{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T18:02:25Z","timestamp":1785952945236,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,30]],"date-time":"2023-04-30T00:00:00Z","timestamp":1682812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-1707548, IIS-1909702"],"award-info":[{"award-number":["IIS-1707548, IIS-1909702"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Department of Homeland Security (DNS) CINA","award":["E205949D"],"award-info":[{"award-number":["E205949D"]}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF21-1-0198"],"award-info":[{"award-number":["W911NF21-1-0198"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,30]]},"DOI":"10.1145\/3543507.3583392","type":"proceedings-article","created":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T23:30:51Z","timestamp":1682551851000},"page":"2263-2273","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":69,"title":["Unnoticeable Backdoor Attacks on Graph Neural Networks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9715-0280","authenticated-orcid":false,"given":"Enyan","family":"Dai","sequence":"first","affiliation":[{"name":"Pennsylvania State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1591-7172","authenticated-orcid":false,"given":"Minhua","family":"Lin","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0940-6595","authenticated-orcid":false,"given":"Xiang","family":"Zhang","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3448-4878","authenticated-orcid":false,"given":"Suhang","family":"Wang","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,30]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML(Proceedings of Machine Learning Research). PMLR.","author":"Bojchevski Aleksandar","year":"2019","unstructured":"Aleksandar Bojchevski and Stephan G\u00fcnnemann. 2019. Adversarial Attacks on Node Embeddings via Graph Poisoning. In Proceedings of the 36th International Conference on Machine Learning, ICML(Proceedings of Machine Learning Research). PMLR."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.039"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5741"},{"key":"e_1_3_2_1_4_1","unstructured":"Ming Chen Zhewei Wei Zengfeng Huang Bolin Ding and Yaliang Li. 2020. Simple and deep graph convolutional networks. In ICML. 1725\u20131735."},{"key":"e_1_3_2_1_5_1","unstructured":"Yongqiang Chen Han Yang Yonggang Zhang MA KAILI Tongliang Liu Bo Han and James Cheng. 2022. Understanding and Improving Graph Injection Attack by Promoting Unnoticeability. In ICLR."},{"key":"e_1_3_2_1_6_1","volume-title":"NRGNN: Learning a Label Noise-Resistant Graph Neural Network on Sparsely and Noisily Labeled Graphs. arXiv preprint arXiv:2106.04714","author":"Dai Enyan","year":"2021","unstructured":"Enyan Dai, Charu Aggarwal, and Suhang Wang. 2021. NRGNN: Learning a Label Noise-Resistant Graph Neural Network on Sparsely and Noisily Labeled Graphs. arXiv preprint arXiv:2106.04714 (2021)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Enyan Dai Wei Jin Hui Liu and Suhang Wang. 2022. Towards robust graph neural networks for noisy graphs with sparse labels. In WSDM. 181\u2013191.","DOI":"10.1145\/3488560.3498408"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Enyan Dai and Suhang Wang. 2021. Say No to the Discrimination: Learning Fair Graph Neural Networks with Limited Sensitive Attribute Information. In WSDM. 680\u2013688.","DOI":"10.1145\/3437963.3441752"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Enyan Dai and Suhang Wang. 2021. Towards self-explainable graph neural network. In CIKM. 302\u2013311.","DOI":"10.1145\/3459637.3482306"},{"key":"e_1_3_2_1_10_1","volume-title":"Robustness, Fairness, and Explainability. arXiv preprint arXiv:2204.08570","author":"Dai Enyan","year":"2022","unstructured":"Enyan Dai, Tianxiang Zhao, Huaisheng Zhu, Junjie Xu, Zhimeng Guo, Hui Liu, Jiliang Tang, and Suhang Wang. 2022. A Comprehensive Survey on Trustworthy Graph Neural Networks: Privacy, Robustness, Fairness, and Explainability. arXiv preprint arXiv:2204.08570 (2022)."},{"key":"e_1_3_2_1_11_1","unstructured":"Enyan Dai Shijie Zhou Zhimeng Guo and Suhang Wang. 2022. Label-Wise Graph Convolutional Network for Heterophilic Graphs. In LOG."},{"key":"e_1_3_2_1_12_1","volume-title":"Adversarial attack on graph structured data. ICML","author":"Dai Hanjun","year":"2018","unstructured":"Hanjun Dai, Hui Li, Tian Tian, Xin Huang, Lin Wang, Jun Zhu, and Le Song. 2018. Adversarial attack on graph structured data. ICML (2018)."},{"key":"e_1_3_2_1_13_1","unstructured":"Chelsea Finn Pieter Abbeel and Sergey Levine. 2017. Model-agnostic meta-learning for fast adaptation of deep networks. In ICML. 1126\u20131135."},{"key":"e_1_3_2_1_14_1","unstructured":"Will Hamilton Zhitao Ying and Jure Leskovec. 2017. Inductive representation learning on large graphs. In NeurIPS. 1024\u20131034."},{"key":"e_1_3_2_1_15_1","unstructured":"Weihua Hu Matthias Fey Marinka Zitnik Yuxiao Dong Hongyu Ren Bowen Liu Michele Catasta and Jure Leskovec. 2020. Open Graph Benchmark: Datasets for Machine Learning on Graphs. In NeurIPS Vol.\u00a033. 22118\u201322133."},{"key":"e_1_3_2_1_16_1","unstructured":"Itay Hubara Matthieu Courbariaux Daniel Soudry Ran El-Yaniv and Yoshua Bengio. 2016. Binarized neural networks. NeurIPS."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1021\/ci3001277"},{"key":"e_1_3_2_1_18_1","unstructured":"Dongkwan Kim and Alice Oh. 2021. How to find your friendly neighborhood: Graph attention design with self-supervision. In ICLR."},{"key":"e_1_3_2_1_19_1","volume-title":"Kipf and Max Welling","author":"N.","year":"2017","unstructured":"Thomas\u00a0N. Kipf and Max Welling. 2017. Semi-Supervised Classification with Graph Convolutional Networks. In ICLR."},{"key":"e_1_3_2_1_20_1","unstructured":"Pang\u00a0Wei Koh and Percy Liang. 2017. Understanding black-box predictions via influence functions. In ICLR. 1885\u20131894."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Yao Ma Suhang Wang Tyler Derr Lingfei Wu and Jiliang Tang. 2021. Graph Adversarial Attack via Rewiring. In SIGKDD. 1161\u20131169.","DOI":"10.1145\/3447548.3467416"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403168"},{"key":"e_1_3_2_1_23_1","volume-title":"Collective classification in network data. AI magazine 29, 3","author":"Sen Prithviraj","year":"2008","unstructured":"Prithviraj Sen, Galileo Namata, Mustafa Bilgic, Lise Getoor, Brian Galligher, and Tina Eliassi-Rad. 2008. Collective classification in network data. AI magazine 29, 3 (2008), 93\u201393."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-92638-0_17"},{"key":"e_1_3_2_1_25_1","volume-title":"Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning Approach","author":"Sun Yiwei","unstructured":"Yiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh, and Vasant Honavar. 2020. Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning Approach. In WWW. Association for Computing Machinery, New York, NY, USA, 673\u2013683."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Shuchang Tao Qi Cao Huawei Shen Junjie Huang Yunfan Wu and Xueqi Cheng. 2021. Single Node Injection Attack against Graph Neural Networks. In CIKM. 1794\u20131803.","DOI":"10.1145\/3459637.3482393"},{"key":"e_1_3_2_1_27_1","volume-title":"Graph attention networks. ICLR","author":"Veli\u010dkovi\u0107 Petar","year":"2018","unstructured":"Petar Veli\u010dkovi\u0107, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, and Yoshua Bengio. 2018. Graph attention networks. ICLR (2018)."},{"key":"e_1_3_2_1_28_1","volume-title":"Evasion attacks to graph neural networks via influence function. arXiv preprint arXiv:2009.00203","author":"Wang Binghui","year":"2020","unstructured":"Binghui Wang, Tianxiang Zhou, Minhua Lin, Pan Zhou, Ang Li, Meng Pang, Cai Fu, Hai Li, and Yiran Chen. 2020. Evasion attacks to graph neural networks via influence function. arXiv preprint arXiv:2009.00203 (2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"A Semi-supervised Graph Attentive Network for Financial Fraud Detection","author":"Wang Daixin","unstructured":"Daixin Wang, Jianbin Lin, Peng Cui, Quanhui Jia, Zhen Wang, Yanming Fang, Quan Yu, Jun Zhou, Shuang Yang, and Yuan Qi. 2019. A Semi-supervised Graph Attentive Network for Financial Fraud Detection. In ICDM. IEEE, 598\u2013607."},{"key":"e_1_3_2_1_30_1","unstructured":"Zhaohan Xi Ren Pang Shouling Ji and Ting Wang. 2021. Graph backdoor. In USENIX Security. 1523\u20131540."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Junjie Xu Enyan Dai Xiang Zhang and Suhang Wang. 2022. HP-GMN: Graph Memory Networks for Heterophilous Graphs. In ICDM. 1263\u20131268.","DOI":"10.1109\/ICDM54844.2022.00165"},{"key":"e_1_3_2_1_32_1","volume-title":"Poster: Clean-label Backdoor Attack on Graph Neural Networks. In CCS. 3491\u20133493.","author":"Xu Jing","year":"2022","unstructured":"Jing Xu and Stjepan Picek. 2022. Poster: Clean-label Backdoor Attack on Graph Neural Networks. In CCS. 3491\u20133493."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Kaidi Xu Hongge Chen Sijia Liu Pin-Yu Chen Tsui-Wei Weng Mingyi Hong and Xue Lin. 2019. Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective. In IJCAI. 3961\u20133967.","DOI":"10.24963\/ijcai.2019\/550"},{"key":"e_1_3_2_1_34_1","volume-title":"How powerful are graph neural networks?arXiv preprint arXiv:1810.00826","author":"Xu Keyulu","year":"2018","unstructured":"Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2018. How powerful are graph neural networks?arXiv preprint arXiv:1810.00826 (2018)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Rex Ying Ruining He Kaifeng Chen Pong Eksombatchai William\u00a0L Hamilton and Jure Leskovec. 2018. Graph convolutional neural networks for web-scale recommender systems. In SIGKDD. 974\u2013983.","DOI":"10.1145\/3219819.3219890"},{"key":"e_1_3_2_1_36_1","volume-title":"Gnnexplainer: Generating explanations for graph neural networks. In Advances in neural information processing systems. 9244\u20139255.","author":"Ying Zhitao","year":"2019","unstructured":"Zhitao Ying, Dylan Bourgeois, Jiaxuan You, Marinka Zitnik, and Jure Leskovec. 2019. Gnnexplainer: Generating explanations for graph neural networks. In Advances in neural information processing systems. 9244\u20139255."},{"key":"e_1_3_2_1_37_1","unstructured":"Hanqing Zeng Hongkuan Zhou Ajitesh Srivastava Rajgopal Kannan and Viktor Prasanna. 2020. GraphSAINT: Graph Sampling Based Inductive Learning Method. In ICLR."},{"key":"e_1_3_2_1_38_1","volume-title":"NeurIPS, H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.). Vol.\u00a033. Curran Associates","author":"Zhang Xiang","unstructured":"Xiang Zhang and Marinka Zitnik. 2020. GNNGuard: Defending Graph Neural Networks against Adversarial Attacks. In NeurIPS, H.\u00a0Larochelle, M.\u00a0Ranzato, R.\u00a0Hadsell, M.F. Balcan, and H.\u00a0Lin (Eds.). Vol.\u00a033. Curran Associates, Inc., 9263\u20139275."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Zaixi Zhang Jinyuan Jia Binghui Wang and Neil\u00a0Zhenqiang Gong. 2021. Backdoor attacks to graph neural networks. In SACMAT. 15\u201326.","DOI":"10.1145\/3450569.3463560"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20898"},{"key":"e_1_3_2_1_41_1","unstructured":"Tianxiang Zhao Xianfeng Tang Xiang Zhang and Suhang Wang. 2020. Semi-Supervised Graph-to-Graph Translation. In CIKM. 1863\u20131872."},{"key":"e_1_3_2_1_42_1","unstructured":"Dingyuan Zhu Ziwei Zhang Peng Cui and Wenwu Zhu. 2019. Robust graph convolutional networks against adversarial attacks. In SIGKDD. 1399\u20131407."},{"key":"e_1_3_2_1_43_1","volume-title":"Self-supervised Training of Graph Convolutional Networks. arXiv preprint arXiv:2006.02380","author":"Zhu Qikui","year":"2020","unstructured":"Qikui Zhu, Bo Du, and Pingkun Yan. 2020. Self-supervised Training of Graph Convolutional Networks. arXiv preprint arXiv:2006.02380 (2020)."},{"key":"e_1_3_2_1_44_1","volume-title":"TDGIA: Effective Injection Attacks on Graph Neural Networks","author":"Zou Xu","year":"2021","unstructured":"Xu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan, Evgeny Kharlamov, Jialiang Lu, and Jie Tang. 2021. TDGIA: Effective Injection Attacks on Graph Neural Networks. In SIGKDD. Association for Computing Machinery, New York, NY, USA, 2461\u20132471."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","unstructured":"Daniel Z\u00fcgner Amir Akbarnejad and Stephan G\u00fcnnemann. 2018. Adversarial attacks on neural networks for graph data. In SIGKDD. 2847\u20132856.","DOI":"10.1145\/3219819.3220078"},{"key":"e_1_3_2_1_46_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Z\u00fcgner Daniel","year":"2019","unstructured":"Daniel Z\u00fcgner and Stephan G\u00fcnnemann. 2019. Adversarial Attacks on Graph Neural Networks via Meta Learning. In International Conference on Learning Representations (ICLR)."}],"event":{"name":"WWW '23: The ACM Web Conference 2023","location":"Austin TX USA","acronym":"WWW '23","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2023"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543507.3583392","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3543507.3583392","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3543507.3583392","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3543507.3583392","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:51Z","timestamp":1750178871000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543507.3583392"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,30]]},"references-count":46,"alternative-id":["10.1145\/3543507.3583392","10.1145\/3543507"],"URL":"https:\/\/doi.org\/10.1145\/3543507.3583392","relation":{},"subject":[],"published":{"date-parts":[[2023,4,30]]},"assertion":[{"value":"2023-04-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}