Backdoor attacks in the traditional graph neural networks (GNNs) field are easily detectable due to the dilemma of confusing labels. To explore the backdoor vulnerability of GNNs and create a more stealthy backdoor attack method, a clean-label graph backdoor attack method(CGBA) in the node classification task is proposed in this paper. Differently from existing backdoor attack methods, CGBA requires neither modification of node labels nor graph structure. Specifically, to solve the problem of inconsistency between the contents and labels of the samples, CGBA selects poisoning samples in a specific target class and uses the label of sample as the target label (i.e., clean-label) after injecting triggers into the target samples. To guarantee the similarity of neighboring nodes, the raw features of the nodes are elaborately picked as triggers to further improve the concealment of the triggers. Extensive experiments results show the effectiveness of our method. When the poisoning rate is 0.04, CGBA can achieve an average attack success rate of 87.8%, 98.9%, 89.1%, and 98.5%, respectively.
翻译:传统图神经网络领域的后门攻击因标签混淆困境而易被察觉。为探究图神经网络的后门脆弱性并构建更隐蔽的后门攻击方法,本文提出了一种面向节点分类任务的干净标签图后门攻击方法(CGBA)。与现有后门攻击方法不同,CGBA 既不需要修改节点标签,也无需改动图结构。具体而言,为解决样本内容与标签不一致的问题,CGBA 从特定目标类别中选取投毒样本,并在向目标样本注入触发器后,将该样本的原始标签作为目标标签(即干净标签)。为保证邻域节点的相似性,该方法精心选取节点的原始特征作为触发器,进一步提升触发器的隐蔽性。大量实验结果表明了本方法的有效性。当投毒率为0.04时,CGBA 的平均攻击成功率分别达到87.8%、98.9%、89.1%和98.5%。