Backdoor Attack on Dynamic Link Prediction
摘要
Based on historical information, graph prediction is performed by Dynamic Link Prediction (DLP). The quality of the training data plays a crucial role as it greatly impacts the prediction performance of most DLP methods, making them highly dependent on it. Backdoor attacks are used to manipulate DLP methods to cause incorrect predictions by the malicious training data, i.e., generating a trigger in the form of a subgraph sequence and embedding it into the training data. Nevertheless, the susceptibility of DLP to backdoor attacks remains unexplored. To tackle this issue, we introduce a new framework for backdoor attacks on DLP. More specifically, it employs a generative adversarial network (GAN) to generate a wide range of initial triggers. Next, the gradient information from the attack discriminator in the GAN is used to select partial links from the initial triggers, forming a trigger set. This process helps reduce the size of the triggers and enhances the concealment of the attack. Experimental results demonstrate that our method successfully launches backdoor attacks on several state-of-the-art DLP models, achieving a success rate exceeding 90%.