Pith. sign in

REVIEW 3 cited by

Robustness Inspired Graph Backdoor Defense

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2406.09836 v2 pith:3H7SCJXF submitted 2024-06-14 cs.LG cs.CR

classification cs.LGcs.CR
keywords backdoorgraphattacksnodespoisonedclassificationcleandefending
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Graph Neural Networks (GNNs) have achieved promising results in tasks such as node classification and graph classification. However, recent studies reveal that GNNs are vulnerable to backdoor attacks, posing a significant threat to their real-world adoption. Despite initial efforts to defend against specific graph backdoor attacks, there is no work on defending against various types of backdoor attacks where generated triggers have different properties. Hence, we first empirically verify that prediction variance under edge dropping is a crucial indicator for identifying poisoned nodes. With this observation, we propose using random edge dropping to detect backdoors and theoretically show that it can efficiently distinguish poisoned nodes from clean ones. Furthermore, we introduce a novel robust training strategy to efficiently counteract the impact of the triggers. Extensive experiments on real-world datasets show that our framework can effectively identify poisoned nodes, significantly degrade the attack success rate, and maintain clean accuracy when defending against various types of graph backdoor attacks with different properties.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Boosting Graph Robustness Against Backdoor Attacks: An Over-Similarity Perspective

    cs.LG 2025-02 conditional novelty 6.0 of 10

    SimGuard detects graph backdoor triggers by exploiting their mutual feature and structural similarity, detecting and removing them during both training and inference.

  2. Fine-tuning is Not Fine: Mitigating Backdoor Attacks in GNNs with Limited Clean Data

    cs.LG 2025-01 conditional novelty 6.0 of 10

    GraphNAD uses degree-weighted graph attention transfer plus layer-relation congruence to distill backdoored GNNs on 3% clean data and lower attack success rate below 5%.

  3. Stealing Training Graphs from Graph Neural Networks

    cs.LG 2024-11 conditional novelty 6.0 of 10

    A white-box attack called GraphSteal reconstructs exact training molecules from a trained GNN by generating candidates with a diffusion model and selecting those whose gradients best explain the model parameters.

Pith tools