Collateral Damage Constrained Backdoor Attacks on Graph Neural Networks
The proposed Collateral Damage Constrained Graph Backdoor Attack (CDCA) combines neighborhood-aware target node selection with a self-constrained trigger generation strategy to suppress trigger-induced propagation by enforcing prediction consistency on clean K -hop neighboring nodes.
Di Jin, Ze-Chuan Zhang, Bingdao Feng et al.
· 0 citations