{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,29]],"date-time":"2025-11-29T07:58:40Z","timestamp":1764403120550,"version":"3.40.3"},"publisher-location":"Cham","reference-count":45,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030926373"},{"type":"electronic","value":"9783030926380"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-92638-0_17","type":"book-chapter","created":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T13:02:45Z","timestamp":1641042165000},"page":"276-296","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Backdoor Attack of Graph Neural Networks Based on Subgraph Trigger"],"prefix":"10.1007","author":[{"given":"Yu","family":"Sheng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rong","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guanyu","family":"Cai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Li","family":"Kuang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,1,1]]},"reference":[{"key":"17_CR1","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Oprea, A., Biggio, B., et al.: Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In: 2018 IEEE Symposium on Security and Privacy (SP). IEEE, 19\u201335 (2018)","DOI":"10.1109\/SP.2018.00057"},{"key":"17_CR2","unstructured":"Shafahi, A., Huang, W.R., Najibi, M., et al.: Poison frogs! targeted clean-label poisoning attacks on neural networks. arXiv preprint arXiv:1804.00792 (2018)"},{"key":"17_CR3","unstructured":"Demontis, A., Melis, M., Pintor, M., et al.: Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In: 28th {USENIX} Security Symposium ({USENIX} Security 19), pp. 321\u2013338 (2019)"},{"key":"17_CR4","unstructured":"Wang, Y., Chaudhuri, K.: Data poisoning attacks against online learning. arXiv preprint arXiv:1808.08994 (2018)"},{"key":"17_CR5","unstructured":"Steinhardt, J., Koh, P.W., Liang, P.: Certified defenses for data poisoning attacks. arXiv preprint arXiv:1706.03691 (2017)"},{"key":"17_CR6","unstructured":"Basu, S., Izmailov, R., Mesterharm, C.: Membership model inversion attacks for deep networks. arXiv preprint arXiv:1910.04257 (2019)"},{"key":"17_CR7","doi-asserted-by":"crossref","unstructured":"Song, C., Ristenpart, T., Shmatikov, V.: Machine learning models that remember too much. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 587\u2013601 (2017)","DOI":"10.1145\/3133956.3134077"},{"issue":"2133","key":"17_CR8","first-page":"20180083","volume":"376","author":"M Veale","year":"2018","unstructured":"Veale, M., Binns, R., Edwards, L.: Algorithms that remember: model inversion attacks and data protection law. Philos. Trans. Royal Soc. Math. Phys. Eng. Sci. 376(2133), 20180083 (2018)","journal-title":"Philos. Trans. Royal Soc. Math. Phys. Eng. Sci."},{"key":"17_CR9","doi-asserted-by":"crossref","unstructured":"Romagnoli, R., Weerakkody, S., Sinopoli, B.: A model inversion based watermark for replay attack detection with output tracking. In: 2019 American Control Conference (ACC). IEEE, pp. 384\u2013390 (2019)","DOI":"10.23919\/ACC.2019.8814483"},{"key":"17_CR10","doi-asserted-by":"crossref","unstructured":"Wang, B., Gong, N.Z.: Stealing hyperparameters in machine learning. In: 2018 IEEE Symposium on Security and Privacy (SP). IEEE, pp. 36\u201352 (2018)","DOI":"10.1109\/SP.2018.00038"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., et al.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506\u2013519 (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Orekondy, T., Schiele, B., Fritz, M.: Knockoff nets: Stealing functionality of black-box models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4954\u20134963 (2019)","DOI":"10.1109\/CVPR.2019.00509"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"Correia-Silva, J.R., Berriel, R.F, Badue, C., et al.: Copycat cnn: Stealing knowledge by persuading confession with random non-labeled data. In: 2018 International Joint Conference on Neural Networks (IJCNN). IEEE, pp. 1\u20138 (2018)","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"17_CR14","unstructured":"Launchbury, J.: A DARPA Perspective on Artificial Intelligence. 11 (2019). Accessed November 2017"},{"key":"17_CR15","unstructured":"Li, H., Wang, Y., Xie, X., et al.: Light can hack your face! black-box backdoor attack on face recognition systems. arXiv preprint arXiv:2009.06996 (2020)"},{"key":"17_CR16","doi-asserted-by":"crossref","unstructured":"Zhao, S., Ma, X., Zheng, X., et al.: Clean-label backdoor attacks on video recognition models. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 14443\u201314452 (2020)","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"17_CR17","unstructured":"Sun, L.: Natural backdoor attack on text data. arXiv preprint arXiv:2006.16176 (2020)"},{"key":"17_CR18","doi-asserted-by":"publisher","first-page":"138872","DOI":"10.1109\/ACCESS.2019.2941376","volume":"7","author":"J Dai","year":"2019","unstructured":"Dai, J., Chen, C., Li, Y.: A backdoor attack against LSTM-based text classification systems. IEEE Access 7, 138872\u2013138878 (2019)","journal-title":"IEEE Access"},{"key":"17_CR19","unstructured":"Chen, X., Liu, C., Li, B., et al.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"17_CR20","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"17_CR21","doi-asserted-by":"crossref","unstructured":"Lin, Y., Zhao, H., Tu, Y., et al.: Threats of adversarial attacks in DNN-based modulation recognition. In: IEEE INFOCOM 2020-IEEE Conference on Computer Communications. IEEE, pp. 2469\u20132478 (2020)","DOI":"10.1109\/INFOCOM41043.2020.9155389"},{"key":"17_CR22","doi-asserted-by":"crossref","unstructured":"Goswami, G., Ratha, N., Agarwal, A., et al.: Unravelling robustness of deep learning based face recognition against adversarial attacks. In: Proceedings of the AAAI Conference on Artificial Intelligence, 32(1) (2018)","DOI":"10.1609\/aaai.v32i1.12341"},{"key":"17_CR23","doi-asserted-by":"crossref","unstructured":"Dong, Y., Su, H., Wu, B., et al.: Efficient decision-based black-box adversarial attacks on face recognition. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 7714\u20137722 (2019)","DOI":"10.1109\/CVPR.2019.00790"},{"key":"17_CR24","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6, 14410\u201314430 (2018)","journal-title":"IEEE Access"},{"issue":"3","key":"17_CR25","first-page":"1","volume":"11","author":"WE Zhang","year":"2020","unstructured":"Zhang, W.E., Sheng, Q.Z., Alhazmi, A., et al.: Adversarial attacks on deep-learning models in natural language processing: a survey. ACM Trans. Intell. Syst. Technol. (TIST) 11(3), 1\u201341 (2020)","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"key":"17_CR26","doi-asserted-by":"crossref","unstructured":"Morris, J., Lifland, E., Yoo, J.Y., et al.: TextAttack: a framework for adversarial attacks, data augmentation, and adversarial training in NLP. In: Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing: System Demonstrations, pp. 119\u2013126 (2020)","DOI":"10.18653\/v1\/2020.emnlp-demos.16"},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Behjati, M., Moosavi-Dezfooli, S.M., Baghshah, M.S., et al.: Universal adversarial attacks on text classifiers. In: ICASSP 2019\u20132019 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, pp. 7345\u20137349 (2019)","DOI":"10.1109\/ICASSP.2019.8682430"},{"key":"17_CR28","unstructured":"Sun, L., Dou, Y., Yang, C., et al.: Adversarial attack and defense on graph data: a survey. arXiv preprint arXiv:1812.10528 (2018)"},{"key":"17_CR29","unstructured":"Chen, L., Li, J., Peng, J., et al.: A survey of adversarial learning on graphs. arXiv preprint arXiv:2003.05730 (2020)"},{"key":"17_CR30","unstructured":"Dai, H., Li, H., Tian, T., et al.: Adversarial attack on graph structured data. In: International Conference on Machine Learning, PMLR, pp. 1115\u20131124 (2018)"},{"key":"17_CR31","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., et al.: Badnets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"key":"17_CR32","unstructured":"Li, Y., Wu, B., Jiang, Y., et al.: Backdoor learning: a survey. arXiv preprint arXiv:2007.08745 (2020)"},{"key":"17_CR33","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., et al.: How to backdoor federated learning. In: International Conference on Artificial Intelligence and Statistics. PMLR, 2938\u20132948 (2020)"},{"key":"17_CR34","unstructured":"Sun, Z., Kairouz, P., Suresh, A.T., et al.: Can you really backdoor federated learning?. arXiv preprint arXiv:1911.07963 (2019)"},{"key":"17_CR35","unstructured":"Wang, H., Sreenivasan, K., Rajput, S., et al.: Attack of the tails: yes, you really can backdoor federated learning. arXiv preprint arXiv:2007.05084 (2020)"},{"key":"17_CR36","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., Akbarnejad, A., G\u00fcnnemann, S.: Adversarial attacks on neural networks for graph data. In: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 2847\u20132856 (2018)","DOI":"10.1145\/3219819.3220078"},{"key":"17_CR37","unstructured":"Ma, Y., Wang, S., Derr, T., et al.: Attacking graph convolutional networks via rewiring. arXiv preprint arXiv:1906.03750 (2019)"},{"key":"17_CR38","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Jia, J., Wang, B., et al.: Backdoor attacks to graph neural networks. arXiv preprint arXiv:2006.11165 (2020)","DOI":"10.1145\/3450569.3463560"},{"key":"17_CR39","unstructured":"Xi, Z., Pang, R., Ji, S., et al.: Graph backdoor. In: 30th {USENIX} Security Symposium ({USENIX} Security 21) (2021)"},{"key":"17_CR40","unstructured":"Ma, J., Ding, S., Mei, Q.: Towards more practical adversarial attacks on graph neural networks. arXiv preprint arXiv:2006.05057 (2020)"},{"key":"17_CR41","doi-asserted-by":"crossref","unstructured":"Takahashi, T.: Indirect adversarial attacks via poisoning neighbors for graph convolutional networks. In: 2019 IEEE International Conference on Big Data (Big Data). IEEE, 1395\u20131400 (2019)","DOI":"10.1109\/BigData47090.2019.9006004"},{"key":"17_CR42","doi-asserted-by":"publisher","first-page":"121538","DOI":"10.1016\/j.physa.2019.121538","volume":"529","author":"H Mo","year":"2019","unstructured":"Mo, H., Deng, Y.: Identifying node importance based on evidence theory in complex networks. Physica A: Stat. Mech. Appl. 529, 121538 (2019)","journal-title":"Physica A: Stat. Mech. Appl."},{"key":"17_CR43","doi-asserted-by":"publisher","first-page":"105606","DOI":"10.1016\/j.asoc.2019.105606","volume":"83","author":"L Ma","year":"2019","unstructured":"Ma, L., Liu, Y.: Maximizing three-hop influence spread in social networks using discrete comprehensive learning artificial bee colony optimizer. Appl. Soft Comput. 83, 105606 (2019)","journal-title":"Appl. Soft Comput."},{"key":"17_CR44","doi-asserted-by":"crossref","unstructured":"Xu, J., Picek, S.: Explainability-based backdoor attacks against graph neural networks. arXiv preprint arXiv:2104.03674 (2021)","DOI":"10.1145\/3468218.3469046"},{"issue":"4","key":"17_CR45","doi-asserted-by":"publisher","first-page":"1141","DOI":"10.1214\/aoms\/1177706098","volume":"30","author":"EN Gilbert","year":"1959","unstructured":"Gilbert, E.N.: Random graphs. Ann. Math. Stat. 30(4), 1141\u20131144 (1959)","journal-title":"Ann. Math. Stat."}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Collaborative Computing: Networking, Applications and Worksharing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-92638-0_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,21]],"date-time":"2023-01-21T12:19:19Z","timestamp":1674303559000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-92638-0_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030926373","9783030926380"],"references-count":45,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-92638-0_17","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"1 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CollaborateCom","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Collaborative Computing: Networking, Applications and Worksharing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 October 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 October 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"colcom2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/collaboratecom.eai-conferences.org\/2021\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confy +","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"206","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"62","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}