跳到主要导航 跳到搜索 跳到主要内容

Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation Models

  • Beihang University
  • Sony Group Corporation
  • Guangxi Normal University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Graph Foundation Models (GFMs) are pre-trained on diverse source domains and adapted to unseen targets, enabling broad generalization for graph learning. Despite that GFMs have attracted considerable attention recently, their vulnerability to backdoor attacks remains largely underexplored. A compromised GFM can introduce backdoor behaviors into downstream applications, posing serious security risks. However, launching backdoor attacks against GFMs is non-trivial due to three key challenges. (1) Effectiveness: Attackers lack knowledge of the downstream task during pre-training, complicating the assurance that triggers reliably induce misclas-sifications into desired classes. (2) Stealthiness: The variability in node features across domains complicates trigger insertion that remains stealthy. (3) Persistence: Downstream fine-tuning may erase backdoor behaviors by updating model parameters. To address these challenges, we propose GFM-BA, a novel Backdoor Attack model against Graph Foundation Models. Specifically, we first design a label-free trigger association module that links the trigger to a set of prototype embeddings, eliminating the need for knowledge about downstream tasks to perform backdoor injection. Then, we introduce a node-adaptive trigger generator, dynamically producing node-specific triggers, reducing the risk of trigger detection while reliably activating the backdoor. Lastly, we develop a persistent backdoor anchoring module that firmly anchors the backdoor to fine-tuning-insensitive parameters, enhancing the persistence of the backdoor under downstream adaptation. Extensive experiments demonstrate the effectiveness, stealthiness, and persistence of GFM-BA.

源语言英语
主期刊名Proceedings of the AAAI Conference on Artificial Intelligence
编辑Sven Koenig, Chad Jenkins, Matthew E. Taylor
出版商Association for the Advancement of Artificial Intelligence
24142-24150
页数9
版本29
ISBN(印刷版)9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067, 9781577359067
DOI
出版状态已出版 - 2026
活动40th AAAI Conference on Artificial Intelligence, AAAI 2026 - Singapore, 新加坡
期限: 20 1月 202627 1月 2026

出版系列

姓名Proceedings of the AAAI Conference on Artificial Intelligence
编号29
40
ISSN(印刷版)2159-5399
ISSN(电子版)2374-3468

会议

会议40th AAAI Conference on Artificial Intelligence, AAAI 2026
国家/地区新加坡
Singapore
时期20/01/2627/01/26

指纹

探究 'Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation Models' 的科研主题。它们共同构成独一无二的指纹。

引用此