Method for constructing multi-constraint graph neural network backdoor attack
By combining the graph classification model and similarity calculation in black box backdoor attacks, low-importance nodes are selected, and conditional GAN is used to optimize the trigger generation model, the shortcomings of attack node selection and trigger generation methods in the existing technology are solved, and the success rate and concealment of backdoor attacks are improved.
Patent Information
- Application Number
- CN202510213544.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-26
- Publication Date
- 2025-06-27
AI Technical Summary
The existing black box backdoor attack method is easy to select high-node nodes when selecting attack nodes, resulting in errors in classification of adjacent nodes. The trigger generation method is difficult to utilize the topological characteristics between nodes, resulting in low similarity between the trigger and the original data and is easily eliminated by the detection defense mechanism.
By using GCN, GAT and GraphSAGE to classify graph nodes, vote to select a set of error-prone classification nodes, and combine the Sarensen-Dice method to calculate the similarity and the Katz algorithm to calculate the node importance, and select low-importance nodes as attack nodes. At the same time, a trigger generation model and a graph discriminator are built, and a conditional GAN is formed for training, and the trigger generation model is optimized to improve its similarity to the original graph data.
It improves the selection accuracy of attack nodes, reduces classification errors of neighboring nodes, enhances the similarity between triggers and original data, improves the success rate of backdoor attacks, and reduces the risk of being eliminated by the detection defense mechanism.
Smart Images

Figure CN120217360A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for constructing a backdoor attack on a multi-constrained graph neural network, belonging to the technical field of computer and information science. Background Art
[0002] In recent years, Graph Neural Networks (GNNs) have been widely applied in fields such as social network analysis, recommendation systems, drug discovery, and traffic analysis due to their remarkable performance in processing graph-structured data. GNNs are based on a message-passing mechanism and update node representations by aggregating information from neighboring nodes, thereby being able to capture the complex relationships between node features and topological structures in a graph. However, despite the breakthrough achievements of GNNs in various tasks, there are still significant challenges in defending against malicious attacks. Research shows that GNNs are vulnerable to adversarial attacks, which can significantly reduce the performance of the model by making minor modifications to the graph structure or node features. This vulnerability may lead to serious security risks in real-world scenarios, such as being unable to accurately identify malicious users in a social network or making incorrect risk assessments in a financial system.
[0003] As a type of adversarial attack on GNNs, the backdoor attack does not require modifying the features of a large number of edges or nodes. The backdoor attack implants a trigger in the training data, causing the model to output the target category specified by the attacker when encountering a test sample with the trigger. Compared with traditional adversarial attacks, the backdoor attack has a low computational cost and less dependence on the model. In most cases, we cannot obtain the original structure of the graph data and can only perform a black-box backdoor attack. In existing black-box attack methods, a single trigger fails to fully utilize the training data, resulting in poor flexibility and concealment of the attack. Malicious clients select training nodes that are densely connected to other nodes in the graph through a clustering method and attach triggers, which easily causes misclassification of adjacent nodes and affects the accuracy of the node classification task of the model; existing trigger generation methods are only based on node attribute information and are difficult to obtain the structural information between nodes, making the nodes contained in the trigger have a low similarity to the original data and increasing the risk of being eliminated by the detection and defense mechanism.
[0004] In summary, the black-box backdoor attack algorithms for different threat scenarios have the following problems: (1) The method based on data clustering selects nodes close to the clustering center and attaches triggers. Since the selected nodes have a high node degree, the change of their labels will cause misclassification of adjacent nodes. (2) Existing trigger generation methods regard the attributes of each node as independent data points and are difficult to extract the topological structure features between nodes, resulting in a weak connection relationship between the trigger and the attack node, being easily deviated from the original data distribution, reducing the similarity between the trigger and the original data, and being easily eliminated by the detection and defense mechanism, leading to the failure of the backdoor attack. Summary of the Invention
[0005] The object of the present invention is to address the problems that the existing methods are prone to attacking high-degree nodes, resulting in misclassification of adjacent nodes, and the trigger is easily detected, and to propose a mechanism for selecting attack nodes with multiple constraints and an adversarial high-concealment trigger generation method.
[0006] The design principle of the present invention is as follows: First, use GCN, GAT, and GraphSAGE to classify graph nodes, and vote to select the set of nodes with error-prone classification. Use the Sarensen-Dice method to calculate the similarity of adjacent nodes in the whole graph, and proportionally select high-similarity node pairs to form a set of similar nodes. Calculate the node importance of the intersection of the two sets through the Katz algorithm, and proportionally select low-importance nodes as attack nodes; then construct a trigger generation model and a graph discriminator, and form a conditional GAN for training; finally, combine the trained trigger generation model with GCN to form a conditional GAN, and optimize the trigger generation model in combination with the selected attack nodes.
[0007] The technical solution of the present invention is implemented through the following steps:
[0008] Step 1: Use GCN, GAT, and GraphSAGE to classify graph nodes, and vote to select the set of nodes with error-prone classification. Use the Sarensen-Dice method to calculate the similarity of adjacent nodes in the whole graph, and proportionally select high-similarity node pairs to form a set of similar nodes. Calculate the node importance of the intersection of the two sets through the Katz algorithm, and proportionally select low-importance nodes as attack nodes.
[0009] Step 1.1: Use GCN, GAT, and GraphSAGE to classify graph nodes, and vote to select the set of nodes with error-prone classification.
[0010] Step 1.2: Use the Sarensen-Dice method to calculate the similarity of adjacent nodes in the whole graph, and proportionally select high-similarity node pairs to form a set of similar nodes.
[0011] Step 1.3: Calculate the node importance of the intersection of the two sets through the Katz algorithm, and proportionally select low-importance nodes as attack nodes.
[0012] Step 2: Construct a trigger generation model and a graph discriminator, and form a conditional GAN for training.
[0013] Step 3: Combine the trained trigger generation model with GCN to form a conditional GAN, and optimize the trigger generation model in combination with the selected attack nodes.
[0014] Beneficial effects
[0015] Compared with other black-box backdoor attack methods, the present invention combines the node features and topological structure of graph data, selects attack nodes with weak influence on adjacent node discrimination, and simultaneously designs a generative adversarial network to train and optimize the trigger generation model, improving the similarity between the trigger and the original graph data and increasing the attack success rate. Description of the Drawings
[0016] Figure 1 It is a flowchart of a backdoor attack on a graph neural network with multiple constraints constructed according to the present invention. Detailed Embodiments
[0017] To better illustrate the purpose and advantages of the present invention, the following further details the implementation manners of the method of the present invention with reference to examples.
[0018] The experimental data comes from the open-source datasets Cora, Pubmed, Citeseer, and Photo. The selected datasets are widely used in graph node classification tasks. The specific information is shown in Table 1.
[0019] Table 1 Information of Experimental Datasets
[0020]
[0021] The Cora dataset comes from the Machine Learning Group at Cornell University and contains 2,708 papers. Each paper is represented by a 1,433-dimensional term frequency vector, with a total of 312,497 citation relationships and 7 research field labels in total.
[0022] The Pubmed dataset is a graph dataset of medical citations on diabetes, with a total of 19,717 medical literature and 44,338 links. The dataset labels are 3 different types of diabetes.
[0023] The Citeseer dataset is a graph dataset of citations in the field of computer science, recording the citation relationships between literature. The nodes represent academic literature (3,327 articles), and the edges represent the citation relationships between the literature. The academic literature is divided into 6 categories: Agents, AI (Artificial Intelligence), DB (Database), IR (Information Retrieval), ML (Machine Language), and HCI.
[0024] The Photo dataset is a graph dataset about Amazon's e-commerce company. The nodes represent products, and the edges represent that 2 products are often purchased together. The node features are product reviews encoded by the bag-of-words, and its feature dimension is 745. The common task of the dataset is to map products to their respective product categories.
[0025] This experiment was conducted on a computer and a server. The specific configurations of the computer are as follows: CPU: Interi7-6700K 3.40GHz, Memory: 20G, Operating System: windows 10, 64-bit; The specific configurations of the server are as follows: CPU: Intel(R)Xeon(R)Gold 6248R, Memory: 128G, GPU: NVIDIAQuadro RTX 6000, Operating System: LinuxUbuntu, 64-bit.
[0026] The specific process of this experiment is as follows:
[0027] Step 1: Use GCN, GAT, and GraphSAGE to classify graph nodes, vote to select the error-prone classification node set, calculate the similarity of adjacent nodes in the whole graph using the Sarensen-Dice method, select high-similarity node pairs in proportion to form a similar node set, calculate the node importance of the intersection of the two sets through the Katz algorithm, and select low-importance nodes in proportion as attack nodes.
[0028] Step 1.1: Use GCN, GAT, and GraphSAGE to classify graph nodes and vote to select the error-prone classification node set. Vote on the classification results according to the following formula, and select the node with the highest vote count S i as the node set that is easily misclassified:
[0029]
[0030] where N represents the total number of nodes, is the indicator function, which is 1 if the condition holds, otherwise 0. and are the discrimination results of node v i in the three expert models respectively.
[0031] Step 1.2: Calculate the similarity of adjacent nodes in the whole graph using the Sarensen-Dice method, and select high-similarity node pairs in proportion to form a similar node set.
[0032] Step 1.2.1: Calculate the similarity coefficient between two adjacent graph nodes in all graph data, and set the percentile threshold according to the similarity distribution. The similarity coefficient formula is as follows:
[0033]
[0034] where N k (u) represents the k-hop neighbors of node u, and |N k (u)| represents the number of k-hop neighbors of node u.
[0035] Step 1.2.2: Select the top 20% of node pairs with high similarity according to the distribution of similarity, and form a similar node set after removing duplicates.
[0036] Step 1.3: Calculate the node importance of the intersection of the two sets through the Katz algorithm, and select the nodes with low importance as attack nodes in proportion.
[0037] Step 1.3.1: Use the Katz algorithm to calculate the node importance of the intersection of the error-prone classification node set and the similar node set. The importance of node v i (i.e., the Katz value) can be calculated by the following formula:
[0038] C = (I - αA) -1 β (3)
[0039] where I is the identity matrix, A is the adjacency matrix, α is a decay factor used to control the weight of the contribution of distant neighbors to node centrality, and β is a one-dimensional column vector used to measure the influence of the node itself to ensure that the node has an initial centrality value even when there are no neighbors.
[0040] Step 1.3.2: Sort in ascending order of importance, and select the top 1% of nodes with low importance as attack nodes.
[0041] Step 2: Construct a trigger generation model and a graph discriminator, and form a conditional GAN for training.
[0042] Step 2.1: Construct a trigger generation model. Input random noise z and node embedding e, where e is regarded as the condition for generating graph data, including node attribute information and topological structure information, used to constrain trigger generation, and the output is the trained trigger generation model.
[0043] Step 2.2: Construct a graph discriminator. The input includes the generated graph data G(z) and the real graph data x, and evaluate the realism of the trigger generated by the generator by comparing the differences between the two.
[0044] Step 2.3: Combine the constructed trigger generation model and discriminator to form a conditional GAN, and train with unlabeled graph nodes to generate triggers similar to the original graph data. The objective function of the conditional GAN can be expressed as minimizing the combination of the generator loss and the discriminator loss:
[0045]
[0046] where, p d(X) is the distribution of training data, p z(Z) is the prior of the input noise information, and G and D represent the trigger generation model and the graph discriminator respectively. E xis the expectation of x, D(x) is the probability that the discriminator judges the generated data x as real data, and G(z) is the generated graph data. L(G, D) represents the loss of the trigger generation model and the graph discriminator, and the loss components are as follows:
[0047]
[0048] Among them, λ represents the weights of each item, balancing the generation effect of the trigger. l sup is the supervised loss, l uns is the unsupervised loss, l sim is the similarity loss, measuring the similarity degree of the direction between the original unlabeled sample x i ∈X U and the generated sample y i ~G(z), l fea is the feature matching loss, which guides the generator to generate more real data by comparing the differences between the features of the generated data and the real data.
[0049] l sup The specific formula is as follows:
[0050]
[0051] Among them, x i ∈X L is the original labeled sample, y i is the label of x i .
[0052] l uns The specific formula is as follows:
[0053]
[0054] Among them, x i ∈X U is the original unlabeled sample, x′ i ~G(z) is the generated sample, P F (·) represents the probability that the node is predicted as false.
[0055] l sim The specific formula is as follows:
[0056]
[0057] l fea The specific formula is as follows:
[0058]
[0059] Among them, h (n) (x) represents the feature extraction result of the last layer network of the discriminator for the sample x, The distance metric representing the feature matching loss is the L2 norm, and x i ∈X batch is the original sample.
[0060] Step 3: Combine the trained trigger generation model with the GCN to form a conditional GAN, and optimize the trigger generation model by combining the selected attack nodes.
[0061] Step 3.1: Initialize the GCN parameters, attach the trained generated trigger to the attack node, train and update the GCN, fix the trigger generation model parameters, update the GCN parameters multiple times, and the loss of the GCN is calculated as follows:
[0062]
[0063] where represents the multi-order subgraph centered on node v i , add(·) represents attaching the trigger g to the attack node in the subgraph j . y i is the label of the normal node , y t is the target label of the attack node , and l CE (·) represents the cross-entropy loss function.
[0064] Step 3.2: After the GCN is updated, the trigger generation model is updated accordingly, and the optimized trigger g is injected i to mislead the GCN to predict the labels of each node in as y t , and the loss of the trigger generation model is calculated as follows:
[0065]
[0066] where f s is the updated GCN model, and l CE (·) represents the cross-entropy loss function.
[0067] Step 3.3: Optimize the trigger generation model in a loop, and finally use the optimized trigger generation model to generate a highly concealed trigger.
[0068] The above specific description further details the purpose, technical solution, and beneficial effects of the invention. It should be understood that the above is only a specific embodiment of the present invention and is not used to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. Construct a multi-constrained graph neural network backdoor attack method, which is characterized by The method comprises the following steps: Step 1: Use GCN, GAT, and GraphSAGE to classify graph nodes, and vote for error-prone classification node sets. Use the Sarensen-Dice method to calculate the similarity of adjacent nodes in the entire graph, and take high-similarity node pairs in proportion to form similar node sets. Use the Katz algorithm to calculate the node importance of the intersection of the two sets, and take low-importance nodes in proportion as attack nodes. Step 2: Build a trigger generation model and graph discriminator, and train them into a conditional GAN. Step 3: Combine the trained trigger generation model with GCN to form a conditional GAN, and optimize the trigger generation model in combination with the selected attack nodes.
2. The method for constructing a multi-constrained graph neural network backdoor attack according to claim 1 is characterized in that: In step 1, three models, GCN, GAT and GraphSAGE, are used to classify nodes according to the formula Voting is performed, where N represents the total number of nodes. is an indicator function, which is 1 if the condition is met, otherwise 0. Select the number of votes S i The highest nodes are taken as the set of nodes that are prone to misclassification.
3. The method for constructing a multi-constrained graph neural network backdoor attack according to claim 1 is characterized in that: In step 1, the Sarensen-Dice method is used to calculate the similarity of adjacent nodes in the entire graph, and the top 20% node pairs with high similarity are selected. After removing duplicate nodes based on the mutual differences of the set, a similar node set is formed.
4. The method for constructing a multi-constrained graph neural network backdoor attack according to claim 1 is characterized in that: In step 1, the Katz algorithm is used to calculate the node importance of the intersection of the error-prone classification node set and the similarity node set, and the nodes are sorted in ascending order by importance, and the top 1% of the nodes with low importance are selected as attack nodes.
5. The method for constructing a multi-constrained graph neural network backdoor attack according to claim 1, characterized in that: In step 2, the trigger generation model and graph discriminator constructed are combined into a conditional GAN to train the trigger generation model. G = l fea +λ1l sim Calculate the loss of the trigger generation model using the formula L D = l sup +λ0l uns +λ1l sim Calculate the loss of the graph discriminator, where λ represents the weight of each item, l sup is the supervised loss, calculated as x i ∈X L is the original labeled sample, y i is x i Label; l uns is the unsupervised loss, calculated as x i ∈X U is the original unlabeled sample, x′ i ~G(z) is the generated sample, P F (·) represents the probability that a node is predicted to be false; l sim is the similarity loss, calculated as l fea is the feature matching loss, calculated as h (n) (x) represents the feature extraction result of the last layer of the discriminator for sample x. The distance metric representing the feature matching loss is the L2 norm, x i ∈X batch For real samples.
6. The method for constructing a multi-constrained graph neural network backdoor attack according to claim 1 is characterized in that: In step 3, conditional GAN is used to optimize the trigger generation model using the formula As the loss of GCN, use the formula As the trigger to generate the model loss, Represents the node v i A multi-order subgraph with a center as the center. add(·) means adding a trigger g to the trigger node of the subgraph. j ,y i It is a normal node The label, y t Is the attack node The target label, l CE (·) represents the cross entropy loss function, f s Represents the GCN model.