{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:17:41Z","timestamp":1783437461175,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the Key Research and Development Project in Shaanxi Province","award":["No. 2023GXLH-024"],"award-info":[{"award-number":["No. 2023GXLH-024"]}]},{"name":"the National Science Foundation of China","award":["No.(62406242, 62037001, 62476215, and 62302380)"],"award-info":[{"award-number":["No.(62406242, 62037001, 62476215, and 62302380)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,4,22]]},"DOI":"10.1145\/3696410.3714630","type":"proceedings-article","created":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T22:47:11Z","timestamp":1745362031000},"page":"852-862","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["NI-GDBA: Non-Intrusive Distributed Backdoor Attack Based on Adaptive Perturbation on Federated Graph Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-3793-2405","authenticated-orcid":false,"given":"Ken","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Xi'an Jiaotong University, Xi'an, China and Ministry of Education Key Laboratory of Intelligent Networks and Network Security, Xi'an Jiaotong University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8272-9361","authenticated-orcid":false,"given":"Bin","family":"Shi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi'an Jiaotong University, Xi'an, China and Ministry of Education Key Laboratory of Intelligent Networks and Network Security, Xi'an Jiaotong University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-3983-5170","authenticated-orcid":false,"given":"Jiazhe","family":"Wei","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi'an Jiaotong University, Xi'an, China and Shaanxi Province Key Laboratory of Big Data Knowledge Engineering, Xi'an Jiaotong University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7695-9072","authenticated-orcid":false,"given":"Bo","family":"Dong","sequence":"additional","affiliation":[{"name":"School of Distance Education, Xi'an Jiaotong University, Xi'an, China and Shaanxi Province Key Laboratory of Big Data Knowledge Engineering, Xi'an Jiaotong University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Emergence of scaling in random networks. science","author":"Barab\u00e1si Albert-L\u00e1szl\u00f3","year":"1999","unstructured":"Albert-L\u00e1szl\u00f3 Barab\u00e1si and R\u00e9ka Albert. 1999. Emergence of scaling in random networks. science, Vol. 286, 5439 (1999), 509--512."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108218"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583392"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/MODELS50736.2021.00016"},{"key":"e_1_3_2_1_5_1","volume-title":"On random graphs I. Publ. math. debrecen","author":"P","year":"1959","unstructured":"P ERDdS and A R&wi. 1959. On random graphs I. Publ. math. debrecen, Vol. 6, 290--297 (1959), 18."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Wenqi Fan Yao Ma Qing Li Yuan He Eric Zhao Jiliang Tang and Dawei Yin. 2019. Graph neural networks for social recommendation. In The world wide web conference. 417--426.","DOI":"10.1145\/3308558.3313488"},{"key":"e_1_3_2_1_7_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Fung Clement","year":"2020","unstructured":"Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 301--316."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3501396"},{"key":"e_1_3_2_1_9_1","volume-title":"Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hyoungshick Kim.","author":"Gao Yansong","year":"2020","unstructured":"Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hyoungshick Kim. 2020. Backdoor attacks and countermeasures on deep learning: A comprehensive review. arXiv preprint arXiv:2007.10760 (2020)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177706098"},{"key":"e_1_3_2_1_11_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_12_1","volume-title":"Fedgraphnn: A federated learning system and benchmark for graph neural networks. arXiv preprint arXiv:2104.07145","author":"He Chaoyang","year":"2021","unstructured":"Chaoyang He, Keshav Balasubramanian, Emir Ceyani, Carl Yang, Han Xie, Lichao Sun, Lifang He, Liangwei Yang, Philip S Yu, Yu Rong, et al. 2021. Fedgraphnn: A federated learning system and benchmark for graph neural networks. arXiv preprint arXiv:2104.07145 (2021)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20643"},{"key":"e_1_3_2_1_14_1","volume-title":"Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907","author":"Kipf Thomas N","year":"2016","unstructured":"Thomas N Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016)."},{"key":"e_1_3_2_1_15_1","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume":"2","author":"Li Tian","year":"2020","unstructured":"Tian Li, Anit Kumar Sahu, Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith. 2020. Federated optimization in heterogeneous networks. Proceedings of Machine learning and systems, Vol. 2 (2020), 429--450.","journal-title":"Proceedings of Machine learning and systems"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"e_1_3_2_1_17_1","volume-title":"Bkd-FedGNN: A Benchmark for Classification Backdoor Attacks on Federated Graph Neural Network. arXiv preprint arXiv:2306.10351","author":"Liu Fan","year":"2023","unstructured":"Fan Liu, Siqi Lai, Yansong Ning, and Hao Liu. 2023. Bkd-FedGNN: A Benchmark for Classification Backdoor Attacks on Federated Graph Neural Network. arXiv preprint arXiv:2306.10351 (2023)."},{"key":"e_1_3_2_1_18_1","volume-title":"Federated graph neural networks: Overview, techniques, and challenges","author":"Liu Rui","year":"2024","unstructured":"Rui Liu, Pengwei Xing, Zichao Deng, Anran Li, Cuntai Guan, and Han Yu. 2024. Federated graph neural networks: Overview, techniques, and challenges. IEEE Transactions on Neural Networks and Learning Systems (2024)."},{"key":"e_1_3_2_1_19_1","unstructured":"Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Aguera y Arcas. 2017a. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR 1273--1282."},{"key":"e_1_3_2_1_20_1","unstructured":"Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Aguera y Arcas. 2017b. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR 1273--1282."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2022.3188728"},{"key":"e_1_3_2_1_22_1","volume-title":"Bioinformatics","volume":"39","author":"Pfeifer Bastian","year":"2023","unstructured":"Bastian Pfeifer, Hryhorii Chereda, Roman Martin, Anna Saranti, Sandra Clemens, Anne-Christin Hauschild, Tim Bei\u00dfbarth, Andreas Holzinger, and Dominik Heider. 2023. Ensemble-GNN: federated ensemble learning with graph neural networks for disease module discovery and classification. Bioinformatics, Vol. 39, 11 (2023), btad703."},{"key":"e_1_3_2_1_23_1","volume-title":"Adaptive federated optimization. arXiv preprint arXiv:2003.00295","author":"Reddi Sashank","year":"2020","unstructured":"Sashank Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett, Keith Rush, Jakub Kone\u010dn\u1ef3, Sanjiv Kumar, and H Brendan McMahan. 2020. Adaptive federated optimization. arXiv preprint arXiv:2003.00295 (2020)."},{"key":"e_1_3_2_1_24_1","volume-title":"Graph attention networks. arXiv preprint arXiv:1710.10903","author":"Veli\u010dkovi\u0107 Petar","year":"2017","unstructured":"Petar Veli\u010dkovi\u0107, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, and Yoshua Bengio. 2017. Graph attention networks. arXiv preprint arXiv:1710.10903 (2017)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM54844.2022.00060"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2019.00070"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539112"},{"key":"e_1_3_2_1_28_1","volume-title":"Collective dynamics of 'small-world'networks. nature","author":"Watts Duncan J","year":"1998","unstructured":"Duncan J Watts and Steven H Strogatz. 1998. Collective dynamics of 'small-world'networks. nature, Vol. 393, 6684 (1998), 440--442."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-022-30714-9"},{"key":"e_1_3_2_1_30_1","volume-title":"Backdoor Graph Condensation. arXiv preprint arXiv:2407.11025","author":"Wu Jiahao","year":"2024","unstructured":"Jiahao Wu, Ning Lu, Zeiyu Dai, Wenqi Fan, Shengcai Liu, Qing Li, and Ke Tang. 2024. Backdoor Graph Condensation. arXiv preprint arXiv:2407.11025 (2024)."},{"key":"e_1_3_2_1_31_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Xi Zhaohan","year":"2021","unstructured":"Zhaohan Xi, Ren Pang, Shouling Ji, and Ting Wang. 2021. Graph backdoor. In 30th USENIX Security Symposium (USENIX Security 21). 1523--1540."},{"key":"e_1_3_2_1_32_1","volume-title":"International conference on learning representations.","author":"Xie Chulin","year":"2019","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2019. Dba: Distributed backdoor attacks against federated learning. In International conference on learning representations."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN54540.2023.10191949"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3633206"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3563531"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567999"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3545948.3545976"},{"key":"e_1_3_2_1_38_1","volume-title":"Methodologies, Applications, and Future Directions. arXiv preprint arXiv:2406.10573","author":"Yang Xiao","year":"2024","unstructured":"Xiao Yang, Gaolei Li, and Jianhua Li. 2024a. Graph Neural Backdoor: Fundamentals, Methodologies, Applications, and Future Directions. arXiv preprint arXiv:2406.10573 (2024)."},{"key":"e_1_3_2_1_39_1","volume-title":"Distributed Backdoor Attacks on Federated Graph Learning and Certified Defenses. arXiv preprint arXiv:2407.08935","author":"Yang Yuxin","year":"2024","unstructured":"Yuxin Yang, Qiang Li, Jinyuan Jia, Yuan Hong, and Binghui Wang. 2024b. Distributed Backdoor Attacks on Federated Graph Learning and Certified Defenses. arXiv preprint arXiv:2407.08935 (2024)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3219342"},{"key":"e_1_3_2_1_41_1","volume-title":"International Conference on Machine Learning. PMLR, 40888--40910","author":"Zhang Hangfan","year":"2023","unstructured":"Hangfan Zhang, Jinghui Chen, Lu Lin, Jinyuan Jia, and Dinghao Wu. 2023. Graph contrastive backdoor attacks. In International Conference on Machine Learning. PMLR, 40888--40910."},{"key":"e_1_3_2_1_42_1","volume-title":"No Matter What You Do!'': Mitigating Backdoor Attacks in Graph Neural Networks. arXiv preprint arXiv:2410.01272","author":"Zhang Jiale","year":"2024","unstructured":"Jiale Zhang, Chengcheng Zhu, Bosen Rao, Hao Sui, Xiaobing Sun, Bing Chen, Chunyi Zhou, and Shouling Ji. 2024b. '' No Matter What You Do!'': Mitigating Backdoor Attacks in Graph Neural Networks. arXiv preprint arXiv:2410.01272 (2024)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671910"},{"key":"e_1_3_2_1_45_1","volume-title":"Patterns","volume":"3","author":"Zhu Wei","year":"2022","unstructured":"Wei Zhu, Jiebo Luo, and Andrew D White. 2022. Federated learning of molecular properties with graph neural networks in a heterogeneous setting. Patterns, Vol. 3, 6 (2022)."},{"key":"e_1_3_2_1_46_1","volume-title":"On the Robustness of Graph Reduction Against GNN Backdoor. arXiv preprint arXiv:2407.02431","author":"Zhu Yuxuan","year":"2024","unstructured":"Yuxuan Zhu, Michael Mandulak, Kerui Wu, George Slota, Yuseok Jeon, Ka-Ho Chow, and Lei Yu. 2024. On the Robustness of Graph Reduction Against GNN Backdoor. arXiv preprint arXiv:2407.02431 (2024). gr"}],"event":{"name":"WWW '25: The ACM Web Conference 2025","location":"Sydney NSW Australia","acronym":"WWW '25","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM on Web Conference 2025"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714630","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3696410.3714630","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:56Z","timestamp":1750295936000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714630"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,22]]},"references-count":46,"alternative-id":["10.1145\/3696410.3714630","10.1145\/3696410"],"URL":"https:\/\/doi.org\/10.1145\/3696410.3714630","relation":{},"subject":[],"published":{"date-parts":[[2025,4,22]]},"assertion":[{"value":"2025-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}