{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T06:22:13Z","timestamp":1764829333985,"version":"3.44.0"},"reference-count":48,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["World Wide Web"],"published-print":{"date-parts":[[2025,7]]},"DOI":"10.1007\/s11280-025-01364-w","type":"journal-article","created":{"date-parts":[[2025,7,8]],"date-time":"2025-07-08T02:22:22Z","timestamp":1751941342000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Graph spectral purification for backdoor defence in graph neural networks"],"prefix":"10.1007","volume":"28","author":[{"given":"Shuiqiao","family":"Yang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bao","family":"Gia Doan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Montague","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Olivier","family":"De Vel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tamas","family":"Abraham","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alsharif","family":"Abuadbba","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ehsan","family":"Abbasnejad","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Seyit","family":"Camtepe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Damith","family":"C. Ranasinghe","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Salil","family":"S. Kanhere","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,7,8]]},"reference":[{"key":"1364_CR1","unstructured":"Kipf, T.N., Welling, M.: Semi-supervised classification with graph convolutional networks. arXiv:1609.02907 (2016)"},{"issue":"6","key":"1364_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11280-024-01312-0","volume":"27","author":"Y Song","year":"2024","unstructured":"Song, Y., Palanisamy, B.: Mapping: debiasing graph neural networks for fair node classification with limited sensitive information leakage. World Wide Web 27(6), 1\u201332 (2024)","journal-title":"World Wide Web"},{"issue":"3","key":"1364_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11280-025-01340-4","volume":"28","author":"M Moosazadeh","year":"2025","unstructured":"Moosazadeh, M., Kaedi, M.: CCT-GNN: collaborative category and time-aware graph neural networks for session-based recommendation systems. World Wide Web 28(3), 1\u201326 (2025)","journal-title":"World Wide Web"},{"issue":"1","key":"1364_CR4","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1007\/s11280-024-01320-0","volume":"28","author":"Y Cao","year":"2025","unstructured":"Cao, Y., Lin, X., Wu, Y., Shi, F., Shang, Y., Tan, Q., Zhou, C., Zhang, P.: A data-centric framework of improving graph neural networks for knowledge graph embedding. World Wide Web 28(1), 2 (2025)","journal-title":"World Wide Web"},{"issue":"4","key":"1364_CR5","doi-asserted-by":"publisher","first-page":"1913","DOI":"10.1007\/s11280-022-01120-4","volume":"26","author":"C Li","year":"2023","unstructured":"Li, C., Wang, Z., Zhao, Z., Duan, H., Zeng, Q.: HGNN-ETA: heterogeneous graph neural network enriched with text attribute. World Wide Web 26(4), 1913\u20131934 (2023)","journal-title":"World Wide Web"},{"key":"1364_CR6","doi-asserted-by":"crossref","unstructured":"Liu, Y., Xie, Y., Srivastava, A.: Neural trojans. In: 2017 IEEE International Conference on Computer Design (ICCD), pp. 45\u201348. IEEE (2017)","DOI":"10.1109\/ICCD.2017.16"},{"key":"1364_CR7","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: Evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"issue":"2","key":"1364_CR8","doi-asserted-by":"publisher","first-page":"976","DOI":"10.1109\/TCBB.2022.3172421","volume":"20","author":"S Liu","year":"2022","unstructured":"Liu, S., Zhang, Y., Cui, Y., Qiu, Y., Deng, Y., Zhang, Z., Zhang, W.: Enhancing drug-drug interaction prediction using deep attention neural networks. IEEE\/ACM Trans. Comput. Biol. Bioinforma. 20(2), 976\u2013985 (2022)","journal-title":"IEEE\/ACM Trans. Comput. Biol. Bioinforma."},{"issue":"1","key":"1364_CR9","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1186\/s12859-022-04763-2","volume":"23","author":"C He","year":"2022","unstructured":"He, C., Liu, Y., Li, H., Zhang, H., Mao, Y., Qin, X., Liu, L., Zhang, X.: Multi-type feature fusion based on graph neural network for drug-drug interaction prediction. BMC Bioinforma. 23(1), 224 (2022)","journal-title":"BMC Bioinforma."},{"key":"1364_CR10","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Jia, J., Wang, B., Gong, N.Z.: Backdoor attacks to graph neural networks. In: Proceedings of the 26th ACM Symposium on Access Control Models and Technologies, pp. 15\u201326 (2021)","DOI":"10.1145\/3450569.3463560"},{"key":"1364_CR11","unstructured":"Xi, Z., Pang, R., Ji, S., Wang, T.: Graph backdoor. In: 30th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 21) (2021)"},{"key":"1364_CR12","doi-asserted-by":"crossref","unstructured":"Yang, S., Doan, B.G., Montague, P., De\u00a0Vel, O., Abraham, T., Camtepe, S., Ranasinghe, D.C., Kanhere, S.S.: Transferable graph backdoor attack. In: Proceedings of the 25th International Symposium on Research in Attacks, Intrusions and Defenses, pp. 321\u2013332 (2022)","DOI":"10.1145\/3545948.3545976"},{"key":"1364_CR13","doi-asserted-by":"crossref","unstructured":"Wang, B., Yao, Y., Shan, S., Li, H., Viswanath, B., Zheng, H., Zhao, B.Y.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"1364_CR14","doi-asserted-by":"crossref","unstructured":"Gao, Y., Xu, C., Wang, D., Chen, S., Ranasinghe, D.C., Nepal, S.: Strip: a defence against trojan attacks on deep neural networks. In: Proceedings of the 35th Annual Computer Security Applications Conference, pp. 113\u2013125 (2019)","DOI":"10.1145\/3359789.3359790"},{"key":"1364_CR15","first-page":"9263","volume":"33","author":"X Zhang","year":"2020","unstructured":"Zhang, X., Zitnik, M.: Gnnguard: defending graph neural networks against adversarial attacks. Adv. Neural Inf. Process. Syst. 33, 9263\u20139275 (2020)","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"2","key":"1364_CR16","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1145\/3447556.3447566","volume":"22","author":"W Jin","year":"2021","unstructured":"Jin, W., Li, Y., Xu, H., Wang, Y., Ji, S., Aggarwal, C., Tang, J.: Adversarial attacks and defenses on graphs. SIGKDD Explor. Newsl. 22(2), 19\u201334 (2021)","journal-title":"SIGKDD Explor. Newsl."},{"key":"1364_CR17","unstructured":"Jiang, B., Li, Z.: Defending against backdoor attack on graph nerual network by explainability. arXiv:2209.02902. (2022)"},{"key":"1364_CR18","doi-asserted-by":"crossref","unstructured":"Zhu, D., Zhang, Z., Cui, P., Zhu, W.: Robust graph convolutional networks against adversarial attacks. In: Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 1399\u20131407 (2019)","DOI":"10.1145\/3292500.3330851"},{"key":"1364_CR19","doi-asserted-by":"crossref","unstructured":"Ding, K., Li, J., Bhanushali, R., Liu, H.: Deep anomaly detection on attributed networks. In: Proceedings of the 2019 SIAM International Conference on Data Mining, pp. 594\u2013602. SIAM (2019)","DOI":"10.1137\/1.9781611975673.67"},{"key":"1364_CR20","doi-asserted-by":"crossref","unstructured":"Entezari, N., Al-Sayouri, S.A., Darvishzadeh, A., Papalexakis, E.E.: All you need is low (rank) defending against adversarial attacks on graphs. In: Proceedings of the 13th International Conference on Web Search and Data Mining, pp. 169\u2013177 (2020)","DOI":"10.1145\/3336191.3371789"},{"key":"1364_CR21","doi-asserted-by":"crossref","unstructured":"Zhao, X., Wu, H., Zhang, X.: Effective backdoor attack on graph neural networks in spectral domain. IEEE Internet of Things Journal (2023)","DOI":"10.1109\/JIOT.2023.3332848"},{"issue":"6","key":"1364_CR22","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1109\/MSP.2020.3014590","volume":"37","author":"R Ramakrishna","year":"2020","unstructured":"Ramakrishna, R., Wai, H.-T., Scaglione, A.: A user guide to low-pass graph signal processing and its applications: tools and applications. IEEE Signal Proc. Mag. 37(6), 74\u201385 (2020)","journal-title":"IEEE Signal Proc. Mag."},{"key":"1364_CR23","doi-asserted-by":"crossref","unstructured":"Doob, M.: Eigenvalues of graphs. Topics in algebraic graph theory, 30\u201357 (2004)","DOI":"10.1017\/CBO9780511529993.004"},{"key":"1364_CR24","unstructured":"Sun, L., Dou, Y., Yang, C., Wang, J., Yu, P.S., He, L., Li, B.: Adversarial attack and defense on graph data: a survey. arXiv:1812.10528 (2018)"},{"key":"1364_CR25","unstructured":"Liu, Y., Chen, X., Liu, C., Song, D.: Delving into transferable adversarial examples and black-box attacks. arXiv:1611.02770 (2016)"},{"key":"1364_CR26","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506\u2013519 (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"1364_CR27","first-page":"20834","volume":"33","author":"Z Zhang","year":"2020","unstructured":"Zhang, Z., Zhang, Z., Zhou, Y., Shen, Y., Jin, R., Dou, D.: Adversarial attacks on deep graph matching. Adv. Neural Inf. Process. Syst. 33, 20834\u201320851 (2020)","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"1364_CR28","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., Akbarnejad, A., G\u00fcnnemann, S.: Adversarial attacks on neural networks for graph data. In: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 2847\u20132856 (2018)","DOI":"10.1145\/3219819.3220078"},{"key":"1364_CR29","doi-asserted-by":"crossref","unstructured":"Xu, K., Chen, H., Liu, S., Chen, P.-Y., Weng, T.-W., Hong, M., Lin, X.: Topology attack and defense for graph neural networks: An optimization perspective. arXiv:1906.04214 (2019)","DOI":"10.24963\/ijcai.2019\/550"},{"key":"1364_CR30","doi-asserted-by":"crossref","unstructured":"Wu, H., Wang, C., Tyshetskiy, Y., Docherty, A., Lu, K., Zhu, L.: Adversarial examples on graph data: Deep insights into attack and defense. arXiv:1903.01610 (2019)","DOI":"10.24963\/ijcai.2019\/669"},{"key":"1364_CR31","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Lin, M., Dai, E., Wang, S.: Rethinking graph backdoor attacks: a distribution-preserving perspective. In: Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 4386\u20134397 (2024)","DOI":"10.1145\/3637528.3671910"},{"key":"1364_CR32","doi-asserted-by":"publisher","first-page":"112433","DOI":"10.1016\/j.knosys.2024.112433","volume":"304","author":"X Xing","year":"2024","unstructured":"Xing, X., Xu, M., Bai, Y., Yang, D.: A clean-label graph backdoor attack method in node classification task. Knowl.-Based Syst.. 304, 112433 (2024)","journal-title":"Knowl.-Based Syst.."},{"key":"1364_CR33","doi-asserted-by":"publisher","first-page":"110449","DOI":"10.1016\/j.patcog.2024.110449","volume":"152","author":"K Wang","year":"2024","unstructured":"Wang, K., Deng, H., Xu, Y., Liu, Z., Fang, Y.: Multi-target label backdoor attacks on graph neural networks. Pattern Recognition. 152, 110449 (2024)","journal-title":"Pattern Recognition."},{"issue":"6","key":"1364_CR34","doi-asserted-by":"publisher","first-page":"2493","DOI":"10.1109\/TKDE.2019.2957786","volume":"33","author":"F Feng","year":"2019","unstructured":"Feng, F., He, X., Tang, J., Chua, T.-S.: Graph adversarial training: dynamically regularizing based on graph structure. IEEE Trans. Knowl. Data Enbackdoorineering 33(6), 2493\u20132504 (2019)","journal-title":"IEEE Trans. Knowl. Data Enbackdoorineering"},{"key":"1364_CR35","doi-asserted-by":"crossref","unstructured":"Wang, B., Jia, J., Cao, X., Gong, N.Z.: Certified robustness of graph neural networks against adversarial structural perturbation. In: Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, pp. 1645\u20131653 (2021)","DOI":"10.1145\/3447548.3467295"},{"key":"1364_CR36","doi-asserted-by":"crossref","unstructured":"Doan, B.G., Abbasnejad, E., Ranasinghe, D.C.: Februus: input purification defense against trojan attacks on deep neural network systems. In: Annual Computer Security Applications Conference, pp. 897\u2013912 (2020)","DOI":"10.1145\/3427228.3427264"},{"key":"1364_CR37","doi-asserted-by":"crossref","unstructured":"Cao, X., Gong, N.Z.: Mitigating evasion attacks to deep neural networks via region-based classification. In: Proceedings of the 33rd Annual Computer Security Applications Conference, pp. 278\u2013287 (2017)","DOI":"10.1145\/3134600.3134606"},{"key":"1364_CR38","doi-asserted-by":"crossref","unstructured":"Liu, X., Cheng, M., Zhang, H., Hsieh, C.-J.: Towards robust neural networks via random self-ensemble. In: Proceedings of the European Conference on Computer Vision (ECCV), pp. 369\u2013385 (2018)","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"1364_CR39","unstructured":"Cohen, J., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In: International Conference on Machine Learning, pp. 1310\u20131320. PMLR (2019)"},{"issue":"77","key":"1364_CR40","first-page":"5","volume":"17","author":"CI Watson","year":"1992","unstructured":"Watson, C.I., Wilson, C.L.: NIST special database 4. Fingerprint Database National Inst. Stand. Technol. 17(77), 5 (1992)","journal-title":"Fingerprint Database National Inst. Stand. Technol."},{"issue":"4","key":"1364_CR41","doi-asserted-by":"publisher","first-page":"771","DOI":"10.1016\/S0022-2836(03)00628-4","volume":"330","author":"PD Dobson","year":"2003","unstructured":"Dobson, P.D., Doig, A.J.: Distinguishing enzyme structures from non-enzymes without alignments. J. Mol. Biol. 330(4), 771\u2013783 (2003)","journal-title":"J. Mol. Biol."},{"key":"1364_CR42","doi-asserted-by":"crossref","unstructured":"Riesen, K., Bunke, H.: IAM graph database repository for graph based pattern recognition and machine learning. In: Structural, Syntactic, and Statistical Pattern Recognition: Joint IAPR International Workshop, SSPR & SPR 2008, Orlando, USA, December 4-6, 2008. Proceedings, pp. 287\u2013297. Springer (2008)","DOI":"10.1007\/978-3-540-89689-0_33"},{"issue":"1","key":"1364_CR43","doi-asserted-by":"publisher","first-page":"312","DOI":"10.1021\/jm040835a","volume":"48","author":"J Kazius","year":"2005","unstructured":"Kazius, J., McGuire, R., Bursi, R.: Derivation and validation of toxicophores for mutagenicity prediction. J. Med. Chem. 48(1), 312\u2013320 (2005)","journal-title":"J. Med. Chem."},{"issue":"6","key":"1364_CR44","doi-asserted-by":"publisher","first-page":"1906","DOI":"10.1021\/ci034143r","volume":"43","author":"JJ Sutherland","year":"2003","unstructured":"Sutherland, J.J., O\u2019brien, L.A., Weaver, D.F.: Spline-fitting with a genetic algorithm: a method for developing classification structure-activity relationships. J. Chem. Inf. Comput. Sci. 43(6), 1906\u20131915 (2003)","journal-title":"J. Chem. Inf. Comput. Sci."},{"key":"1364_CR45","unstructured":"Kipf, T.N., Welling, M.: Variational graph auto-encoders. arXiv:1611.07308 (2016)"},{"key":"1364_CR46","unstructured":"Xu, K., Hu, W., Leskovec, J., Jegelka, S.: How powerful are graph neural networks? arXiv:1810.00826 (2018)"},{"key":"1364_CR47","unstructured":"Hamilton, W., Ying, Z., Leskovec, J.: Inductive representation learning on large graphs. Adv. Neural Inf. Process. Syst. 30 (2017)"},{"key":"1364_CR48","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., Romero, A., Lio, P., Bengio, Y.: Graph attention networks. arXiv:1710.10903 (2017)"}],"container-title":["World Wide Web"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-025-01364-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11280-025-01364-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11280-025-01364-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,7]],"date-time":"2025-09-07T01:39:57Z","timestamp":1757209197000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11280-025-01364-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7]]},"references-count":48,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,7]]}},"alternative-id":["1364"],"URL":"https:\/\/doi.org\/10.1007\/s11280-025-01364-w","relation":{},"ISSN":["1386-145X","1573-1413"],"issn-type":[{"type":"print","value":"1386-145X"},{"type":"electronic","value":"1573-1413"}],"subject":[],"published":{"date-parts":[[2025,7]]},"assertion":[{"value":"29 January 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 May 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 July 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 July 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}},{"value":"The authors declare no Conflict of interest.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"49"}}