🤖 AI Summary
This work presents the first systematic study of backdoor attacks against text-guided graph generation diffusion models. Focusing on the joint latent diffusion model (LDM)–variational autoencoder (VAE) architecture, we propose a text-triggered data poisoning method that injects semantically benign textual prompts—e.g., “in the style of X”—paired with malicious subgraphs during training. Experiments demonstrate that the backdoor is primarily embedded during VAE reconstruction and diffusion process training—not during pretraining. On four benchmark datasets, our attack achieves ≥50% success rate with ≤10% poisoning ratio and >80% success rate at 24% poisoning ratio, while negligibly degrading clean-sample generation quality. This reveals a critical security vulnerability in multimodal graph generation models and provides novel insights for designing effective defenses.
📝 Abstract
The rapid progress of graph generation has raised new security concerns, particularly regarding backdoor vulnerabilities. While prior work has explored backdoor attacks in image diffusion and unconditional graph generation, conditional, especially text-guided graph generation remains largely unexamined. This paper proposes BadGraph, a backdoor attack method targeting latent diffusion models for text-guided graph generation. BadGraph leverages textual triggers to poison training data, covertly implanting backdoors that induce attacker-specified subgraphs during inference when triggers appear, while preserving normal performance on clean inputs. Extensive experiments on four benchmark datasets (PubChem, ChEBI-20, PCDes, MoMu) demonstrate the effectiveness and stealth of the attack: less than 10% poisoning rate can achieves 50% attack success rate, while 24% suffices for over 80% success rate, with negligible performance degradation on benign samples. Ablation studies further reveal that the backdoor is implanted during VAE and diffusion training rather than pretraining. These findings reveal the security vulnerabilities in latent diffusion models of text-guided graph generation, highlight the serious risks in models'applications such as drug discovery and underscore the need for robust defenses against the backdoor attack in such diffusion models.