{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T15:11:52Z","timestamp":1778080312593,"version":"3.51.4"},"publisher-location":"Cham","reference-count":51,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032059802","type":"print"},{"value":"9783032059819","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,9,23]],"date-time":"2025-09-23T00:00:00Z","timestamp":1758585600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,23]],"date-time":"2025-09-23T00:00:00Z","timestamp":1758585600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-05981-9_22","type":"book-chapter","created":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T19:05:01Z","timestamp":1759172701000},"page":"367-383","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Bkd-FedGNN: A Benchmark for\u00a0Classification Backdoor Attacks on\u00a0Federated Graph Neural Network"],"prefix":"10.1007","author":[{"given":"Fan","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Siqi","family":"Lai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yansong","family":"Ning","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,23]]},"reference":[{"key":"22_CR1","doi-asserted-by":"crossref","unstructured":"Barab\u00e1si, A.L., Albert, R.: Emergence of scaling in random networks. Science 286(5439), 509\u2013512 (1999)","DOI":"10.1126\/science.286.5439.509"},{"key":"22_CR2","unstructured":"Blanchard, P., El\u00a0Mhamdi, E.M., Guerraoui, R., Stainer, J.: Machine learning with adversaries: byzantine tolerant gradient descent. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"22_CR3","doi-asserted-by":"crossref","unstructured":"Borgwardt, K.M., Ong, C.S., Sch\u00f6nauer, S., Vishwanathan, S.V.N., Smola, A.J., Kriegel, H.: Protein function prediction via graph kernels. In: Proceedings Thirteenth International Conference on Intelligent Systems for Molecular Biology 2005, Detroit, MI, USA, 25\u201329 June 2005, pp. 47\u201356 (2005)","DOI":"10.1093\/bioinformatics\/bti1007"},{"key":"22_CR4","doi-asserted-by":"crossref","unstructured":"Cheibub, J.A., Gandhi, J., Vreeland, J.R.: Democracy and dictatorship revisited. Public Choice, pp. 67\u2013101 (2010)","DOI":"10.1007\/s11127-009-9491-2"},{"key":"22_CR5","doi-asserted-by":"crossref","unstructured":"Chen, J., Huang, G., Zheng, H., Yu, S., Jiang, W., Cui, C.: Graph-fraudster: adversarial attacks on graph neural network-based vertical federated learning. IEEE Trans. Comput. Soc. Syst. (2022)","DOI":"10.1109\/TCSS.2022.3161016"},{"key":"22_CR6","doi-asserted-by":"crossref","unstructured":"Dai, E., Lin, M., Zhang, X., Wang, S.: Unnoticeable backdoor attacks on graph neural networks. In: WWW 2023, Proceedings of the ACM Web Conference 2023, pp. 2263\u20132273. New York, NY, USA (2023)","DOI":"10.1145\/3543507.3583392"},{"key":"22_CR7","unstructured":"Fang, M., Cao, X., Jia, J., Gong, N.Z.: Local model poisoning attacks to byzantine-robust federated learning. In: 29th USENIX Security Symposium, USENIX Security 2020, August 12\u201314, 2020, pp. 1605\u20131622. USENIX Association (2020)"},{"issue":"4","key":"22_CR8","doi-asserted-by":"publisher","first-page":"1141","DOI":"10.1214\/aoms\/1177706098","volume":"30","author":"EN Gilbert","year":"1959","unstructured":"Gilbert, E.N.: Random graphs. Ann. Math. Stat. 30(4), 1141\u20131144 (1959)","journal-title":"Ann. Math. Stat."},{"key":"22_CR9","unstructured":"Gilmer, J., Schoenholz, S.S., Riley, P.F., Vinyals, O., Dahl, G.E.: Neural message passing for quantum chemistry. In: Proceedings of the 34th International Conference on Machine Learning, ICML 2017, Sydney, NSW, Australia, 6\u201311 August 2017. Proceedings of Machine Learning Research, vol.\u00a070, pp. 1263\u20131272. PMLR (2017)"},{"key":"22_CR10","unstructured":"Guo, Z., Han, R., Liu, H.: Against multifaceted graph heterogeneity via asymmetric federated prompt learning. arXiv:2411.02003 (2024)"},{"key":"22_CR11","doi-asserted-by":"publisher","unstructured":"Guo, Z., Yao, D., Yang, Q., Liu, H.: Hifgl: a hierarchical framework for cross-silo cross-device federated graph learning. In: KDD 2024, Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 968\u2013979. Association for Computing Machinery, New York, NY, USA (2024). https:\/\/doi.org\/10.1145\/3637528.3671660","DOI":"10.1145\/3637528.3671660"},{"key":"22_CR12","unstructured":"Halimi, A., Kadhe, S., Rawat, A., Baracaldo, N.: Federated unlearning: how to efficiently erase a client in FL? CoRR arXiv:2207.05521 (2022)"},{"key":"22_CR13","unstructured":"Hamilton, W.L., Ying, Z., Leskovec, J.: Inductive representation learning on large graphs. In: Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, December 4\u20139, 2017, Long Beach, CA, USA, pp. 1024\u20131034 (2017)"},{"issue":"5","key":"22_CR14","doi-asserted-by":"publisher","first-page":"5230","DOI":"10.1109\/TKDE.2022.3149815","volume":"35","author":"J Han","year":"2022","unstructured":"Han, J., Liu, H., Xiong, H., Yang, J.: Semi-supervised air quality forecasting via self-supervised hierarchical graph neural network. IEEE Trans. Knowl. Data Eng. 35(5), 5230\u20135243 (2022)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"22_CR15","doi-asserted-by":"publisher","unstructured":"Han, J., Zhang, W., Liu, H., Tao, T., Tan, N., Xiong, H.: Bigst: linear complexity spatio-temporal graph neural network for traffic forecasting on large-scale road networks. Proc. VLDB Endow. 17(5), 1081\u20131090 (2024). https:\/\/doi.org\/10.14778\/3641204.3641217","DOI":"10.14778\/3641204.3641217"},{"key":"22_CR16","doi-asserted-by":"crossref","unstructured":"He, C., Ceyani, E., Balasubramanian, K., Annavaram, M., Avestimehr, S.: SpreadGNN: decentralized multi-task federated learning for graph neural networks on molecular data (2021)","DOI":"10.1609\/aaai.v36i6.20643"},{"key":"22_CR17","unstructured":"Huang, X., et al.: Dgraph: a large-scale financial dataset for graph anomaly detection. In: NeurIPS (2022)"},{"key":"22_CR18","unstructured":"Karimireddy, S.P., Kale, S., Mohri, M., Reddi, S.J., Stich, S.U., Suresh, A.T.: Scaffold: stochastic controlled averaging for on-device federated learning. arXiv preprint arXiv:1910.06378 (2019)"},{"key":"22_CR19","unstructured":"Kipf, T.N., Welling, M.: Semi-supervised classification with graph convolutional networks. In: 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24\u201326, 2017, Conference Track Proceedings. OpenReview.net (2017). https:\/\/openreview.net\/forum?id=SJU4ayYgl"},{"key":"22_CR20","unstructured":"Knyazev, B., Taylor, G.W., Amer, M.: Understanding attention and generalization in graph neural networks. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"22_CR21","unstructured":"Li, H., Wu, C., Zhu, S., Zheng, Z.: Learning to backdoor federated learning. arXiv preprint arXiv:2303.03320 (2023)"},{"key":"22_CR22","doi-asserted-by":"crossref","unstructured":"Li, Q., Diao, Y., Chen, Q., He, B.: Federated learning on non-iid data silos: an experimental study. In: 2022 IEEE 38th International Conference on Data Engineering (ICDE), pp. 965\u2013978. IEEE (2022)","DOI":"10.1109\/ICDE53745.2022.00077"},{"key":"22_CR23","first-page":"429","volume":"2","author":"T Li","year":"2020","unstructured":"Li, T., Sahu, A.K., Zaheer, M., Sanjabi, M., Talwalkar, A., Smith, V.: Federated optimization in heterogeneous networks. Proc. Mach. learn. syst. 2, 429\u2013450 (2020)","journal-title":"Proc. Mach. learn. syst."},{"key":"22_CR24","unstructured":"Liu, F., et al.: Jailjudge: a comprehensive jailbreak judge benchmark with multi-agent enhanced explanation evaluation framework. arXiv:2410.12855 (2024)"},{"key":"22_CR25","doi-asserted-by":"publisher","unstructured":"Liu, F., Liu, H.: Subgraph federated unlearning. In: WWW 2025, Proceedings of the ACM on Web Conference 2025, pp. 1205\u20131215. Association for Computing Machinery, New York, NY, USA (2025). https:\/\/doi.org\/10.1145\/3696410.3714821","DOI":"10.1145\/3696410.3714821"},{"key":"22_CR26","unstructured":"Maekawa, S., Noda, K., Sasaki, Y., Onizuka, M.: Beyond real-world benchmark datasets: An empirical study of node classification with GNNs. In: NeurIPS (2022)"},{"key":"22_CR27","doi-asserted-by":"crossref","unstructured":"McAuley, J., Targett, C., Shi, Q., van\u00a0den Hengel, A.: Image-based recommendations on styles and substitutes. In: SIGIR 2015, Proceedings of the 38th International ACM SIGIR Conference on Research and Development in Information Retrieval, pp. 43\u201352. Association for Computing Machinery (2015)","DOI":"10.1145\/2766462.2767755"},{"key":"22_CR28","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., y\u00a0Arcas, B.A.: Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017, 20\u201322 April 2017, Fort Lauderdale, FL, USA. Proceedings of Machine Learning Research, vol.\u00a054, pp. 1273\u20131282. PMLR (2017)"},{"key":"22_CR29","doi-asserted-by":"crossref","unstructured":"\u00d6zdayi, M.S., Kantarcioglu, M., Gel, Y.R.: Defending against backdoors in federated learning with robust learning rate. In: Thirty-Fifth AAAI Conference on Artificial Intelligence, AAAI 2021, pp. 9268\u20139276. AAAI Press (2021)","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"22_CR30","unstructured":"Reddi, S., et al.: Adaptive federated optimization. arXiv preprint arXiv:2003.00295 (2020)"},{"key":"22_CR31","doi-asserted-by":"crossref","unstructured":"Riesen, K., Bunke, H.: IAM graph database repository for graph based pattern recognition and machine learning. In: Structural, Syntactic, and Statistical Pattern Recognition, Joint IAPR International Workshop, SSPR & SPR 2008, Orlando, USA, December 4\u20136, 2008. Proceedings. Lecture Notes in Computer Science, vol.\u00a05342, pp. 287\u2013297. Springer (2008)","DOI":"10.1007\/978-3-540-89689-0_33"},{"key":"22_CR32","doi-asserted-by":"crossref","unstructured":"Rong, Y., et al.: Deep graph learning: foundations, advances and applications. In: KDD 2020: The 26th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Virtual Event, CA, USA, August 23\u201327, 2020, pp. 3555\u20133556. ACM (2020)","DOI":"10.1145\/3394486.3406474"},{"key":"22_CR33","doi-asserted-by":"crossref","unstructured":"Rossi, R., Ahmed, N.: The network data repository with interactive graph analytics and visualization. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 29, no. 1 (2015)","DOI":"10.1609\/aaai.v29i1.9277"},{"key":"22_CR34","unstructured":"Shchur, O., Mumme, M., Bojchevski, A., G\u00fcnnemann, S.: Pitfalls of graph neural network evaluation. In: Relational Representation Learning Workshop, NeurIPS 2018 (2018)"},{"issue":"4","key":"22_CR35","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1017\/S0963548399003867","volume":"8","author":"A Steger","year":"1999","unstructured":"Steger, A., Wormald, N.C.: Generating random regular graphs quickly. Comb. Probab. Comput. 8(4), 377\u2013396 (1999)","journal-title":"Comb. Probab. Comput."},{"key":"22_CR36","doi-asserted-by":"publisher","unstructured":"Tolpegin, V., Truex, S., Gursoy, M.E., Liu, L.: Data poisoning attacks against federated learning systems. In: Chen, L., Li, N., Liang, K., Schneider, S. (eds.) ESORICS 2020. LNCS, vol. 12308, pp. 480\u2013501. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58951-6_24","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"22_CR37","unstructured":"Velickovic, P., Cucurull, G., Casanova, A., Romero, A., Li\u00f2, P., Bengio, Y.: Graph attention networks. In: 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 \u2013 May 3, 2018, Conference Track Proceedings (2018). https:\/\/openreview.net\/forum?id=rJXMpikCZ"},{"key":"22_CR38","doi-asserted-by":"publisher","unstructured":"Wale, N., Karypis, G.: Comparison of descriptor spaces for chemical compound retrieval and classification. In: Sixth International Conference on Data Mining (ICDM 2006), pp. 678\u2013689 (2006). https:\/\/doi.org\/10.1109\/ICDM.2006.39","DOI":"10.1109\/ICDM.2006.39"},{"key":"22_CR39","doi-asserted-by":"publisher","unstructured":"Wang, Z., et al.: Federatedscope-GNN: towards a unified, comprehensive and efficient package for federated graph learning. In: KDD 2022, Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 4110\u20134120. New York, NY, USA (2022). https:\/\/doi.org\/10.1145\/3534678.3539112","DOI":"10.1145\/3534678.3539112"},{"key":"22_CR40","doi-asserted-by":"crossref","unstructured":"Watts, D.J., Strogatz, S.H.: Collective dynamics of \u2018small-world\u2019 networks. Nature 393(6684), 440\u2013442 (1998)","DOI":"10.1038\/30918"},{"key":"22_CR41","unstructured":"Xi, Z., Pang, R., Ji, S., Wang, T.: Graph backdoor. In: USENIX Security Symposium, pp. 1523\u20131540 (2021)"},{"key":"22_CR42","unstructured":"Xie, C., Chen, M., Chen, P., Li, B.: CRFL: certifiably robust federated learning against backdoor attacks. In: Proceedings of the 38th International Conference on Machine Learning, ICML 2021, 18\u201324 July 2021, Virtual Event. Proceedings of Machine Learning Research, vol.\u00a0139, pp. 11372\u201311382. PMLR (2021)"},{"key":"22_CR43","doi-asserted-by":"crossref","unstructured":"Xu, J., Abad, G., Picek, S.: Rethinking the trigger-injecting position in graph backdoor attack. arXiv preprint arXiv:2304.02277 (2023)","DOI":"10.1109\/IJCNN54540.2023.10191949"},{"key":"22_CR44","doi-asserted-by":"crossref","unstructured":"Xu, J., Wang, R., Koffas, S., Liang, K., Picek, S.: More is better (mostly): on the backdoor attacks in federated graph neural networks. In: Proceedings of the 38th Annual Computer Security Applications Conference, pp. 684\u2013698 (2022)","DOI":"10.1145\/3564625.3567999"},{"key":"22_CR45","doi-asserted-by":"crossref","unstructured":"Xu, J., Xue, M., Picek, S.: Explainability-based backdoor attacks against graph neural networks. In: Proceedings of the 3rd ACM Workshop on Wireless Security and Machine Learning, pp. 31\u201336 (2021)","DOI":"10.1145\/3468218.3469046"},{"key":"22_CR46","doi-asserted-by":"crossref","unstructured":"Xu, R., Baracaldo, N., Zhou, Y., Anwar, A., Kadhe, S., Ludwig, H.: Detrust-FL: privacy-preserving federated learning in decentralized trust setting. In: IEEE 15th International Conference on Cloud Computing, CLOUD 2022, Barcelona, Spain, July 10\u201316, 2022. pp. 417\u2013426. IEEE (2022)","DOI":"10.1109\/CLOUD55607.2022.00065"},{"key":"22_CR47","doi-asserted-by":"crossref","unstructured":"Yang, S., et al.: Transferable graph backdoor attack. In: Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses, pp. 321\u2013332 (2022)","DOI":"10.1145\/3545948.3545976"},{"key":"22_CR48","unstructured":"Yang, Z., Cohen, W.W., Salakhutdinov, R.: Revisiting semi-supervised learning with graph embeddings. In: Proceedings of the 33nd International Conference on Machine Learning, ICML 2016, New York City, NY, USA, June 19\u201324, 2016. JMLR Workshop and Conference Proceedings, vol.\u00a048, pp. 40\u201348. JMLR.org (2016)"},{"key":"22_CR49","unstructured":"Zhang, K., Yang, C., Li, X., Sun, L., Yiu, S.M.: Subgraph federated learning with missing neighbor generation. In: Advances in Neural Information Processing Systems, vol. 34, pp. 6671\u20136682 (2021)"},{"key":"22_CR50","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Jia, J., Wang, B., Gong, N.Z.: Backdoor attacks to graph neural networks. In: Proceedings of the 26th ACM Symposium on Access Control Models and Technologies, pp. 15\u201326 (2021)","DOI":"10.1145\/3450569.3463560"},{"key":"22_CR51","doi-asserted-by":"crossref","unstructured":"Zheng, H., Xiong, H., Chen, J., Ma, H., Huang, G.: Motif-backdoor: rethinking the backdoor attack on graph neural networks via motifs. IEEE Trans. Comput. Soc. Syst. (2023)","DOI":"10.1109\/TCSS.2023.3267094"}],"container-title":["Lecture Notes in Computer Science","Machine Learning and Knowledge Discovery in Databases. Research Track"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-05981-9_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,29]],"date-time":"2025-09-29T19:05:32Z","timestamp":1759172732000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-05981-9_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,23]]},"ISBN":["9783032059802","9783032059819"],"references-count":51,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-05981-9_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,23]]},"assertion":[{"value":"23 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Porto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ecmlpkdd.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}