DTGBA: A stronger graph backdoor attack with dual triggers.
basic_science · Level V
Where this comes from
- Record sourced from PubMed, PMID 40561588.
- Also identified by DOI 10.1016/j.neunet.2025.107726.
- No licence information is recorded for this record.
- Because redistribution is not established, this page shows the abstract only. Follow the links below for the full text.
Abstract
Graph backdoor attacks can significantly degrade the performance of graph neural networks (GNNs). Specifically, during the training phase, graph backdoor attacks inject triggers and target class labels into poisoned nodes to create a backdoored GNN. During the testing phase, triggers are added to target nodes, causing them to be misclassified as the target class. However, existing graph backdoor attacks lack sufficient imperceptibility and can be easily resisted by random edge dropping-based defense, limiting their effectiveness. To address these issues, we propose Dual Triggers Graph Backdoor Attack (DTGBA). Initially, we deploy an imperceptible injected trigger generator and multiple discriminators, driving the imperceptibility of the injected triggers through adversarial game between them. Additionally, we introduce a feature mask learner to extract the high-impact and low-impact feature dimensions of the target class's nodes, and then create feature-based triggers by modifying the key feature dimensions of poisoned/target nodes, ensuring that the backdoor implantation can still be effective even if the injected triggers are removed by random edge dropping. Finally, we conduct extensive experiments to demonstrate that DTGBA achieves superior performance. Our code is available at https://github.com/SnowStone-DingLi/DTGBA-main.
Medical subject headings
- Neural Networks, Computer
- Computer Security