Are You Using Reliable Graph Prompts? Trojan Prompt Attacks on Graph Neural Networks
Minhua Lin, Zhiwei Zhang, Enyan Dai, Zongyu Wu, Yilong Wang, Xiang Zhang, Suhang Wang
Abstract
Graph Prompt Learning (GPL) has been introduced as a promising approach that uses prompts to adapt pre-trained GNN models to specific downstream tasks without requiring fine-tuning of the entire model. Despite the advantages of GPL, little attention has been given to its vulnerability to backdoor attacks, where an adversary can manipulate the model's behavior by embedding hidden triggers. Existing graph backdoor attacks rely on modifying model parameters during training, but this approach is impractical in GPL as GNN encoder parameters are frozen after pre-training. Moreover, downstream users may fine-tune their own task models on clean datasets, further complicating the attack. In this paper, we propose TGPA, a backdoor attack framework designed specifically for GPL. TGPA injects backdoors into graph prompts without modifying pretrained GNN encoders and ensures high attack success rates and clean accuracy. To address the challenge of model fine-tuning by users, we introduce a finetuning-resistant poisoning approach that maintains the effectiveness of the backdoor even after downstream model adjustments. Extensive experiments on multiple datasets under various settings demonstrate the effectiveness of TGPA in compromising GPL models with fixed GNN encoders. Our code is publicly available at: https://github.com/ventr1c/TPGA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 444d7214-ebfc-4530-b922-bc57849632a2Cited by top-tier papers1
Ask how each one uses itBuilds on33
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen et al.NeurIPS 2020 · 3,042 citations
- Strategies for Pre-training Graph Neural NetworksWeihua Hu, Bowen Liu, Joseph Gomes, Marinka Zitnik et al.ICLR 2020 · 1,744 citations
- AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated PromptsTaylor Shin, Yasaman Razeghi, Robert L. Logan IV, Eric Wallace et al.EMNLP 2020 · 1,162 citations
- SimGRACE: A Simple Framework for Graph Contrastive Learning without Data AugmentationJun Xia, Lirong Wu, Jintao Chen, Bozhen Hu et al.WWW 2022 · 424 citations
Related papers
- Cross-Context Backdoor Attacks against Graph Prompt LearningXiaoting Lyu, Yufei Han, Wei Wang, Hangwei Qian et al.KDD 2024 · 10 citations
- Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation ModelsJiayi Luo, Qingyun Sun, Lingjuan Lyu, Ziwei Zhang et al.AAAI 2026 · 1 citation
- Prompt as a Double-Edged Sword: A Dynamic Equilibrium Gradient-Assigned Attack against Graph Prompt LearningJu Jia, Jingxuan Yu, Di Wu, Cong Wu et al.KDD 2025 · 3 citations
- Prompt-based Unifying Inference Attack on Graph Neural NetworksYuecen Wei, Xingcheng Fu, Lingyun Liu, Qingyun Sun et al.AAAI 2025 · 6 citations
- BadPrompt: Backdoor Attacks on Continuous PromptsXiangrui Cai, Haidong Xu, Sihan Xu, Ying Zhang et al.NeurIPS 2022 · 103 citations
