Skip to content
Open access

An Explainable CS-Mitigation Triangular (ECSMT) Framework to Secure Graph Neural Networks

Jul 2026 · Electronics · Vol 15, pp. 2967 · 0 citations · 7 references

TL;DR

This study indicates that the proposed triangular mitigation strategy offers a valuable, scalable blueprint for enhancing the technical resilience and prognostic economic modeling of critical infrastructure networks.

Abstract

This research addresses cyber risk by defending against backdoor attacks on Graph Neural Networks (GNNs). We propose the Explainable Complex System-Mitigation Triangular (ECSMT) Framework, which integrates Robust Training, Graph Regularization, and Data Sanitization into a lightweight, hardware-efficient defense layer. To evaluate structural generalizability, we conducted empirical evaluations across three distinct benchmark domains (AIDS, MUTAG, and PROTEINS) using a Graph Isomorphism Network (GIN) backbone. Under a baseline 5% backdoor subgraph trigger injection ratio, ECSMT achieves excellent utility retention, securing a Clean Accuracy (CA) of 97.33% (±0.62%) while reducing the Attack Success Rate (ASR) from 97.00% down to 69.45% on the primary AIDS benchmark. Cross-domain testing reveals that defensive efficacy is strongly constrained by dataset characteristics: small-scale datasets such as MUTAG suffer from persistent trigger concentration, while complex graph manifolds such as PROTEINS exhibit high levels of topological noise. Furthermore, mapping these technical outcomes into an enterprise asset framework yields a 61% expenditure compression at critical technological feeder locations and a 98.93% reduction in total systemic loss. This study indicates that the proposed triangular mitigation strategy offers a valuable, scalable blueprint for enhancing the technical resilience and prognostic economic modeling of critical infrastructure networks.

Read PDF

Similar papers

Collateral Damage Constrained Backdoor Attacks on Graph Neural Networks

The proposed Collateral Damage Constrained Graph Backdoor Attack (CDCA) combines neighborhood-aware target node selection with a self-constrained trigger generation strategy to suppress trigger-induced propagation by enforcing prediction consistency on clean K -hop neighboring nodes.

Di Jin, Ze-Chuan Zhang, Bingdao Feng et al. · 0 citations
Book Open access Aug 2026

Defending against Model Extraction for GNNs with Model Reprogramming

Graph Neural Networks (GNNs) serve as the backbone for high-stakes applications in Machine-Learning-as-a-Service (MLaaS). Still, their black-box deployment exposes them to Model Extraction (ME) attacks, in which adversaries steal intellectual property by querying APIs. Existing defenses suffer from a critical ''Euclidean bias'': they transfer image-based strategies (e.g., random noise) to graphs, ignoring the complex topological dependencies between nodes, which often results in severe utility degradation. Passive methods like watermarking also fail to prevent theft in real time. To bridge this gap, we propose GraphRP (Graph Reprogramming Protection), a proactive defense framework that repurposes Model Reprogramming for security. Unlike static perturbations, GraphRP introduces a Structure-Aware Gating Mechanism driven by learnable topological prototypes. This creates a dynamic ''structural firewall'' that selectively modulates the model's decision boundary: it preserves fidelity for benign queries residing on the training manifold, while maximizing the Fisher Information along the perturbation direction for adversarial queries. Under standard assumptions (bounded loss, optimal attacker, and local second-order approximation), we prove a lower bound on the attacker's estimation error that increases with the structural sensitivity of the reprogramming noise. Extensive experiments on both hard-label and soft-label ME attacks demonstrate that GraphRP significantly degrades attack effectiveness while preserving benign utility.

Yan Wen, Zhenyi Wang, Heng Huang · 0 citations
Jul 2026

Evolutionary graph structure learning for adversarial defense in GNNs

This research introduces a new graph adversarial attack protection approach termed evolutionary algorithm integration of neighbor importance estimate to tackle this issue and attains notably superior performance in comparison to alternative defense methodologies.

Hong Pan, Jingwei Guo, Liang Cheng et al. · 0 citations
Preprint Aug 2026

Are LLM-Enhanced GNNs Privacy-Safe?

A systematic evaluation of privacy risks in LLM-enhanced GNNs through a unified framework consisting of five stages and reveals that semantic enrichment amplifies link-, label-, and membership-related signals in the embedding space, making them more exploitable by inference attacks.

Longzhu He, Zekun Wen, Chaozhuo Li et al. · 0 citations
Open access Aug 2026

A Hybrid Z-Isomorphic GNN Framework for Robust DDoS Attack Detection in Software-Defined Networks

Abstract Although SDN provides a programmable, centrally managed framework for modern networks, that same centralization leaves it exposed to attacks such as Distributed Denial of Service (DDoS). This paper proposes an intrusion detection framework that couples Z-Isomorphic Sigmoid Graph Neural Networks (ZIS-GNN) with Bonobo-Optimization-based (EKPC-BOA) feature selection. The sigmoid-based activation strengthens the graph representation relative to conventional GNNs, capturing complex traffic patterns more faithfully, while the hybrid selector – combining the Bonobo Optimization Algorithm with an entropy score and Pearson correlation – distils the most informative features from the traffic data and thereby improves both efficiency and accuracy. Experiments demonstrate that the proposed ZIS-GNN+EKPC-BOA model attains an accuracy of 97.36%, a precision of 97.37%, and an F1-score of 97.58%, outperforming baseline models such as DNN (89.60%), LSTM (91.68%), BiLSTM (93.77%), and GNN (95.86%), as well as the standard graph baselines GCN (96.18%) and the attention-based GAT (96.58%). The results show the effectiveness of combining graph-based learning with hybrid feature selection for intrusion detection in SDN.

Zahir Mulani, Suhasini Vijaykumar, Priya Chandran · 0 citations
Open access Sep 2026

Privacy-Preserving and Fair Training for Federated GNN

Graph neural networks (GNNs) have become a dominant paradigm for learning over graph-structured data. To protect data privacy in distributed graph settings, federated GNNs have emerged as a promising solution by enabling collaborative model training without raw data sharing. However, recent studies demonstrate that federated GNNs can inherit and even amplify biases from distributed data, resulting in unfair global models. While state-of-the-art (SOTA) approaches have introduced fairness-aware federated GNN frameworks, they overlook the privacy risks arising from client–server communications during training. To address this gap, we propose SaFeGNN, a Secure and Fair Federated Graph Neural Network framework that jointly enforces privacy protection and fairness guarantees. SaFeGNN secures the communication process via additive secret sharing and client-level differential privacy, achieving stronger security guarantees compared to existing solutions. Experimental results show that SaFeGNN maintains performance close to that of the baseline, with only an additional overhead of 2.7 s and 3.6 MB per global round.

Jia-Qiang Chen, Zhang He, Xiaoning Liu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.