Clean-Label Graph Backdoor Attack in the Node Classification Task
Hui Xia, Xiangwei Zhao, Rui Zhang, Shuo Xu, Luming Wang
Abstract
Graph neural networks (GNNs) have achieved impressive results in various graph learning tasks. Backdoor attacks pose a significant threat to GNNs, with a focus on dirty-label attacks. However, these attacks often necessitate the inclusion of blatantly incorrect inputs into the training set, rendering them easily detectable through simple filtering. In response to this challenge, we introduce Clean-Label Graph Backdoor Attack (CGBA). The majority of features in the generated poisoned nodes align with their true labels, significantly enhancing the difficulty of detecting the attack. Firstly, leveraging the uncertainty inherent in the GNNs, we develop a low-budget strategy for selecting poisoned nodes. This approach focuses on nodes in the target class with uncertain and low-degree classifications, allowing for efficient attacks within a limited budget while mitigating the impact on other clean nodes. Secondly, we present an innovative strategy for generating feature triggers. By boosting the confidence of poisoned samples in the target class, this tactic establishes a robust association between the trigger and the target class, even without modifying the labels of poisoned nodes. Additionally, we incorporate two constraints to reduce disruption to the graph structure. In conclusion, comprehensive experimental results unequivocally showcase CGBA's exceptional attack performance across three benchmark datasets and four GNNs models. Notably, the attack targeting the GraphSAGE model attains a 100% success rate, accompanied by a marginal benign accuracy drop of no more than 0.5%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 74f8e583-b111-4e4a-ad43-15540cf5ca11Cited by top-tier papers1
Ask how each one uses itBuilds on5
- Hidden Trigger Backdoor AttacksAniruddha Saha, Akshayvarun Subramanya, Hamed PirsiavashAAAI 2020 · 743 citations
- Deep Feature Space Trojan Attack of Neural Networks by Controlled DetoxificationSiyuan Cheng, Yingqi Liu, Shiqing Ma, Xiangyu ZhangAAAI 2021 · 191 citations
- Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from ScratchHossein Souri, Liam Fowl, Rama Chellappa, Micah Goldblum et al.NeurIPS 2022 · 184 citations
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 85 citations
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 12 citations
Related papers
- Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph ClassificationXiaobao Wang, Ruoxiao Sun, Yujun Zhang, Bingdao Feng et al.NeurIPS 2025 · 5 citations
- Rethinking Graph Backdoor Attacks: A Distribution-Preserving PerspectiveZhiwei Zhang, Minhua Lin, Enyan Dai, Suhang WangKDD 2024 · 21 citations
- SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor AttacksYuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen et al.WWW 2025 · 12 citations
- A2GBD: Attack-Agnostic Graph Backdoor DefenseChenxu Du, Yang Liu, Xingtong Yu, Zhuoer Xu et al.WWW 2026
- Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger OptimizationBinyan Xu, Fan Yang, Di Tang, Xilin Dai et al.AAAI 2026 · 1 citation
