arrow
Return

A Clean-Label Graph Backdoor Attack Method in Node Classification Task

delete2024-11-01
delete0
delete
OA
AI
M
Ming Xu *
Y
Yujing Bai
D
Dongdong Yang
DOI:10.1016/j.knosys.2024.112433delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Backdoor attacks in the traditional graph neural networks (GNNs) field are easily detectable due to the dilemma of confusing labels. To explore the backdoor vulnerability of GNNs and create a more stealthy backdoor attack method, a clean-label graph backdoor attack method(CGBA) in the node classification task is proposed in this paper. Differently from existing backdoor attack methods, CGBA requires neither modification of node labels nor graph structure. Specifically, to solve the problem of inconsistency between the contents and labels of the samples, CGBA selects poisoning samples in a specific target class and uses the samples' own label as the target label (i.e., clean-label) after injecting triggers into the target samples. To guarantee the similarity of neighboring nodes, the raw features of the nodes are elaborately picked as triggers to further improve the concealment of the triggers. Extensive experiments results show the effectiveness of our method. When the poisoning rate is 0.04, CGBA can achieve an average attack success rate of 87.8%, 98.9%, 89.1%, and 98.5%, respectively.
Keywords:
Machine learning
Network security
Graph neural networks
Backdoor
Node classification
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

K
Knowledge-Based Systems
IF:
7.6
Papers:
1.2W
Citations:
4.5W

Organization

H
Hangzhou Dianzi University
Scholars:
1.3W
Papers: 9.6K
Citations: 7.5K
A
Army Engineering University of PLA
Scholars:
4.9K
Papers: 3.7K
Citations: 5