Return
Semantic-consistent trigger generation for backdoor attacks on graph neural networks
DOI:10.1016/j.knosys.2026.116900.png)
Abstract
En 中文
Graph Neural Networks (GNNs) have shown exceptional performance across diverse tasks due to their inherent capability to process non-Euclidean data. However, recent studies reveal that GNNs are vulnerable to structural perturbations and node attribute manipulations during training, leading to biased or erroneous decisions. Current feature-based backdoor attack methods generally rely on fixed-form triggers or necessitate structural modifications for viable activation, which may cause substantial disruption to the original graph structure. To address this challenge, we propose SCGBA, a high-performance adaptive strategy for generating and embedding feature triggers. SCGBA is the first to leverage semantic consistency to enable effective backdoor attacks without altering the original graph structure. Moreover, it incorporates a global structure-preserving constraint during the trigger embedding process, enhancing its ability to evade advanced backdoor defense mechanisms. Extensive experiments on multiple real-world graph datasets demonstrate that SCGBA significantly outperforms existing backdoor attack methods in trigger activation rates while maintaining robust evasiveness against various mainstream defense strategies.
Keywords:
Graph neural networks (GNNs)
Backdoor attack
Feature trigger
Semantic consistency
Structure preservation
Journal
K
IF:
7.6
Papers:
1.2W
Citations:
4.5W

