Diffusion models have demonstrated remarkable generative capabilities in continuous data domains such as images and videos. Recently, discrete graph diffusion models (DGDMs) have extended this success to graph generation, achieving state-of-the-art performance. However, deploying DGDMs in safety-critical applications, such as drug discovery, poses significant risks without a thorough understanding of their security vulnerabilities. In this work, we conduct the first study of backdoor attacks on DGDMs, a potent threat that manipulates both the training and generation phases of graph diffusion. We begin by formalizing the threat model and then design a backdoor attack that enables the compromised model to: 1) generate high-quality, benign graphs when the backdoor is not activated, 2) produce effective, stealthy, and persistent backdoored graphs when triggered, and 3) preserve fundamental graph properties (permutation equivariance and exchangeability) even under attack. We validate 1) and 2) empirically, both with and without backdoor defenses, and support 3) through theoretical analysis inspired by prior work.
Figures & tables
Figure 1 : Overview of our backdoor attack on DGDMs. A backdoored DGDM is trained on both clean and backdoored (with a subgraph trigger) molecule graphs. The noise is added based on Markov transition matrices associated with node types (e.g., C, N, F, O) and edge types (e.g., ’NoBond’: ∅ , ’SINGLE Bond’: − , ’DOUBLE Bond’: = , ’TRIPLE Bond’: ≡ ). In forward diffusion, clean and backdoored graphs will converge to different limit distributions. In the reverse denoising diffusion, a clean/backdoored graph is generated and denoised step by step from the limit distribution produced by clean/backdoored graphs.
Figure 2 : Example clean molecules and backdoored ones.
Datasets
QM9
MOSES
GuacaMol
ASR
V
U
ASR
V
U
ASR
V
U
w/o. attack
-
99
100
-
83
100
-
85
100
w. attack
100
97
100
87
83
100
85
86
100
Table 1 : Default results (%) on the three tested datasets.
Table 4
Dataset
#Epochs
r=0.2
r=0.5
r=1
ASR
V
U
ASR
V
U
ASR
V
U
QM9
0
100
97
100
100
97
100
100
100
100
10
100
97
100
99
97
100
100
100
100
20
99
98
100
99
98
100
100
100
100
50
98
98
100
99
98
100
99
100
100
100
98
99
100
99
100
100
99
100
100
Table 6 : Backdoor attack results against finetuning on clean graphs with varying epochs and r (PR=5%).
Dataset
Ratio
r=0.2
r=0.5
r=1
ASR
V
U
ASR
V
U
ASR
V
U
QM9
0%
100
97
100
100
97
100
100
100
100
1%
99
97
100
99
97
100
100
99
100
2%
99
98
100
99
95
100
99
100
100
5%
98
97
100
99
92
100
97
100
100
10%
98
99
100
99
94
100
98
99
100
Table 7 : Backdoor attack results against finetuning on varying ratios of backdoored graphs mapped to the clean limit distribution.
Datasets
QM9
MOSES
GuacaMol
ASR
V
U
ASR
V
U
ASR
V
U
Transfer attack
100
95
100
99
92
100
99
94
100
Finetune on clean graphs
100
100
100
99
88
100
98
90
100
Finetune on backdoored graphs
100
100
100
98
91
100
96
92
100
Table 8 : Transferring our attack results on DisCo without and with defenses under the default setting.
Appendix figures & tables6 assets
Supplementary material from the paper’s appendix.
Appendix
Figure 3 : Examples of generated clean graphs.
Figure 4 : Examples of generated backdoored graphs.
ASR
V
U
w/o. attack
-
62
100
w. attack
95
56
100
Appendix
Table 9 : Attack results (%) on SBM.
#atoms
ASR
V
U
1
78
100
100
2
100
100
100
3
100
97
100
Appendix
Table 10 : Attack results (%) with valid chemical triggers.
Pruning Ratio
ASR
V
U
0%
100
97
100
10%
95
97
100
20%
67
97
100
30%
54
86
100
40%
47
55
100
Appendix
Table 11 : Fine-pruning results on the backdoored QM9 model.
Trigger
Motif
FPR
TPR
Top Anomalous
Size
Motif
O=C-F
1
0.03
1.00
F
O=C-F
2
0.06
1.00
C-F
O=C-F
3
0.22
1.00
O=C-F
N-N
1
0.03
0.01
N
N-N
2
0.06
1.00
N-N
Appendix
Table 12: Trajectory-level detectability results on QM9. The detector is trigger-agnostic and calibrates thresholds using only clean calibration trajectories.