USENIX Security2026Top-tier venue
Fend for Yourself! Backdoor Purification in Federated Graph Learning with an Evolving Knowledge Anchor
Chengcheng Zhu, Yunlong Mao, Jiale Zhang, Bosen Rao, Sheng Zhong
Abstract
Federated Graph Learning (FedGL) enables collaborative training on decentralized graph data while preserving privacy, yet its distributed nature makes it highly vulnerable to backdoor attacks. These attacks compromise the integrity of the global model by injecting malicious triggers. Existing defenses, however, are often ineffective on complex graph data or rely on a trusted server, creating an architectural conflict with modern privacy-preserving technologies. To overcome these limitations, we propose GBHINDER, a novel and practical trusted-server-free defense framework where each benign participant defends itself. GBHINDER establishes a virtuous cycle: it leverages its own trusted historical knowledge as a benign anchor to purify the downloaded global model, and in turn, selectively incorporates the global model's benign knowledge to progressively evolve the anchor itself. Specifically, this cycle is driven by two key components. A Historical Channel Attention Regularization module uses the anchor to constrain the global model's representations and disrupt backdoor propagation. To resolve the tension between local trust and global collaboration, an Adaptive Momentum Information Update mechanism enables the anchor to safely evolve by dynamically integrating robust global information, ensuring the anchor remains effective with federated iteration. Extensive experiments on several benchmark datasets demonstrate that GBHINDER significantly outperforms state-of-the-art (SOTA) defenses, successfully reducing the backdoor attack success rate to below 10% while preserving high accuracy on the main task.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 563fd45d-3d56-4ce1-81b2-27369dcdc6fdBuilds on16
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen et al.NeurIPS 2020 · 3,042 citations
- Personalized Federated Learning with Moreau EnvelopesCanh T. Dinh, Nguyen Hoang Tran, Tuan Dung NguyenNeurIPS 2020 · 1,542 citations
- Ditto: Fair and Robust Federated Learning Through PersonalizationTian Li, Shengyuan Hu, Ahmad Beirami, Virginia SmithICML 2021 · 1,313 citations
- Defending against Backdoors in Federated Learning with Robust Learning RateMustafa Safa Özdayi, Murat Kantarcioglu, Yulia R. GelAAAI 2021 · 250 citations
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 85 citations
Related papers
- Distributed Backdoor Attacks on Federated Graph Learning and Certified DefensesYuxin Yang, Qiang Li, Jinyuan Jia, Yuan Hong et al.CCS 2024 · 8 citations
- NI-GDBA: Non-Intrusive Distributed Backdoor Attack Based on Adaptive Perturbation on Federated Graph LearningKen Li, Bin Shi, Jiazhe Wei, Bo DongWWW 2025 · 3 citations
- Energy-based Backdoor Defense Against Federated Graph LearningGuancheng Wan, Zitong Shi, Wenke Huang, Guibin Zhang et al.ICLR 2025
- MultiKD: Backdoor Defense in Federated Graph Learning via Attention-Guided Multi-Teacher DistillationJiale Zhang, Yanan Wang, Bosen Rao, Chengcheng Zhu et al.AAAI 2026
- FedGMark: Certifiably Robust Watermarking for Federated Graph LearningYuxin Yang, Qiang Li, Yuan Hong, Binghui WangNeurIPS 2024 · 11 citations
