Cross-Context Backdoor Attacks against Graph Prompt Learning
Xiaoting Lyu, Yufei Han, Wei Wang, Hangwei Qian, Ivor W. Tsang, Xiangliang Zhang
摘要
Graph Prompt Learning (GPL) bridges significant disparities between pretraining and downstream applications to alleviate the knowledge transfer bottleneck in real-world graph learning. While GPL offers superior effectiveness in graph knowledge transfer and computational efficiency, the security risks posed by backdoor poisoning effects embedded in pretrained models remain largely unexplored. Our study provides a comprehensive analysis of GPL's vulnerability to backdoor attacks. We introduce CrossBA, the first cross-context backdoor attack against GPL, which manipulates only the pretraining phase without requiring knowledge of downstream applications. Our investigation reveals both theoretically and empirically that tuning trigger graphs, combined with prompt transformations, can seamlessly transfer the backdoor threat from pretrained encoders to downstream applications. Through extensive experiments involving 3 representative GPL methods across 5 distinct cross-context scenarios and 5 benchmark datasets of node and graph classification tasks, we demonstrate that CrossBA consistently achieves high attack success rates while preserving the functionality of downstream applications over clean input. We also explore potential countermeasures against CrossBA and conclude that current defenses are insufficient to mitigate CrossBA. Our study highlights the persistent backdoor threats to GPL systems, raising trustworthiness concerns in the practices of GPL techniques.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- PR-Attack: Coordinated Prompt-RAG Attacks on Retrieval-Augmented Generation in Large Language Models via Bilevel OptimizationYang Jiao, Xiaodong Wang, Kai YangSIGIR 2025 · 被引用 6 次
- Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph ClassificationXiaobao Wang, Ruoxiao Sun, Yujun Zhang, Bingdao Feng 等NeurIPS 2025 · 被引用 5 次
- Attack by Yourself: Effective and Unnoticeable Multi-Category Graph Backdoor Attacks with Subgraph Triggers PoolJiangtong Li, Dongyi Liu, Kun Zhu, Dawei Cheng 等NeurIPS 2025 · 被引用 4 次
- Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation ModelsJiayi Luo, Qingyun Sun, Lingjuan Lyu, Ziwei Zhang 等AAAI 2026 · 被引用 1 次
- Are You Using Reliable Graph Prompts? Trojan Prompt Attacks on Graph Neural NetworksMinhua Lin, Zhiwei Zhang, Enyan Dai, Zongyu Wu 等KDD 2025
它引用的顶会 Paper17
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen 等NeurIPS 2020 · 被引用 3,042 次
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 被引用 416 次
- GraphPrompt: Unifying Pre-Training and Downstream Tasks for Graph Neural NetworksZemin Liu, Xingtong Yu, Yuan Fang, Xinming ZhangWWW 2023 · 被引用 263 次
- Universal Prompt Tuning for Graph Neural NetworksTaoran Fang, Yunchao Zhang, Yang Yang, Chunping Wang 等NeurIPS 2023 · 被引用 166 次
- All in One: Multi-Task Prompting for Graph Neural NetworksXiangguo Sun, Hong Cheng, Jia Li, Bo Liu 等KDD 2023 · 被引用 149 次
相关 Paper
- Graph Contrastive Backdoor AttacksHangfan Zhang, Jinghui Chen, Lu Lin, Jinyuan Jia 等ICML 2023 · 被引用 25 次
- NOTABLE: Transferable Backdoor Attacks Against Prompt-based NLP ModelsKai Mei, Zheng Li, Zhenting Wang, Yang Zhang 等ACL 2023 · 被引用 17 次
- One Prompt Fits All: Universal Graph Adaptation for Pretrained ModelsYongqi Huang, Jitao Zhao, Dongxiao He, Xiaobao Wang 等NeurIPS 2025 · 被引用 15 次
- GPromptShield: Elevating Resilience in Graph Prompt Tuning Against Adversarial AttacksShuhan Song, Ping Li, Ming Dun, Maolei Huang 等ICLR 2025
- Prompt as a Double-Edged Sword: A Dynamic Equilibrium Gradient-Assigned Attack against Graph Prompt LearningJu Jia, Jingxuan Yu, Di Wu, Cong Wu 等KDD 2025 · 被引用 3 次
