Backdoor Attacks on Discrete Graph Diffusion Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Jiawen, Karim, Samin, Hong, Yuan, Wang, Binghui
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910865273389056
author Wang, Jiawen
Karim, Samin
Hong, Yuan
Wang, Binghui
author_facet Wang, Jiawen
Karim, Samin
Hong, Yuan
Wang, Binghui
contents Diffusion models are powerful generative models in continuous data domains such as image and video data. Discrete graph diffusion models (DGDMs) have recently extended them for graph generation, which are crucial in fields like molecule and protein modeling, and obtained the SOTA performance. However, it is risky to deploy DGDMs for safety-critical applications (e.g., drug discovery) without understanding their security vulnerabilities. In this work, we perform the first study on graph diffusion models against backdoor attacks, a severe attack that manipulates both the training and inference/generation phases in graph diffusion models. We first define the threat model, under which we design the attack such that the backdoored graph diffusion model can generate 1) high-quality graphs without backdoor activation, 2) effective, stealthy, and persistent backdoored graphs with backdoor activation, and 3) graphs that are permutation invariant and exchangeable--two core properties in graph generative models. 1) and 2) are validated via empirical evaluations without and with backdoor defenses, while 3) is validated via theoretical results.
format Preprint
id arxiv_https___arxiv_org_abs_2503_06340
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Backdoor Attacks on Discrete Graph Diffusion Models
Wang, Jiawen
Karim, Samin
Hong, Yuan
Wang, Binghui
Cryptography and Security
Machine Learning
Diffusion models are powerful generative models in continuous data domains such as image and video data. Discrete graph diffusion models (DGDMs) have recently extended them for graph generation, which are crucial in fields like molecule and protein modeling, and obtained the SOTA performance. However, it is risky to deploy DGDMs for safety-critical applications (e.g., drug discovery) without understanding their security vulnerabilities. In this work, we perform the first study on graph diffusion models against backdoor attacks, a severe attack that manipulates both the training and inference/generation phases in graph diffusion models. We first define the threat model, under which we design the attack such that the backdoored graph diffusion model can generate 1) high-quality graphs without backdoor activation, 2) effective, stealthy, and persistent backdoored graphs with backdoor activation, and 3) graphs that are permutation invariant and exchangeable--two core properties in graph generative models. 1) and 2) are validated via empirical evaluations without and with backdoor defenses, while 3) is validated via theoretical results.
title Backdoor Attacks on Discrete Graph Diffusion Models
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2503.06340