{"as_of":"2026-08-19T01:20:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:c37dab77804574420c1ea70f870d6f5bbe025db3f8eefb48201c51ab9d39933c","coverage":[{"denominator":57,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":57,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T11:48:09.554667Z","state":"measured"},{"denominator":57,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":57,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-18T06:34:40.430872+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2411.18648/citation-record","integrity":"/paper/2411.18648/integrity","json":"/paper/2411.18648/citation-record.json","paper":"/paper/2411.18648"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.382743Z","title":"Graph neural networks for social recommendation,","venue":null,"work_id":"1d06e5d3-12d0-4c72-bb8a-2891f330cec9","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.304935Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:1975af953cf8d1e851c7538a61bad64dafe2635f9726f1949d7b8bb33e64e95f","observation_id":"7485f764-06f4-4d73-9bbc-25c6ce4dcc5d","resolution":{"observed_at":"2026-08-12T11:48:10.387173Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.369087Z","title":"Random graph models of social networks,","venue":null,"work_id":"e4b74233-f171-4f31-9ce6-0f35344c0706","year":2002},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.310053Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:86effb93148b43aa516e6a9af1b22cd45617a6181292bf3ce817d0b7e87f4271","observation_id":"3592f5eb-80fc-4b98-9a12-903285058d8d","resolution":{"observed_at":"2026-08-12T11:48:10.373485Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.355050Z","title":"Trinajstic, Chemical graph theory","venue":null,"work_id":"068deb13-cec7-4106-8aad-ef513fd7ee71","year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.314578Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:60f8c23415baf7ae51c2a7c6f52bc776cd34e9526e354b1575c6e64e45075c37","observation_id":"90b56844-6987-48ee-aaf5-27db9c96bbed","resolution":{"observed_at":"2026-08-12T11:48:10.359605Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.341251Z","title":"Beyond homophily in graph neural networks: Current limitations and effective designs,","venue":null,"work_id":"9b3b82c4-4a89-44b3-9d33-de2f7d52a1f3","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.319342Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:0b0fe14555c864dc9f2a55d73d562d194e728932291371926b36cf7556da7f06","observation_id":"315ab3f8-a176-44fd-9e74-320d114b6108","resolution":{"observed_at":"2026-08-12T11:48:10.345730Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.326852Z","title":"Powerful graph convolutional networks with adaptive propagation mechanism for homophily and heterophily,","venue":null,"work_id":"71f47577-c8e8-4178-bbd5-88739483fff1","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.324092Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:75bd02d893bb3da609dc68b539dd1cdda933f612b100d8e2436e7f888cc2ad22","observation_id":"5197be1e-14c4-4f3e-8646-54c357756bf3","resolution":{"observed_at":"2026-08-12T11:48:10.331556Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1609.02907","last_updated":"2017-02-22T09:55:36Z","snapshot_observed_at":"2026-08-17T10:49:36.026134Z","submitted_at":"2016-09-09T19:48:41Z","title":"Semi-Supervised Classification with Graph Convolutional Networks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1609.02907","snapshot_observed_at":"2026-08-12T11:48:09.328783Z","title":"Semi-supervised classi- fication with graph convolutional networks,","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.328783Z"},"links":{"cited_paper":"/paper/1609.02907","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:79fbf5c9657ca21a8e603688f321b8bc87cd1959f6f69389e08d3ec16949f303","observation_id":"f27110b5-5bcc-401a-9a0d-5659c0afe2d2","resolution":{"observed_at":"2026-08-12T11:48:09.328783Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.334101Z","title":"Inductive representation learning on large graphs,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.334101Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:c58fbbe710fd7b2fc107b4653d7f7c39e4e2e844de918d940b6a40cada488eb9","observation_id":"3d99f80c-faa0-4fdf-98c7-a718e040f0d4","resolution":{"observed_at":"2026-08-12T11:48:09.334101Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.302740Z","title":"Gated graph sequence neural networks,","venue":null,"work_id":"ed8ca259-d558-4264-b6b1-43d55ab11dae","year":2016},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.338497Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:e3dc0e25f2ce91f6f4b38d825421a7faf356445bca5646e7415a4e385a2030de","observation_id":"627694c8-c0aa-440a-ade1-35a28106455a","resolution":{"observed_at":"2026-08-12T11:48:10.307508Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.289101Z","title":"Predicting drug–target interaction using a novel graph neural network with 3d structure-embedded graph representation,","venue":null,"work_id":"dd460066-38a5-4214-be65-fbb5086094ac","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.342952Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ef40f2a4abab2378ce5a131504c415a86fecad0d6ecfc577ef4f58fb2be9eefd","observation_id":"2c770ef9-cdbe-4a83-9684-e32f6f998387","resolution":{"observed_at":"2026-08-12T11:48:10.293617Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.274623Z","title":"Kgnn: Knowledge graph neural network for drug-drug interaction prediction","venue":null,"work_id":"73565906-b952-4faa-bc5b-5e435ae32cda","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.347434Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:d1ad054b35d49763c5b206c6bb642b346c23023f298931db4becd9e2b0a8264d","observation_id":"ffe35faa-2c8c-4f66-82f3-be5a170a3520","resolution":{"observed_at":"2026-08-12T11:48:10.279363Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.260390Z","title":"Could graph neural networks learn better molecular representation for drug discovery? a comparison study of descriptor-based and graph-based models,","venue":null,"work_id":"8411052c-81f1-4be0-b86a-0f10a54bb620","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.351605Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:c781ac3c63813a904a6f6ff3e5326d589ead6bf5e0da37610d6095b64cf0909b","observation_id":"633a7e61-ac37-440d-a759-0e16316084cf","resolution":{"observed_at":"2026-08-12T11:48:10.265143Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.246340Z","title":"Graph neural network for traffic forecasting: A survey,","venue":null,"work_id":"0634cead-3a62-4edf-9237-b839b553ca65","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.356248Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:67e4692a002fc3b099f9844ab9b03cb3e1ed324a5b66be8ac20e7aa4c10442fc","observation_id":"95bec72d-59eb-4ad5-ac9e-09ae9b1c87a6","resolution":{"observed_at":"2026-08-12T11:48:10.251041Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.232669Z","title":"Point-gnn: Graph neural network for 3d object detection in a point cloud,","venue":null,"work_id":"47906c4b-c2f0-48ed-b72d-55a744328868","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.360517Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:650a8974ede4a7816f570b651381cd18c5d1d13f5a3dee75df03a03a33b2bdf1","observation_id":"b272f3ca-fe82-4a2e-97db-2cdb2f018d78","resolution":{"observed_at":"2026-08-12T11:48:10.237081Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.218981Z","title":"Neural graph collaborative filtering,","venue":null,"work_id":"3381e3eb-b6c1-4969-9124-7e5f6dcce194","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.365039Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:b91b6179a0610adb5e505881c269dfd331e1aefb22e27ae93179bb1fecaf3948","observation_id":"a9dac2d9-94ae-4da7-8844-c7a00cff9cc5","resolution":{"observed_at":"2026-08-12T11:48:10.223544Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.203580Z","title":"Scaling graph neural networks with approxi- mate pagerank,","venue":null,"work_id":"0403bf72-368c-413b-a547-29c29b7871a8","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.369292Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:a7bcc3ca2e457d7998da3da4733f9ef8b978d292b754a554b5f9b5b6613dddb4","observation_id":"5ea2f21d-3674-490c-a62d-eca1933e6311","resolution":{"observed_at":"2026-08-12T11:48:10.209031Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1810.05997","last_updated":"2022-04-05T11:39:26Z","snapshot_observed_at":"2026-08-18T15:06:05.060057Z","submitted_at":"2018-10-14T08:36:54Z","title":"Predict then Propagate: Graph Neural Networks meet Personalized PageRank","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1810.05997","snapshot_observed_at":"2026-08-12T11:48:09.373547Z","title":"Predict then propagate: Graph neural networks meet personal- ized pagerank,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.373547Z"},"links":{"cited_paper":"/paper/1810.05997","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:6989583ed9f91c6611e8ecfb8fda51996978121308a3b556b63ebf623460af7c","observation_id":"cdb881e4-ece8-4679-9f83-30728c9d9aac","resolution":{"observed_at":"2026-08-12T11:48:09.373547Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.188741Z","title":"Graph backdoor,","venue":null,"work_id":"22079345-f9c0-4f42-9998-0a4dc021bd5a","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.378062Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:b9c13f01a682a0307c16f4ebbe576f138c55011f687c1dd7a6511f3a38aa1998","observation_id":"7a382b2d-d580-46fb-8215-ea15e39b95b9","resolution":{"observed_at":"2026-08-12T11:48:10.193153Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.174338Z","title":"Backdoor attacks to graph neural networks,","venue":null,"work_id":"13621dda-0751-4fee-8a7d-024d754cb049","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.382356Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:e5341e683d15d6f56733cbdf1bfa69335fb7cc174dacac4d06d13015fbf9a192","observation_id":"24976171-aebd-417a-b7ea-48c509edcd4b","resolution":{"observed_at":"2026-08-12T11:48:10.178936Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.159170Z","title":"Transferable graph backdoor attack,","venue":null,"work_id":"d6c0e520-65c8-4628-a9b7-b663993bb9af","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.387512Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:1da00e1e5da850927faea0ec3002ddcb0a119b42f74fdcbbde7997301b5427ca","observation_id":"b1200a99-b4ae-4b61-841d-0b156d0707c7","resolution":{"observed_at":"2026-08-12T11:48:10.164148Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.144937Z","title":"Adversarial neuron pruning purifies backdoored deep models,","venue":null,"work_id":"acb4ba9a-b5b1-4eab-8f33-88dcdc0f71e5","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.391934Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:c26ea07020277fbb1fe722b97c6fe7d586f9342f81fa2fcbf8610ba8b3094ccd","observation_id":"0a77a778-5674-48ed-8ba5-3aaf82b3eaee","resolution":{"observed_at":"2026-08-12T11:48:10.149554Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.130629Z","title":"Anti- backdoor learning: Training clean models on poisoned data,","venue":null,"work_id":"ed4e9dc9-4710-4f7e-b59a-5420dd4ac32f","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.396341Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:073dbd420aa221efe55ebd8652f79ee5564c146c4d89f8fd88df9208e87deac1","observation_id":"5f0a78dc-5741-4199-ad41-9ab2e9c77006","resolution":{"observed_at":"2026-08-12T11:48:10.135419Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2212.09067","last_updated":"2022-12-18T11:30:59Z","snapshot_observed_at":"2026-08-16T16:07:52.186532Z","submitted_at":"2022-12-18T11:30:59Z","title":"Fine-Tuning Is All You Need to Mitigate Backdoor Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2212.09067","snapshot_observed_at":"2026-08-12T11:48:09.400727Z","title":"Fine-tuning is all you need to mitigate backdoor at- tacks,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.400727Z"},"links":{"cited_paper":"/paper/2212.09067","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:0b7499b8aeca22dbd1f6959f8911dca752960358feb29affcd0940778becb537","observation_id":"3bda1cc4-d3d1-44cf-b2b0-2eab37928c83","resolution":{"observed_at":"2026-08-12T11:48:09.400727Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1409.1556","last_updated":"2015-04-10T16:25:04Z","snapshot_observed_at":"2026-08-17T19:17:06.411141Z","submitted_at":"2014-09-04T19:48:04Z","title":"Very Deep Convolutional Networks for Large-Scale Image Recognition","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1409.1556","snapshot_observed_at":"2026-08-12T11:48:09.405469Z","title":"Very deep convolu- tional networks for large-scale image recognition,","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.405469Z"},"links":{"cited_paper":"/paper/1409.1556","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:fce7e0164e8e78c3f32170857fd365584420a36c66ef7ffe326dd7009fdaac42","observation_id":"1f0640cd-0178-490c-a9ab-dfa0dba50722","resolution":{"observed_at":"2026-08-12T11:48:09.405469Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.410415Z","title":"Deep residual learning for image recognition,","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.410415Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:e51d7060f50a59d1c6ff0dd4286268807a57e16f8e432a99a9db51128994b620","observation_id":"1fa5f7e3-ca9d-4d04-9532-b308ea7426a5","resolution":{"observed_at":"2026-08-12T11:48:09.410415Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.414574Z","title":"Attention is all you need,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.414574Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:94cad7da264b7d71faf03a2979049ea7dd65feae2f6acc2a043c7569312b5c22","observation_id":"299a7c7d-a6b5-4405-a97d-fe35652c0df6","resolution":{"observed_at":"2026-08-12T11:48:09.414574Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.097196Z","title":"Spectral signatures in backdoor attacks,","venue":null,"work_id":"a1194230-ead2-452c-b557-ac333f769850","year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.418732Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:f70f57cdc08d7e5007d527bef430717f3e252c52d4cc862ac27537044b44a0b1","observation_id":"cebfe35c-1d34-4079-b531-09b7d2ef5877","resolution":{"observed_at":"2026-08-12T11:48:10.102032Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1712.05526","last_updated":"2017-12-15T04:26:26Z","snapshot_observed_at":"2026-07-06T06:14:30.795326Z","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1712.05526","snapshot_observed_at":"2026-08-12T11:48:09.422784Z","title":"Targeted backdoor attacks on deep learning systems using data poisoning,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.422784Z"},"links":{"cited_paper":"/paper/1712.05526","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:99059ef71591a536a2d535150e6aab90a48bb3e46be95656f1feb436751f77ab","observation_id":"d6c41fb2-b5f5-4883-87bc-1c8e716ad642","resolution":{"observed_at":"2026-08-12T11:48:09.422784Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1708.06733","last_updated":"2019-03-11T20:45:33Z","snapshot_observed_at":"2026-08-12T15:43:59.037380Z","submitted_at":"2017-08-22T17:31:54Z","title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1708.06733","snapshot_observed_at":"2026-08-12T11:48:09.428229Z","title":"Badnets: Iden- tifying vulnerabilities in the machine learning model supply chain,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.428229Z"},"links":{"cited_paper":"/paper/1708.06733","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:43910cdc6662ed2d0277b7f4900891bac417e26d5b670d3cc2476960f3ccc042","observation_id":"a2c95cc2-430a-457c-8f1a-5c843b53c272","resolution":{"observed_at":"2026-08-12T11:48:09.428229Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.083097Z","title":"Reflection backdoor: A natural backdoor attack on deep neural networks,","venue":null,"work_id":"feba8f9d-a403-4a1c-8443-f1702c448838","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.432727Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:89ef0a2e6c31743ee95084745724add0680a3f5887cea7cabf10d0c78d146633","observation_id":"5bf00900-bbc4-4084-ac14-12806369dc64","resolution":{"observed_at":"2026-08-12T11:48:10.087806Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.068327Z","title":"Re- thinking the reverse-engineering of trojan triggers,","venue":null,"work_id":"79db5e2a-411d-4a67-9a20-1f09190de8b7","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.437026Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:a06f45311aecb5d0184a359f6e525cafc1aaf8c6ebf689493d8343c8135f5036","observation_id":"0f7d6d8c-1da4-438d-9ad5-df652220cb3a","resolution":{"observed_at":"2026-08-12T11:48:10.073412Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.053781Z","title":"Few-shot backdoor defense using shapley estimation,","venue":null,"work_id":"6037001a-5514-4342-9d43-ef1cae85d852","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.441228Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:cc36d75b9e61f0d8ac4a811a608c90c082db24a9757429bb0895c3990cfdf6ec","observation_id":"8fc8d755-3132-4057-a19e-76acc99b2e04","resolution":{"observed_at":"2026-08-12T11:48:10.058345Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.039808Z","title":"Unnotice- able backdoor attacks on graph neural networks,","venue":null,"work_id":"3997177e-722b-48f4-972b-963a3aabf520","year":2023},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.445396Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ab1e7aa3868e0a37bcdc521bb2fc433a0e6d4d3a6e03ab50348e4504f53748bf","observation_id":"1a981ac3-9aec-4644-a8e1-0d5a6644d0dd","resolution":{"observed_at":"2026-08-12T11:48:10.044211Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.026039Z","title":"Textual backdoor attack for the text classification system,","venue":null,"work_id":"a3adc045-0f8a-45d3-90b2-8441d7083527","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.449668Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ccd735ad1d5b18cf6fec38783a5a7068aa9ff573b2ed82980b192eed75b6c57a","observation_id":"3897a9a8-de8a-431d-8a98-292098bf4070","resolution":{"observed_at":"2026-08-12T11:48:10.030581Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2110.07139","last_updated":"2021-10-14T03:54:16Z","snapshot_observed_at":"2026-08-16T17:49:27.353998Z","submitted_at":"2021-10-14T03:54:16Z","title":"Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style Transfer","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2110.07139","snapshot_observed_at":"2026-08-12T11:48:09.453816Z","title":"Mind the style of text! adversarial and backdoor attacks based on text style transfer,","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.453816Z"},"links":{"cited_paper":"/paper/2110.07139","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:7c7900de28f87257dc2f52803a460f127213118ba1b3db76c289160eed725961","observation_id":"e0ee6e92-964a-44ed-8a57-b5af50e3d613","resolution":{"observed_at":"2026-08-12T11:48:09.453816Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.010800Z","title":"A backdoor attack against lstm-based text classification systems,","venue":null,"work_id":"b299ae2b-9f32-4c0b-8a2e-e6df5aa63bec","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.458363Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:f6c739414d27cd5e02d631e2cda4295d987df636d4a71524a9b6a439be5878c1","observation_id":"f7e1401c-8d6c-4961-877f-6537396f7855","resolution":{"observed_at":"2026-08-12T11:48:10.015965Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.995546Z","title":"How does heterophily impact the robustness of graph neural networks? theoretical connections and practical implications,","venue":null,"work_id":"8ab48032-047f-4c64-9a6a-5c3199bed397","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.462650Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:fc302088b666b281e5f5e00b2b45bf318dd74912112c76be3f7095e2a8fa3841","observation_id":"7aadce62-d3d1-4bb5-81df-7a8087c8b410","resolution":{"observed_at":"2026-08-12T11:48:10.000280Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.981349Z","title":"Finding global homophily in graph neural networks when meeting heterophily,","venue":null,"work_id":"e3d9f5e1-b638-4439-8b75-04b2cc34d258","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.466836Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:064e1fbc8d1dee129bd8f0ec93e7510e4ffde9c81c25fa05814806c4d9efc8f2","observation_id":"bd2d5980-58da-483a-b78c-8ec28148c055","resolution":{"observed_at":"2026-08-12T11:48:09.985963Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.967127Z","title":"Grad-cam: Visual explanations from deep networks via gradient-based localization,","venue":null,"work_id":"b80e8e81-584d-4481-9d54-4c1e3b8640eb","year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.470983Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:75a383cc8e5bdaf3db86153cc8fa3fc5d9a56edf9a8bc2a34fac64aaf2a2894d","observation_id":"639457db-30ee-40c8-be47-e0472f2d8be7","resolution":{"observed_at":"2026-08-12T11:48:09.971886Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2202.10582","last_updated":"2022-02-18T05:00:08Z","snapshot_observed_at":"2026-08-16T17:20:24.462036Z","submitted_at":"2022-02-18T05:00:08Z","title":"Debiasing Backdoor Attack: A Benign Application of Backdoor Attack in Eliminating Data Bias","version":1},"cited_work":{"arxiv_id":"2202.10582","doi":null,"metadata_source":"pith","pith_arxiv_id":"2202.10582","snapshot_observed_at":"2026-08-12T11:48:09.663343Z","title":"Debiasing Backdoor Attack: A Benign Application of Backdoor Attack in Eliminating Data Bias","venue":"cs.CR","work_id":"3624557a-36b2-4f0f-9462-2f54fec06127","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.475323Z"},"links":{"cited_paper":"/paper/2202.10582","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:821ecef69e7a97fa86de6427c009bdcb514f3df921be8785648658077a1be093","observation_id":"85587266-037b-41ef-b1ad-ed11b470026a","resolution":{"observed_at":"2026-08-12T11:48:09.670096Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.953258Z","title":"Iam graph database reposi- tory for graph based pattern recognition and machine learning,","venue":null,"work_id":"37bc6ad0-e2c7-421e-9b57-b89a3d022df0","year":2008},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.479973Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:2a9ed33a98377fc0bbae4bda2e1ced8de8098400a82c7c50902fe70661113168","observation_id":"fc9d4e3f-ccd1-4ca8-94c4-7955d3c9ce5b","resolution":{"observed_at":"2026-08-12T11:48:09.957849Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.939048Z","title":"Protein function prediction via graph kernels,","venue":null,"work_id":"facfe6ee-94e1-4684-b7a5-973847acdfe7","year":2005},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.484128Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:d629ce4f070e65cbe6cd84dfe9aea29cf9cb6e72a38150e3b2e36bbbebf22b42","observation_id":"fc33b25d-ba7a-4523-96b7-0da3ec5d5c31","resolution":{"observed_at":"2026-08-12T11:48:09.943629Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.488440Z","title":"Automating the construction of internet portals with machine learning,","venue":null,"work_id":null,"year":2000},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.488440Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:16bd5ca8b8aaf602463e62b7e1dc65c442814738d4edce0f29f99ab6af981807","observation_id":"85d69dc5-dc92-4da4-881c-aceba0662f55","resolution":{"observed_at":"2026-08-12T11:48:09.488440Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.914957Z","title":"Collective classification in network data,","venue":null,"work_id":"198665ba-e359-43f9-9175-c49e6fe8b7e3","year":2008},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.492528Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:599e521b86321addcc18dd29a5bcbfe2688f3ec003c43169d164c3db538f6829","observation_id":"745abff6-65ad-4c80-b622-0520aa92747e","resolution":{"observed_at":"2026-08-12T11:48:09.920203Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.900791Z","title":"Open graph benchmark: Datasets for machine learning on graphs,","venue":null,"work_id":"120ffee4-d40c-4e92-a772-bffeb52c316c","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.497009Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:8cf0ab40c0c65aa921c1f388efd4ab980ba5f1c969fbf8f5229b747478d997aa","observation_id":"9d3861a7-c558-4c13-9035-b89b4ad9091c","resolution":{"observed_at":"2026-08-12T11:48:09.905626Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1907.04931","last_updated":"2020-02-16T00:42:48Z","snapshot_observed_at":"2026-08-17T15:19:05.606929Z","submitted_at":"2019-07-10T21:11:13Z","title":"GraphSAINT: Graph Sampling Based Inductive Learning Method","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1907.04931","snapshot_observed_at":"2026-08-12T11:48:09.501189Z","title":"Graphsaint: Graph sampling based induc- tive learning method,","venue":null,"work_id":null,"year":1907},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.501189Z"},"links":{"cited_paper":"/paper/1907.04931","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:7300f3827aad77b1b65321cd0f5551f3390cebc1f7f349d7f8289f2a9897ecfc","observation_id":"d6eeae10-ca14-44fc-82a6-ca82ef42c892","resolution":{"observed_at":"2026-08-12T11:48:09.501189Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.886132Z","title":"Graph informa- tion bottleneck,","venue":null,"work_id":"f039018d-dbce-416e-838c-7d685835d162","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.505640Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:e46ef8cbe0025c999ffc9538fbb6d9a8a2b5d150a186bf660f0d0302b0ef6f12","observation_id":"292197e0-1a41-4c29-b279-e26e29c36dfc","resolution":{"observed_at":"2026-08-12T11:48:09.890886Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1710.10903","last_updated":"2018-02-04T19:13:29Z","snapshot_observed_at":"2026-08-13T22:35:40.714745Z","submitted_at":"2017-10-30T12:41:12Z","title":"Graph Attention Networks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1710.10903","snapshot_observed_at":"2026-08-12T11:48:09.509714Z","title":"Graph attention networks,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.509714Z"},"links":{"cited_paper":"/paper/1710.10903","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:2d29036e4e43ff8db1fb1bfc13e37ee444035c20ab147ac1f94c6ec00a6658fb","observation_id":"94f8c77a-f4d7-4f86-a0fa-bd1a1e393343","resolution":{"observed_at":"2026-08-12T11:48:09.509714Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1808.10307","last_updated":"2018-08-30T14:13:39Z","snapshot_observed_at":"2026-08-14T18:35:07.398380Z","submitted_at":"2018-08-30T14:13:39Z","title":"Backdoor Embedding in Convolutional Neural Network Models via Invisible Perturbation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1808.10307","snapshot_observed_at":"2026-08-12T11:48:09.514129Z","title":"Backdoor embedding in convolutional neural net- work models via invisible perturbation,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.514129Z"},"links":{"cited_paper":"/paper/1808.10307","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:75c81b36a32a193d570b9a50bece3ecc9f06a79e10edd969bb4d2bd114788863","observation_id":"d82b4d8d-374a-4e84-8b27-50f6a59a38ec","resolution":{"observed_at":"2026-08-12T11:48:09.514129Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.870935Z","title":"Clean-label backdoor attacks on video recognition models,","venue":null,"work_id":"264535fc-dc69-4492-9414-eea731d0df96","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.518506Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:28d86ca170ce36fc2f88df1462c6666b202c75d20641c7bb8ee1d268ffb63e4c","observation_id":"65bad140-d3f6-4300-8e4b-ca2f3e8183bb","resolution":{"observed_at":"2026-08-12T11:48:09.875993Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2202.03423","last_updated":"2022-02-05T03:34:01Z","snapshot_observed_at":"2026-08-16T17:23:28.157097Z","submitted_at":"2022-02-05T03:34:01Z","title":"Backdoor Defense via Decoupling the Training Process","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2202.03423","snapshot_observed_at":"2026-08-12T11:48:09.522831Z","title":"Backdoor defense via decoupling the training process,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.522831Z"},"links":{"cited_paper":"/paper/2202.03423","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:f5fad29e3f33dd8b3dee48b63f345046327bf2d48e865b03d9a58ba7c193c71e","observation_id":"1440e17b-67f1-4c5f-b6c5-9c2d135720e1","resolution":{"observed_at":"2026-08-12T11:48:09.522831Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2209.02902","last_updated":"2022-09-07T03:19:29Z","snapshot_observed_at":"2026-08-16T16:34:17.214863Z","submitted_at":"2022-09-07T03:19:29Z","title":"Defending Against Backdoor Attack on Graph Nerual Network by Explainability","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2209.02902","snapshot_observed_at":"2026-08-12T11:48:09.527428Z","title":"Defending against backdoor attack on graph nerual network by explainability,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.527428Z"},"links":{"cited_paper":"/paper/2209.02902","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:196a950a1e64319e8910df4f6127171cbf78737b7d09c2109822444c68ef4396","observation_id":"79e395ad-2347-48cf-9661-f0bccdbb6e99","resolution":{"observed_at":"2026-08-12T11:48:09.527428Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.855763Z","title":"Svd-gcn: A simpli- fied graph convolution paradigm for recommendation,","venue":null,"work_id":"32aacc8d-5eee-4a33-b1d2-45eca186a69e","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.532309Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:9f340999876523b061746075f9342cd4dae4eb6be40e6732832bb712070904d9","observation_id":"8c77ebb2-2302-42d5-95b7-c373cb296d77","resolution":{"observed_at":"2026-08-12T11:48:09.860865Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.840194Z","title":"In this paper, the experiment JOURNAL OF LATEX CLASS FILES, VOL","venue":null,"work_id":"96772a61-ae07-40bb-a423-a2ced6407a49","year":2015},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.536986Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:1659d33911ed78040151380e8da32f17c8c42146f47fb966b943277df904d3ea","observation_id":"9eff147a-48c5-4e6e-bea4-c8f32cfe367a","resolution":{"observed_at":"2026-08-12T11:48:09.844923Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.824877Z","title":null,"venue":null,"work_id":"cb34e54e-1142-440b-b05b-5d7e19f4faf8","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.541005Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:38a0c1a4be7bf7a999ca87f058af07fd6518585b63b49c7997b76c8d596a2b37","observation_id":"13456e22-de08-4569-974a-2bc8a0b361dd","resolution":{"observed_at":"2026-08-12T11:48:09.829579Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.810401Z","title":"For typical graph defense methods,","venue":null,"work_id":"38bc31fb-c470-4687-b1ed-bbdcd1f4065b","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.545763Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:36d1f4b10646d2211a81f19976cee33bc5eef1a7ba8d7693eadae6c3561645b7","observation_id":"146ed87f-c684-447d-994e-191c3c603bc5","resolution":{"observed_at":"2026-08-12T11:48:09.815073Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.795620Z","title":null,"venue":null,"work_id":"1a844e50-4bda-4e7c-8a81-f631a1618a90","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.550242Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:684ecd9b93b34068d85577654f64195efc44648508bba0254b018f6be76993cc","observation_id":"7596040f-fc68-4881-8a53-967310863afe","resolution":{"observed_at":"2026-08-12T11:48:09.800475Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.780795Z","title":"This modification aims to concentrate solely on the features associated with the K-largest singular vectors, thereby enhancing the model’s robustness to perturbations","venue":null,"work_id":"c004a922-114f-4ce7-956c-87e1d09892f9","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.554667Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:15afeca1d85b22c23013a56004a9279d4e77aac7725dfb0513532ef4acbc943d","observation_id":"6c17c3b3-fba9-474b-8eba-cf64cb53e313","resolution":{"observed_at":"2026-08-12T11:48:09.785514Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-18T06:34:40.430872+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-18T09:13:53.538381Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning"},"reference_resolution":{"displayed":57,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":18,"verified_exact":1,"verified_fuzzy":38},"total_outbound_references":57},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-18T06:34:40.430872+00:00","source":"crossref"},{"observed_at":"2026-08-18T06:34:34.496301+00:00","source":"retraction_watch"}],"thesis":"As of 19 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 0 inbound Pith citation observations for arXiv:2411.18648."}