{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T15:59:12Z","timestamp":1780675152953,"version":"3.54.1"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031804076","type":"print"},{"value":"9783031804083","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T00:00:00Z","timestamp":1733702400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T00:00:00Z","timestamp":1733702400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-80408-3_10","type":"book-chapter","created":{"date-parts":[[2024,12,12]],"date-time":"2024-12-12T10:29:30Z","timestamp":1733999370000},"page":"149-174","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Benchmarking Backdoor Attacks on\u00a0Graph Convolution Neural Networks: A Comprehensive Analysis of\u00a0Poisoning Techniques"],"prefix":"10.1007","author":[{"given":"Rupesh Raj","family":"Karn","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ozgur","family":"Sinanoglu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Alrahis, L., et al.: MaliGNNoma: GNN-based malicious circuit classifier for secure cloud FPGAs. In: 2024 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), pp. 383\u2013393. IEEE (2024)","DOI":"10.1109\/HOST55342.2024.10545411"},{"issue":"10","key":"10_CR2","doi-asserted-by":"publisher","first-page":"2822","DOI":"10.1109\/TC.2023.3271126","volume":"72","author":"L Alrahis","year":"2023","unstructured":"Alrahis, L., Patnaik, S., Hanif, M.A., Shafique, M., Sinanoglu, O.: PoisonedGNN: backdoor attack on graph neural networks-based hardware security systems. IEEE Trans. Comput. 72(10), 2822\u20132834 (2023)","journal-title":"IEEE Trans. Comput."},{"key":"10_CR3","doi-asserted-by":"crossref","unstructured":"Alrahis, L., Sinanoglu, O.: Graph neural networks for hardware vulnerability analysis\u2013can you trust your GNN? In: 2023 IEEE 41st VLSI Test Symposium (VTS), pp.\u00a01\u20134. IEEE (2023)","DOI":"10.1109\/VTS56346.2023.10140095"},{"key":"10_CR4","volume-title":"Pattern Recognition and Machine Learning","author":"CM Bishop","year":"2006","unstructured":"Bishop, C.M., Nasrabadi, N.M.: Pattern Recognition and Machine Learning, vol. 4. Springer, New York (2006)"},{"key":"10_CR5","doi-asserted-by":"crossref","unstructured":"Dai, E., Lin, M., Zhang, X., Wang, S.: Unnoticeable backdoor attacks on graph neural networks. In: Proceedings of the ACM Web Conference 2023, pp. 2263\u20132273 (2023)","DOI":"10.1145\/3543507.3583392"},{"key":"10_CR6","unstructured":"(DGL), D.G.L.: Blitz introduction to DGL (2024). https:\/\/www.dgl.ai\/dgl_docs\/en\/2.3.x\/tutorials\/blitz\/1_introduction.html. Accessed 06 Sept 2024"},{"key":"10_CR7","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1016\/j.ymeth.2020.08.004","volume":"192","author":"Y Ding","year":"2021","unstructured":"Ding, Y., Tian, L.P., Lei, X., Liao, B., Wu, F.X.: Variational graph auto-encoders for miRNA-disease association prediction. Methods 192, 25\u201334 (2021)","journal-title":"Methods"},{"key":"10_CR8","unstructured":"Goodfellow, I.: Deep learning (2016)"},{"key":"10_CR9","unstructured":"Jin, W., Li, Y., Xu, H., Wang, Y., Tang, J.: Adversarial attacks and defenses on graphs: a review and empirical study. arXiv preprint arXiv:2003.00653 (2020). 10(3447556.3447566)"},{"key":"10_CR10","doi-asserted-by":"publisher","first-page":"111820","DOI":"10.1109\/ACCESS.2022.3211306","volume":"10","author":"H Kim","year":"2022","unstructured":"Kim, H., Lee, B.S., Shin, W.Y., Lim, S.: Graph anomaly detection with graph neural networks: current status and challenges. IEEE Access 10, 111820\u2013111829 (2022)","journal-title":"IEEE Access"},{"key":"10_CR11","unstructured":"Kipf, T.N., Welling, M.: Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016)"},{"key":"10_CR12","first-page":"3454","volume":"33","author":"TA Nguyen","year":"2020","unstructured":"Nguyen, T.A., Tran, A.: Input-aware dynamic backdoor attack. Adv. Neural. Inf. Process. Syst. 33, 3454\u20133464 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Saha, A., Subramanya, A., Pirsiavash, H.: Hidden trigger backdoor attacks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a034, pp. 11957\u201311965 (2020)","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"10_CR14","doi-asserted-by":"crossref","unstructured":"Sun, Y., Wang, S., Tang, X., Hsieh, T.Y., Honavar, V.: Adversarial attacks on graph neural networks via node injections: a hierarchical reinforcement learning approach. In: Proceedings of the Web Conference 2020, pp. 673\u2013683 (2020)","DOI":"10.1145\/3366423.3380149"},{"key":"10_CR15","doi-asserted-by":"crossref","unstructured":"Tang, X., Li, Y., Sun, Y., Yao, H., Mitra, P., Wang, S.: Transferring robustness for graph neural network against poisoning attacks. In: Proceedings of the 13th International Conference on Web Search and Data Mining, pp. 600\u2013608 (2020)","DOI":"10.1145\/3336191.3371851"},{"issue":"20","key":"10_CR16","first-page":"10","volume":"1050","author":"P Velickovic","year":"2017","unstructured":"Velickovic, P., et al.: Graph attention networks. Stat 1050(20), 10\u201348550 (2017)","journal-title":"Stat"},{"key":"10_CR17","unstructured":"Wang, H., Leskovec, J.: Unifying graph convolutional neural networks and label propagation. arXiv preprint arXiv:2002.06755 (2020)"},{"key":"10_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2024.110449","volume":"152","author":"K Wang","year":"2024","unstructured":"Wang, K., Deng, H., Xu, Y., Liu, Z., Fang, Y.: Multi-target label backdoor attacks on graph neural networks. Pattern Recogn. 152, 110449 (2024)","journal-title":"Pattern Recogn."},{"key":"10_CR19","series-title":"Lecture Notes in Business Information Processing","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1007\/978-3-030-94343-1_3","volume-title":"Business Process Management Workshops","author":"S Weinzierl","year":"2022","unstructured":"Weinzierl, S.: Exploring gated graph sequence neural networks for predicting next process activities. In: Marrella, A., Weber, B. (eds.) BPM 2021. LNBIP, vol. 436, pp. 30\u201342. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-94343-1_3"},{"issue":"1","key":"10_CR20","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1109\/TNNLS.2020.2978386","volume":"32","author":"Z Wu","year":"2020","unstructured":"Wu, Z., Pan, S., Chen, F., Long, G., Zhang, C., Philip, S.Y.: A comprehensive survey on graph neural networks. IEEE Trans. Neural Netw. Learn. Syst. 32(1), 4\u201324 (2020)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"10_CR21","unstructured":"Xi, Z., Pang, R., Ji, S., Wang, T.: Graph backdoor. In: 30th USENIX Security Symposium (USENIX Security 2021), pp. 1523\u20131540 (2021)"},{"key":"10_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.112433","volume":"304","author":"X Xing","year":"2024","unstructured":"Xing, X., Xu, M., Bai, Y., Yang, D.: A clean-label graph backdoor attack method in node classification task. Knowl.-Based Syst. 304, 112433 (2024)","journal-title":"Knowl.-Based Syst."},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Xu, J., Picek, S.: Poster: clean-label backdoor attack on graph neural networks. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, pp. 3491\u20133493 (2022)","DOI":"10.1145\/3548606.3563531"},{"key":"10_CR24","doi-asserted-by":"crossref","unstructured":"Xu, J., Xue, M., Picek, S.: Explainability-based backdoor attacks against graph neural networks. In: Proceedings of the 3rd ACM Workshop on Wireless Security and Machine Learning, pp. 31\u201336 (2021)","DOI":"10.1145\/3468218.3469046"},{"key":"10_CR25","unstructured":"Xu, K., Hu, W., Leskovec, J., Jegelka, S.: How powerful are graph neural networks? In: International Conference on Learning Representations (ICLR) (2019)"},{"key":"10_CR26","unstructured":"Yang, X., Li, G., Li, J.: Graph neural backdoor: fundamentals, methodologies, applications, and future directions. arXiv preprint arXiv:2406.10573 (2024)"},{"issue":"1","key":"10_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40649-019-0069-y","volume":"6","author":"S Zhang","year":"2019","unstructured":"Zhang, S., Tong, H., Xu, J., Maciejewski, R.: Graph convolutional networks: a comprehensive review. Comput. Soc. Netw. 6(1), 1\u201323 (2019)","journal-title":"Comput. Soc. Netw."},{"key":"10_CR28","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Jia, J., Wang, B., Gong, N.Z.: Backdoor attacks to graph neural networks. In: Proceedings of the 26th ACM Symposium on Access Control Models and Technologies, pp. 15\u201326 (2021)","DOI":"10.1145\/3450569.3463560"},{"key":"10_CR29","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Lin, M., Dai, E., Wang, S.: Rethinking graph backdoor attacks: a distribution-preserving perspective. In: Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 4386\u20134397 (2024)","DOI":"10.1145\/3637528.3671910"},{"key":"10_CR30","doi-asserted-by":"publisher","first-page":"12102","DOI":"10.1109\/JIOT.2023.3332848","volume":"11","author":"X Zhao","year":"2023","unstructured":"Zhao, X., Wu, H., Zhang, X.: Effective backdoor attack on graph neural networks in spectral domain. IEEE Internet Things J. 11, 12102\u201312114 (2023)","journal-title":"IEEE Internet Things J."},{"key":"10_CR31","unstructured":"Zhu, X., Ghahramani, Z., Lafferty, J.D.: Semi-supervised learning using gaussian fields and harmonic functions. In: Proceedings of the 20th International conference on Machine Learning (ICML 2003), pp. 912\u2013919 (2003)"},{"key":"10_CR32","doi-asserted-by":"crossref","unstructured":"Zhu, Y., et al.: On the robustness of graph reduction against GNN backdoor. arXiv preprint arXiv:2407.02431 (2024)","DOI":"10.1145\/3689932.3694762"},{"key":"10_CR33","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., Akbarnejad, A., G\u00fcnnemann, S.: Adversarial attacks on neural networks for graph data. In: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 2847\u20132856 (2018)","DOI":"10.1145\/3219819.3220078"}],"container-title":["Lecture Notes in Computer Science","Security, Privacy, and Applied Cryptography Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-80408-3_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,6]],"date-time":"2025-03-06T07:55:22Z","timestamp":1741247722000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-80408-3_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,9]]},"ISBN":["9783031804076","9783031804083"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-80408-3_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,9]]},"assertion":[{"value":"9 December 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SPACE","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security, Privacy, and Applied Cryptography Engineering","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kottayam","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 December 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 December 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"space2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/space2024.cse.iitk.ac.in\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}