USENIX Security2021Top-tier venue
Graph Backdoor
Zhaohan Xi, Ren Pang, Shouling Ji, Ting Wang
Abstract
Graph Neural Networks (GNNs) are vulnerable to backdoor attacks, where adversaries implant malicious triggers to manipulate model predictions. Existing graph backdoor attacks are susceptible to defense mechanisms or robust classifiers because they rely on subgraph injection or structural perturbations, e.g., creating additional edges to attach backdoor triggers to the original graph. To enhance the stealthiness of graph backdoors, we propose SPEAR, a novel structure-preserving graph backdoor attack that avoids modifying the graph's topology. SPEAR operates within a limited attack budget by selectively perturbing node attributes while ensuring the triggers exert significant influence through a global importance-driven feature selection strategy. Additionally, a neighborhood-aware trigger generator is employed to underpin a high attack success rate by utilizing semantic information from the neighborhood. SPEAR amplifies effectiveness and stealthiness by combining subtle yet impactful attribute manipulation with a refined trigger generation mechanism. Extensive experiments demonstrate that SPEAR achieves state-of-the-art effectiveness in bypassing defenses on real-world datasets, establishing it as a potent and stealthy backdoor attack for graph-based tasks. Code is available at https://github.com/yhDing/SPEAR.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 867de5f5-db62-40aa-99d4-da458aa42279Cited by top-tier papers47
- Invisible Backdoor Attack with Sample-Specific TriggersYuezun Li, Yiming Li, Baoyuan Wu, Longkang Li et al.ICCV 2021 · 639 citations
- BadEncoder: Backdoor Attacks to Pre-trained Encoders in Self-Supervised LearningJinyuan Jia, Yupei Liu, Neil Zhenqiang GongS&P 2022 · 200 citations
- Model Stealing Attacks Against Inductive Graph Neural NetworksYun Shen, Xinlei He, Yufei Han, Yang ZhangS&P 2022 · 88 citations
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 85 citations
- Rethinking the Reverse-engineering of Trojan TriggersZhenting Wang, Kai Mei, Hailun Ding, Juan Zhai et al.NeurIPS 2022 · 75 citations
Builds on23
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Strategies for Pre-training Graph Neural NetworksWeihua Hu, Bowen Liu, Joseph Gomes, Marinka Zitnik et al.ICLR 2020 · 1,744 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
Related papers
- SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor AttacksYuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen et al.WWW 2025 · 12 citations
- A2GBD: Attack-Agnostic Graph Backdoor DefenseChenxu Du, Yang Liu, Xingtong Yu, Zhuoer Xu et al.WWW 2026
- Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph ClassificationXiaobao Wang, Ruoxiao Sun, Yujun Zhang, Bingdao Feng et al.NeurIPS 2025 · 5 citations
- Clean-Label Graph Backdoor Attack in the Node Classification TaskHui Xia, Xiangwei Zhao, Rui Zhang, Shuo Xu et al.AAAI 2025 · 4 citations
- Attack by Yourself: Effective and Unnoticeable Multi-Category Graph Backdoor Attacks with Subgraph Triggers PoolJiangtong Li, Dongyi Liu, Kun Zhu, Dawei Cheng et al.NeurIPS 2025 · 4 citations
