Key Substructure-Driven Backdoor Attacks on Graph Neural Networks
摘要
Backdoor attacks on GNNs aim to mislead the model by introducing patterns or triggers into the input graph, resulting in inaccurate predictions. Existing backdoor attacks have two main limitations: Firstly, they lack flexibility and effectiveness in associating predefined substructures with predicted labels, limiting their ability to influence the classifier. Secondly, the injection locations of these substructures lack stealth, failing to exploit vulnerabilities in the target system. To address the limitations, we present a novel approach with two core modules for targeting key substructures in backdoor attacks. The key substructure detection module identifies predictive relevant substructures in the input graph, explaining the model’s predictions and suggesting target aspects for accurate categorization. The graph alignment module transforms non-target class key substructures into attacker-chosen target class key substructures, modifying few critical edges and nodes. Our approach across real datasets spanning diverse domains highlights its efficiency. The proposed methodology establishes a pioneering direction for refining backdoor attack techniques on GNNs.