Distributed Backdoor Attacks on Federated Graph Learning and Certified Defenses
Yuxin Yang, Qiang Li, Jinyuan Jia, Yuan Hong, Binghui Wang
Abstract
Federated graph learning (FedGL) is an emerging federated learning (FL) framework that extends FL to learn graph data from diverse sources. FL for non-graph data has shown to be vulnerable to backdoor attacks, which inject a shared backdoor trigger into the training data such that the trained backdoored FL model can predict the testing data containing the trigger as the attacker desires. However, FedGL against backdoor attacks is largely unexplored, and no effective defense exists. In this paper, we aim to address such significant deficiency. First, we propose an effective, stealthy, and persistent backdoor attack on FedGL. Our attack uses a subgraph as the trigger and designs an adaptive trigger generator that can derive the effective trigger location and shape for each graph. Our attack shows that empirical defenses are hard to detect/remove our generated triggers. To mitigate it, we further develop a certified defense for any backdoored FedGL model against the trigger with any shape at any location. Our defense involves carefully dividing a testing graph into multiple subgraphs and designing a majority vote-based ensemble classifier on these subgraphs. We then derive the deterministic certified robustness based on the ensemble classifier and prove its tightness. We extensively evaluate our attack and defense on six graph datasets. Our attack results show our attack can obtain > 90% backdoor accuracy in almost all datasets. Our defense results show, in certain cases, the certified accuracy for clean testing graphs against an arbitrary trigger with size 20 can be close to the normal accuracy under no attack, while there is a moderate gap in other cases. Moreover, the certified backdoor accuracy is always 0 for backdoored testing graphs generated by our attack, implying our defense can fully mitigate the attack. Source code is available at: https://github.com/Yuxin104/Opt-GDBA .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 10f20156-8970-4033-91d9-449e6e526159Cited by top-tier papers11
- FedGMark: Certifiably Robust Watermarking for Federated Graph LearningYuxin Yang, Qiang Li, Yuan Hong, Binghui WangNeurIPS 2024 · 11 citations
- Practicable Black-Box Evasion Attacks on Link Prediction in Dynamic Graphs - a Graph Sequential Embedding MethodJiate Li, Meng Pang, Binghui WangAAAI 2025 · 4 citations
- Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation ModelsJiayi Luo, Qingyun Sun, Lingjuan Lyu, Ziwei Zhang et al.AAAI 2026 · 1 citation
- MultiKD: Backdoor Defense in Federated Graph Learning via Attention-Guided Multi-Teacher DistillationJiale Zhang, Yanan Wang, Bosen Rao, Chengcheng Zhu et al.AAAI 2026
- Towards Robust Text-Attributed Federated Graph Learning: Multimodal Threats and DefenseZitong Shi, Guancheng Wan, Wenke Huang, Yuxin Wu et al.AAAI 2026
Builds on47
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 901 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
Related papers
- NI-GDBA: Non-Intrusive Distributed Backdoor Attack Based on Adaptive Perturbation on Federated Graph LearningKen Li, Bin Shi, Jiazhe Wei, Bo DongWWW 2025 · 3 citations
- Fend for Yourself! Backdoor Purification in Federated Graph Learning with an Evolving Knowledge AnchorChengcheng Zhu, Yunlong Mao, Jiale Zhang, Bosen Rao et al.USENIX Security 2026
- Energy-based Backdoor Defense Against Federated Graph LearningGuancheng Wan, Zitong Shi, Wenke Huang, Guibin Zhang et al.ICLR 2025
- FedBAP: Backdoor Defense via Benign Adversarial Perturbation in Federated LearningXinhai Yan, Libing Wu, Zhuangzhuang Zhang, Bingyi Liu et al.ACM MM 2025 · 2 citations
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 66 citations
