Effective Backdoor Attack on Graph Neural Networks in Spectral Domain
Xiangyu Zhao,Hanzhou Wu,Xinpeng Zhang
DOI: https://doi.org/10.1109/jiot.2023.3332848
IF: 10.6
2023-01-01
IEEE Internet of Things Journal
Abstract:The susceptibility of Graph Neural Networks (GNNs) to backdoor attacks poses a significant potential threat to GNN-based Internet of Things (IoT) systems. In such attacks, GNNs are manipulated to behave abnormally when presented with maliciously crafted samples known as trigger samples, which can be exploited by attackers for their malicious intent. To address this issue, this paper studies the vulnerability of GNNs from the attacker’s angle by proposing a novel backdoor attack on GNNs. Our technincal motivation is that most existing backdoor attacks only treat GNNs as black box and define trigger samples in the spatial domain, which lack deeper insights and further exploitation of GNNs, limiting the attacking effectiveness. Inspired by frequency-based backdoor attacks in vision domain and spectral graph theory, we propose an effective graph backdoor attack based on the spectral domain of graph data, which injects trigger signals into the frequency spectrum of normal attributed graphs. By injecting subtle trigger signal into the important frequency band of important node features, the learning of backdoor and clean data are entangled. As a result, it becomes hard for the defender to remove the backdoor without degrading the model’s normal performance, improving the robustness of the attack. Experiments on both homophilic graphs and heterophilic graphs, with commonly used GNN architectures show that our proposed method achieves high attack success rate without significantly degrading the normal performance of the victim GNN. The attack is also shown to be robust against various processing towards graph data due to the entanglement strategy.
computer science, information systems,telecommunications,engineering, electrical & electronic