Cross-Context Backdoor Attacks against Graph Prompt Learning
Xiaoting Lyu, Yufei Han, Wei Wang, Hangwei Qian, Ivor W. Tsang, Xiangliang Zhang
Abstract
Graph Prompt Learning (GPL) bridges significant disparities between pretraining and downstream applications to alleviate the knowledge transfer bottleneck in real-world graph learning. While GPL offers superior effectiveness in graph knowledge transfer and computational efficiency, the security risks posed by backdoor poisoning effects embedded in pretrained models remain largely unexplored. Our study provides a comprehensive analysis of GPL's vulnerability to backdoor attacks. We introduce CrossBA, the first cross-context backdoor attack against GPL, which manipulates only the pretraining phase without requiring knowledge of downstream applications. Our investigation reveals both theoretically and empirically that tuning trigger graphs, combined with prompt transformations, can seamlessly transfer the backdoor threat from pretrained encoders to downstream applications. Through extensive experiments involving 3 representative GPL methods across 5 distinct cross-context scenarios and 5 benchmark datasets of node and graph classification tasks, we demonstrate that CrossBA consistently achieves high attack success rates while preserving the functionality of downstream applications over clean input. We also explore potential countermeasures against CrossBA and conclude that current defenses are insufficient to mitigate CrossBA. Our study highlights the persistent backdoor threats to GPL systems, raising trustworthiness concerns in the practices of GPL techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 28422ca2-2c47-4cee-9ae9-3784d8e3af13Cited by top-tier papers6
- PR-Attack: Coordinated Prompt-RAG Attacks on Retrieval-Augmented Generation in Large Language Models via Bilevel OptimizationYang Jiao, Xiaodong Wang, Kai YangSIGIR 2025 · 6 citations
- Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph ClassificationXiaobao Wang, Ruoxiao Sun, Yujun Zhang, Bingdao Feng et al.NeurIPS 2025 · 5 citations
- Attack by Yourself: Effective and Unnoticeable Multi-Category Graph Backdoor Attacks with Subgraph Triggers PoolJiangtong Li, Dongyi Liu, Kun Zhu, Dawei Cheng et al.NeurIPS 2025 · 4 citations
- Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation ModelsJiayi Luo, Qingyun Sun, Lingjuan Lyu, Ziwei Zhang et al.AAAI 2026 · 1 citation
- Are You Using Reliable Graph Prompts? Trojan Prompt Attacks on Graph Neural NetworksMinhua Lin, Zhiwei Zhang, Enyan Dai, Zongyu Wu et al.KDD 2025
Builds on17
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen et al.NeurIPS 2020 · 3,042 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- GraphPrompt: Unifying Pre-Training and Downstream Tasks for Graph Neural NetworksZemin Liu, Xingtong Yu, Yuan Fang, Xinming ZhangWWW 2023 · 263 citations
- Universal Prompt Tuning for Graph Neural NetworksTaoran Fang, Yunchao Zhang, Yang Yang, Chunping Wang et al.NeurIPS 2023 · 166 citations
- All in One: Multi-Task Prompting for Graph Neural NetworksXiangguo Sun, Hong Cheng, Jia Li, Bo Liu et al.KDD 2023 · 149 citations
Related papers
- Graph Contrastive Backdoor AttacksHangfan Zhang, Jinghui Chen, Lu Lin, Jinyuan Jia et al.ICML 2023 · 25 citations
- NOTABLE: Transferable Backdoor Attacks Against Prompt-based NLP ModelsKai Mei, Zheng Li, Zhenting Wang, Yang Zhang et al.ACL 2023 · 17 citations
- One Prompt Fits All: Universal Graph Adaptation for Pretrained ModelsYongqi Huang, Jitao Zhao, Dongxiao He, Xiaobao Wang et al.NeurIPS 2025 · 15 citations
- GPromptShield: Elevating Resilience in Graph Prompt Tuning Against Adversarial AttacksShuhan Song, Ping Li, Ming Dun, Maolei Huang et al.ICLR 2025
- Prompt as a Double-Edged Sword: A Dynamic Equilibrium Gradient-Assigned Attack against Graph Prompt LearningJu Jia, Jingxuan Yu, Di Wu, Cong Wu et al.KDD 2025 · 3 citations
