cs.CRMar 8, 2025

Backdoor Attacks on Discrete Graph Diffusion Models

Authors: Jiawen Wang, Samin Bin Karim, Yuan Hong, Binghui Wang

Organizations: Illinois Institute of Technology · University of Connecticut

Abstract

Diffusion models have demonstrated remarkable generative capabilities in continuous data domains such as images and videos. Recently, discrete graph diffusion models (DGDMs) have extended this success to graph generation, achieving state-of-the-art performance. However, deploying DGDMs in safety-critical applications, such as drug discovery, poses significant risks without a thorough understanding of their security vulnerabilities. In this work, we conduct the first study of backdoor attacks on DGDMs, a potent threat that manipulates both the training and generation phases of graph diffusion. We begin by formalizing the threat model and then design a backdoor attack that enables the compromised model to: 1) generate high-quality, benign graphs when the backdoor is not activated, 2) produce effective, stealthy, and persistent backdoored graphs when triggered, and 3) preserve fundamental graph properties (permutation equivariance and exchangeability) even under attack. We validate 1) and 2) empirically, both with and without backdoor defenses, and support 3) through theoretical analysis inspired by prior work.

Figures & tables

Appendix figures & tables6 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. TEMPO-Diffusion: Temporally Exposed Malicious Poisoning of Diffusion Models

    Jun 24, 2026William Aiken, Paula Branco, Guy-Vincent Jourdan +1Diffusion ModelsDiffusion Dynamics

  2. Local Message-Passing for Discrete Graph Generation

    Mar 9, 2026Jay Revolinsky, Harry Shomer, Jiliang TangPhysics-Guided DiffusionGnn-Based Detectors