在文本图中藏隐蔽毒饵,让模型误判却难察觉。
Graph-Aware Stealthy Poison-Text Backdoors for Text-Attributed Graphs
- 选易改节点,用影子图模型生成伪装文本
- 攻击成功率高,跨模型迁移性强,抗防御
- 适合关注文本图安全的科研与工程人员
现代图学习系统常将边连接与文本结合,如带摘要的引用网络或含用户帖子的社交图。此类系统中,文本比图结构更易修改,带来实际安全风险:攻击者可在训练文本中隐藏微小恶意线索,后续触发错误预测。本文研究在仅修改节点文本、不改变图结构的现实场景下该风险。提出图感知后门攻击TAGBD:先选取易操控的训练节点,再通过影子图模型生成隐蔽毒饵文本,最后以替换或追加短语方式注入。在三个基准数据集上的实验表明,TAGBD实现极高攻击成功率,具备跨不同图模型的迁移能力,并在常见防御下仍有效。结果表明,看似无害的毒饵文本即可成为文本属性图中的可靠攻击通道,凸显需同时审查节点内容与图结构的必要性。
原文摘要 · Abstract (English)
Modern graph learning systems often combine links with text, as in citation networks with abstracts or social graphs with user posts. In such systems, text is usually easier to edit than graph structure, which creates a practical security risk: an attacker may hide a small malicious cue in training text and later use it to trigger incorrect predictions. This paper studies that risk in a realistic setting where the attacker edits only node text and leaves the graph unchanged. We propose \textbf{TAGBD}, a graph-aware backdoor attack that first selects training nodes that are easier to manipulate, then generates stealthy poison text with a shadow graph model, and finally injects the text by replacing the original content or appending a short phrase. Experiments on three benchmark datasets show that TAGBD achieves very high attack success rates, transfers across different graph models, and remains effective under common defenses. These results show that inconspicuous poison text alone can serve as a reliable attack channel in text-attributed graphs, highlighting the need for defenses that inspect both node content and graph structure.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。