SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor Attacks
Yuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen, Qing He, Xiang Ao
摘要
Graph Neural Networks (GNNs) are vulnerable to backdoor attacks, where adversaries implant malicious triggers to manipulate model predictions. Existing graph backdoor attacks are susceptible to defense mechanisms or robust classifiers because they rely on subgraph injection or structural perturbations, e.g., creating additional edges to attach backdoor triggers to the original graph. To enhance the stealthiness of graph backdoors, we propose SPEAR, a novel structure-preserving graph backdoor attack that avoids modifying the graph's topology. SPEAR operates within a limited attack budget by selectively perturbing node attributes while ensuring the triggers exert significant influence through a global importance-driven feature selection strategy. Additionally, a neighborhood-aware trigger generator is employed to underpin a high attack success rate by utilizing semantic information from the neighborhood. SPEAR amplifies effectiveness and stealthiness by combining subtle yet impactful attribute manipulation with a refined trigger generation mechanism. Extensive experiments demonstrate that SPEAR achieves state-of-the-art effectiveness in bypassing defenses on real-world datasets, establishing it as a potent and stealthy backdoor attack for graph-based tasks. Code is available at https://github.com/yhDing/SPEAR .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- STRAP: Spatio-Temporal Pattern Retrieval for Out-of-Distribution GeneralizationHaoyu Zhang, Wentao Zhang, Hao Miao, Xinke Jiang 等NeurIPS 2025 · 被引用 12 次
- LoSplit: Loss-Guided Dynamic Split for Training-Time Defense Against Graph Backdoor AttacksDi Jin, Yuxiang Zhang, Bingdao Feng, Xiaobao Wang 等NeurIPS 2025 · 被引用 4 次
- GRASP: Differentially Private Graph Reconstruction Defense with Structured PerturbationZhiyu Guo, Yang Liu, Xiang Ao, Qing HeKDD 2025 · 被引用 3 次
- A2GBD: Attack-Agnostic Graph Backdoor DefenseChenxu Du, Yang Liu, Xingtong Yu, Zhuoer Xu 等WWW 2026
它引用的顶会 Paper14
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong 等NeurIPS 2020 · 被引用 3,935 次
- Understanding Global Feature Contributions With Additive Importance MeasuresIan Covert, Scott M. Lundberg, Su-In LeeNeurIPS 2020 · 被引用 476 次
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 被引用 416 次
- AUC-oriented Graph Neural Network for Fraud DetectionMengda Huang, Yang Liu, Xiang Ao, Kuan Li 等WWW 2022 · 被引用 114 次
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 被引用 85 次
相关 Paper
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 被引用 12 次
- Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph ClassificationXiaobao Wang, Ruoxiao Sun, Yujun Zhang, Bingdao Feng 等NeurIPS 2025 · 被引用 5 次
- Clean-Label Graph Backdoor Attack in the Node Classification TaskHui Xia, Xiangwei Zhao, Rui Zhang, Shuo Xu 等AAAI 2025 · 被引用 4 次
- Attack by Yourself: Effective and Unnoticeable Multi-Category Graph Backdoor Attacks with Subgraph Triggers PoolJiangtong Li, Dongyi Liu, Kun Zhu, Dawei Cheng 等NeurIPS 2025 · 被引用 4 次
- Rethinking Graph Backdoor Attacks: A Distribution-Preserving PerspectiveZhiwei Zhang, Minhua Lin, Enyan Dai, Suhang WangKDD 2024 · 被引用 21 次
