Related Experiment Videos
BGNAS: Backdoored graph neural architecture search
Gusheng Tian1, Hong Yang1, Peng Zhang1
1Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou, 510006, China.
Abstract:
Graph Neural Networks (GNNs) have been shown to be vulnerable to backdoor attacks, where attackers implant hidden backdoors into model weights of GNNs. However, backdoors hidden in GNN weights are non-persistent and easily erased by retraining models on clean data. To this end, we investigate a new threat of implanting backdoors in GNNs neural architectures that is independent of the model weights of GNNs. A new backdoored graph neural architecture search model (BGNAS for short) is proposed to use graph neural architecture search algorithms to discover new GNN neural architectures with backdoors. Unlike previous works that rely on manually designed backdoored neural architecture and triggers, BGNAS simultaneously designs backdoored GNN neural architectures associated with their trigger generators, where the generated triggers are indistinguishable within the overall graph data to ensure stealthiness. Theoretical analysis demonstrates that backdoors embedded in graph neural architectures remain effective even after weight re-initialization and retraining on clean data. Experimental results further show that BGNAS achieves high attack effectiveness while maintaining competitive prediction performance on benign data.