Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph Classification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Xiaobao, Sun, Ruoxiao, Zhang, Yujun, Feng, Bingdao, He, Dongxiao, Wang, Luzhi, Jin, Di
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911316387561472
author Wang, Xiaobao
Sun, Ruoxiao
Zhang, Yujun
Feng, Bingdao
He, Dongxiao
Wang, Luzhi
Jin, Di
author_facet Wang, Xiaobao
Sun, Ruoxiao
Zhang, Yujun
Feng, Bingdao
He, Dongxiao
Wang, Luzhi
Jin, Di
contents Graph Neural Networks (GNNs) have demonstrated strong performance across tasks such as node classification, link prediction, and graph classification, but remain vulnerable to backdoor attacks that implant imperceptible triggers during training to control predictions. While node-level attacks exploit local message passing, graph-level attacks face the harder challenge of manipulating global representations while maintaining stealth. We identify two main sources of anomaly in existing graph classification backdoor methods: structural deviation from rare subgraph triggers and semantic deviation caused by label flipping, both of which make poisoned graphs easily detectable by anomaly detection models. To address this, we propose DPSBA, a clean-label backdoor framework that learns in-distribution triggers via adversarial training guided by anomaly-aware discriminators. DPSBA effectively suppresses both structural and semantic anomalies, achieving high attack success while significantly improving stealth. Extensive experiments on real-world datasets validate that DPSBA achieves a superior balance between effectiveness and detectability compared to state-of-the-art baselines.
format Preprint
id arxiv_https___arxiv_org_abs_2509_26032
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph Classification
Wang, Xiaobao
Sun, Ruoxiao
Zhang, Yujun
Feng, Bingdao
He, Dongxiao
Wang, Luzhi
Jin, Di
Machine Learning
Cryptography and Security
Graph Neural Networks (GNNs) have demonstrated strong performance across tasks such as node classification, link prediction, and graph classification, but remain vulnerable to backdoor attacks that implant imperceptible triggers during training to control predictions. While node-level attacks exploit local message passing, graph-level attacks face the harder challenge of manipulating global representations while maintaining stealth. We identify two main sources of anomaly in existing graph classification backdoor methods: structural deviation from rare subgraph triggers and semantic deviation caused by label flipping, both of which make poisoned graphs easily detectable by anomaly detection models. To address this, we propose DPSBA, a clean-label backdoor framework that learns in-distribution triggers via adversarial training guided by anomaly-aware discriminators. DPSBA effectively suppresses both structural and semantic anomalies, achieving high attack success while significantly improving stealth. Extensive experiments on real-world datasets validate that DPSBA achieves a superior balance between effectiveness and detectability compared to state-of-the-art baselines.
title Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph Classification
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2509.26032