Skip to content

Collateral Damage Constrained Backdoor Attacks on Graph Neural Networks

· 0 citations · 33 references

TL;DR

The proposed Collateral Damage Constrained Graph Backdoor Attack (CDCA) combines neighborhood-aware target node selection with a self-constrained trigger generation strategy to suppress trigger-induced propagation by enforcing prediction consistency on clean K -hop neighboring nodes.

View source

Similar papers

2025

LoSplit: Loss-Guided Dynamic Split for Training-Time Defense Against Graph Backdoor Attacks

LoSplit is proposed, the first training-time defense framework in graph that leverages this early-stage loss drift to accurately split target nodes, and dynamically selects epochs with maximal loss divergence, clusters target nodes via Gaussian Mixture Models, and applies a Decoupling-Forgetting strategy to break the association between target nodes and malicious label.

Di Jin, Yuxiang Zhang, Bingdao Feng et al. · 4 citations
Jul 2026

Evolutionary graph structure learning for adversarial defense in GNNs

This research introduces a new graph adversarial attack protection approach termed evolutionary algorithm integration of neighbor importance estimate to tackle this issue and attains notably superior performance in comparison to alternative defense methodologies.

Hong Pan, Jingwei Guo, Liang Cheng et al. · 0 citations
Preprint Aug 2026

Cognitive Graph Intelligence for Adaptive and Robust DDoS Attack Detection in Next Generation Networks

By integrating temporal graph construction, adversarial augmentation, and GCN classification, GraphGAN effectively models coordinated attack behaviors and mitigates class imbalance, providing a robust and topology-aware solution for intrusion detection in data-constrained environments.

Mohammad Arif Hossain, Yeahia Sarker, Md Jafrin Hossain et al. · 0 citations
Jul 2026

Chameleon: Backdoor Attacks With Restoration-Based Triggers Using Diffusion Models.

Deep neural networks (DNNs) are vulnerable to backdoor attacks, where the backdoored models behave normally on benign samples but misclassify trigger-carrying samples. However, when triggers are introduced as external cues inconsistent with original images, the resulting distribution shift makes existing backdoor attacks vulnerable to defenses based on abnormal latent representation detection. We propose Chameleon, a backdoor attack framework that reformulates sample-specific trigger generation as the restoration of a salient masked region. Chameleon combines diffusion-based image restoration guided by surrounding context with saliency-based mask positioning to generate semantically consistent triggers that are less separable from benign samples in latent space. We compare Chameleon with five baseline attacks on three datasets under six state-of-the-art backdoor defense methods, that is, STRIP, SentiNet, RNP, CCA-UD, SCAn, and Beatrix. Experimental results demonstrate that Chameleon achieves a 28.42% higher effective attack success rate (E-ASR) (i.e., successful attacks that evade defenses) compared to the best baseline when averaged across all defenses.

Boyang Zhou, Yixin He, Xiaofu Chen et al. · 0 citations
Preprint Aug 2026

Mitigating Backdoors via Decoy Shortcuts and Knowledge Decoupling

This work reveals that backdoor behaviors tend to be absorbed by a simpler parallel branch when jointly trained with the main network, and proposes Trapping and Removing (TR), a simple yet effective training-time defense that introduces a lightweight shortcut branch as a "honeypot" to trap backdoor knowledge.

Zixuan Zhu, Rui Wang, Lihua Jing et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.