经网络(HGNNs)在众多实际应用中表现优异,但针对异构图的目标后门投毒攻击研究仍较少。本文研究异构节点分类中的后门攻击:攻击者在训练阶段注入少量触发节点及连接,使特定受害节点在测试时被错误分类为目标标签,同时保持正常性能。提出HeteroHBA,一种生成式后门框架,通过基于显著性筛选选择有影响力的辅助邻居用于触发附着,并合成多样的触发特征与连接模式,以更好匹配局部异构上下文。为提升隐蔽性,结合自适应实例归一化(AdaIN)与最大均值差异(MMD)损失,使触发特征分布与良性数据对齐,降低可检测性;并通过双层优化目标,联合提升攻击成功率与保持干净准确率。在多个真实世界异构图上,使用代表性HGNN架构的实验表明,HeteroHBA持续优于现有后门基线,且对干净准确率影响相当或更小;此外,在异构性感知结构防御(CSD)下攻击仍有效。结果揭示了异构图学习中的实际后门风险,推动更强防御机制的发展。

原文摘要 · Abstract (English)

Heterogeneous graph neural networks (HGNNs) have achieved strong performance in many real-world applications, yet targeted backdoor poisoning on heterogeneous graphs remains less studied. We consider backdoor attacks for heterogeneous node classification, where an adversary injects a small set of trigger nodes and connections during training to force specific victim nodes to be misclassified into an attacker-chosen label at test time while preserving clean performance. We propose HeteroHBA, a generative backdoor framework that selects influential auxiliary neighbors for trigger attachment via saliency-based screening and synthesizes diverse trigger features and connection patterns to better match the local heterogeneous context. To improve stealthiness, we combine Adaptive Instance Normalization (AdaIN) with a Maximum Mean Discrepancy (MMD) loss to align the trigger feature distribution with benign statistics, thereby reducing detectability, and we optimize the attack with a bilevel objective that jointly promotes attack success and maintains clean accuracy. Experiments on multiple real-world heterogeneous graphs with representative HGNN architectures show that HeteroHBA consistently achieves higher attack success than prior backdoor baselines with comparable or smaller impact on clean accuracy; moreover, the attack remains effective under our heterogeneity-aware structural defense, CSD. These results highlight practical backdoor risks in heterogeneous graph learning and motivate the development of stronger defenses.

后门攻击异构图生成式安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。