Researchers have developed STAG, a novel framework designed to stealthily inject backdoors into Graph Foundation Models (GFMs) that process text-attributed graphs (TAGs). Unlike previous attacks that target graph or text modalities independently, STAG leverages the graph-language alignment interface to coordinate graph triggers with text-side soft prompts. This coordinated approach ensures that both graph and text representations shift towards a target class. To maintain stealth, STAG generates readable text triggers and regularizes the subgraph structure to appear close to the original, making the attack difficult to detect through inspection or filtering. Experiments on various TAG datasets and GFMs have demonstrated STAG's effectiveness and stealth. AI
IMPACT This research highlights new vulnerabilities in graph foundation models, potentially impacting the security and trustworthiness of AI systems that process graph-structured data with text attributes.
RANK_REASON The cluster contains a research paper detailing a new attack framework against graph foundation models. [lever_c_demoted from research: ic=1 ai=1.0]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →