arrow
Return

Backdoor Attacks on Graph Classification via Data Augmentation and Dynamic Poisoning

delete2026-01-01
delete0
PRE
AI
Y
Yadong Wang
Z
Zhiwei Zhang *
P
Pengpeng Qiao
Y
Ye Yuan
王国仁 (Guoren Wang)
DOI:10.1007/978-3-032-06066-2_16delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Graph neural networks (GNNs) have gained widespread adoption in domains such as bioinformatics, social networks, and cheminformatics, yet they remain susceptible to backdoor attacks. Existing backdoor attacks typically rely on subgraph triggers, which often introduce detectable anomalies and employ random poisoned sample selection, resulting in reduced stealthiness and efficiency. To address these limitations, we propose a novel backdoor attack framework that leverages data augmentation-based triggers and dynamic poisoned sample selection. Specifically, we design three alternative data augmentation strategies, edge modification guided by cosine similarity, edge removal based on degree centrality, and feature masking via gradient saliency, as backdoor triggers. Furthermore, we introduce a dynamic poisoned sample selection method informed by forgetting events. This method dynamically prioritizes high-impact poisoned samples to enhance attack efficiency while reducing the number of samples required to achieve the corresponding attack success rate (ASR). Experiments on four benchmark datasets, PROTEINS, NCI1, Mutagenicity, and ENZYMES, demonstrate the superiority of our method.
Keywords:
GNNs
Graph Classification
Backdoor Attacks

Journal

M
MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES. RESEARCH TRACK, ECML PKDD 2025, PT III
IF:
0
Papers:
30
Citations:
0

Organization

B
beijing institute of technology
Scholars:
5.5W
Papers: 4.0W
Citations: 63
I
institute of science tokyo
Scholars:
3.3K
Papers: 1.2K
Citations: 0