SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor Attacks
Yuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen, Qing He, Xiang Ao
Abstract
Graph Neural Networks (GNNs) are vulnerable to backdoor attacks, where adversaries implant malicious triggers to manipulate model predictions. Existing graph backdoor attacks are susceptible to defense mechanisms or robust classifiers because they rely on subgraph injection or structural perturbations, e.g., creating additional edges to attach backdoor triggers to the original graph. To enhance the stealthiness of graph backdoors, we propose SPEAR, a novel structure-preserving graph backdoor attack that avoids modifying the graph's topology. SPEAR operates within a limited attack budget by selectively perturbing node attributes while ensuring the triggers exert significant influence through a global importance-driven feature selection strategy. Additionally, a neighborhood-aware trigger generator is employed to underpin a high attack success rate by utilizing semantic information from the neighborhood. SPEAR amplifies effectiveness and stealthiness by combining subtle yet impactful attribute manipulation with a refined trigger generation mechanism. Extensive experiments demonstrate that SPEAR achieves state-of-the-art effectiveness in bypassing defenses on real-world datasets, establishing it as a potent and stealthy backdoor attack for graph-based tasks. Code is available at https://github.com/yhDing/SPEAR .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- STRAP: Spatio-Temporal Pattern Retrieval for Out-of-Distribution GeneralizationHaoyu Zhang, Wentao Zhang, Hao Miao, Xinke Jiang et al.NeurIPS 2025 · 12 citations
- LoSplit: Loss-Guided Dynamic Split for Training-Time Defense Against Graph Backdoor AttacksDi Jin, Yuxiang Zhang, Bingdao Feng, Xiaobao Wang et al.NeurIPS 2025 · 4 citations
- GRASP: Differentially Private Graph Reconstruction Defense with Structured PerturbationZhiyu Guo, Yang Liu, Xiang Ao, Qing HeKDD 2025 · 3 citations
- A2GBD: Attack-Agnostic Graph Backdoor DefenseChenxu Du, Yang Liu, Xingtong Yu, Zhuoer Xu et al.WWW 2026
Builds on14
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Understanding Global Feature Contributions With Additive Importance MeasuresIan Covert, Scott M. Lundberg, Su-In LeeNeurIPS 2020 · 476 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- AUC-oriented Graph Neural Network for Fraud DetectionMengda Huang, Yang Liu, Xiang Ao, Kuan Li et al.WWW 2022 · 114 citations
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 85 citations
Related papers
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 12 citations
- Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph ClassificationXiaobao Wang, Ruoxiao Sun, Yujun Zhang, Bingdao Feng et al.NeurIPS 2025 · 5 citations
- Clean-Label Graph Backdoor Attack in the Node Classification TaskHui Xia, Xiangwei Zhao, Rui Zhang, Shuo Xu et al.AAAI 2025 · 4 citations
- Attack by Yourself: Effective and Unnoticeable Multi-Category Graph Backdoor Attacks with Subgraph Triggers PoolJiangtong Li, Dongyi Liu, Kun Zhu, Dawei Cheng et al.NeurIPS 2025 · 4 citations
- Rethinking Graph Backdoor Attacks: A Distribution-Preserving PerspectiveZhiwei Zhang, Minhua Lin, Enyan Dai, Suhang WangKDD 2024 · 21 citations
