{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,9,3]],"date-time":"2026-09-03T15:06:58Z","timestamp":1788448018325,"version":"build-2803163510"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-sa\/4.0\/"}],"funder":[{"name":"Innovation Funding of Institute of Computing Technology, Chinese Academy of Sciences","award":["E461060"],"award-info":[{"award-number":["E461060"]}]},{"DOI":"10.13039\/https:\/\/doi.org\/10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2436209, 62476263, 62406307"],"award-info":[{"award-number":["U2436209, 62476263, 62406307"]}],"id":[{"id":"10.13039\/https:\/\/doi.org\/10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/https:\/\/doi.org\/10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFC3303302"],"award-info":[{"award-number":["2022YFC3303302"]}],"id":[{"id":"10.13039\/https:\/\/doi.org\/10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Postdoctoral Fellowship Program of CPSF","award":["GZB20240761"],"award-info":[{"award-number":["GZB20240761"]}]},{"DOI":"10.13039\/https:\/\/doi.org\/10.13039\/501100005090","name":"Beijing Nova Program","doi-asserted-by":"publisher","award":["20230484430"],"award-info":[{"award-number":["20230484430"]}],"id":[{"id":"10.13039\/https:\/\/doi.org\/10.13039\/501100005090","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,4,22]]},"DOI":"10.1145\/3696410.3714665","type":"proceedings-article","created":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T18:57:28Z","timestamp":1745348248000},"page":"1237-1247","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-2416-8010","authenticated-orcid":false,"given":"Yuanhao","family":"Ding","sequence":"first","affiliation":[{"name":"Key Laboratory of AI Safety, Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China and University of Chinese Academy of Sciences, CAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1525-0788","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Key Laboratory of AI Safety, Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4824-9684","authenticated-orcid":false,"given":"Yugang","family":"Ji","sequence":"additional","affiliation":[{"name":"Individual Researcher, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4597-6053","authenticated-orcid":false,"given":"Weigao","family":"Wen","sequence":"additional","affiliation":[{"name":"Individual Researcher, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8833-5398","authenticated-orcid":false,"given":"Qing","family":"He","sequence":"additional","affiliation":[{"name":"Key Laboratory of AI Safety, Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China and University of Chinese Academy of Sciences, CAS, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9633-8361","authenticated-orcid":false,"given":"Xiang","family":"Ao","sequence":"additional","affiliation":[{"name":"Key Laboratory of AI Safety, Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, University of Chinese Academy of Sciences, CAS, Beijing, China, and Institute of Intelligent Computing Technology, CAS, Suzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS52979.2021.00098"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.039"},{"key":"e_1_3_2_1_3_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1155\/2023\/5418398"},{"key":"e_1_3_2_1_5_1","first-page":"17212","article-title":"Understanding global feature contributions with additive importance measures","volume":"33","author":"Covert Ian","year":"2020","unstructured":"Ian Covert, Scott M Lundberg, and Su-In Lee. 2020. Understanding global feature contributions with additive importance measures. Advances in Neural Information Processing Systems, Vol. 33 (2020), 17212--17223.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583392"},{"key":"e_1_3_2_1_7_1","volume-title":"International conference on machine learning. PMLR, 1115--1124","author":"Dai Hanjun","year":"2018","unstructured":"Hanjun Dai, Hui Li, Tian Tian, Xin Huang, Lin Wang, Jun Zhu, and Le Song. 2018. Adversarial attack on graph structured data. In International conference on machine learning. PMLR, 1115--1124."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Wenqi Fan Yao Ma Qing Li Yuan He Eric Zhao Jiliang Tang and Dawei Yin. 2019. Graph neural networks for social recommendation. In The world wide web conference. 417--426.","DOI":"10.1145\/3308558.3313488"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3008732"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109512"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_1_12_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_13_1","volume-title":"Open graph benchmark: Datasets for machine learning on graphs. Advances in neural information processing systems","author":"Hu Weihua","year":"2020","unstructured":"Weihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong, Hongyu Ren, Bowen Liu, Michele Catasta, and Jure Leskovec. 2020. Open graph benchmark: Datasets for machine learning on graphs. Advances in neural information processing systems, Vol. 33 (2020), 22118--22133."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512178"},{"key":"e_1_3_2_1_15_1","volume-title":"Kipf and Max Welling","author":"Thomas","year":"2017","unstructured":"Thomas N. Kipf and Max Welling. 2017. Semi-Supervised Classification with Graph Convolutional Networks. In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24--26, 2017, Conference Track Proceedings."},{"key":"e_1_3_2_1_16_1","volume-title":"Boosting the Adversarial Robustness of Graph Neural Networks: An OOD Perspective. In The Twelfth International Conference on Learning Representations.","author":"Li Kuan","year":"2023","unstructured":"Kuan Li, YiWen Chen, Yang Liu, Jin Wang, Qing He, Minhao Cheng, and Xiang Ao. 2023a. Boosting the Adversarial Robustness of Graph Neural Networks: An OOD Perspective. In The Twelfth International Conference on Learning Representations."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539484"},{"key":"e_1_3_2_1_18_1","volume-title":"The Eleventh International Conference on Learning Representations.","author":"Li Kuan","year":"2023","unstructured":"Kuan Li, Yang Liu, Xiang Ao, and Qing He. 2023b. Revisiting graph adversarial attack and defense from a data distribution perspective. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_19_1","volume-title":"Gated Graph Sequence Neural Networks. In 4th International Conference on Learning Representations, ICLR 2016, May 2--4, 2016, Conference Track Proceedings.","author":"Li Yujia","unstructured":"Yujia Li, Daniel Tarlow, Marc Brockschmidt, and Richard S. Zemel. 2016. Gated Graph Sequence Neural Networks. In 4th International Conference on Learning Representations, ICLR 2016, May 2--4, 2016, Conference Track Proceedings."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109042"},{"key":"e_1_3_2_1_21_1","first-page":"462","article-title":"Spatiotemporal activity modeling via hierarchical cross-modal embedding","volume":"34","author":"Liu Yang","year":"2020","unstructured":"Yang Liu, Xiang Ao, Linfeng Dong, Chao Zhang, Jin Wang, and Qing He. 2020. Spatiotemporal activity modeling via hierarchical cross-modal embedding. IEEE Transactions on Knowledge and Data Engineering, Vol. 34, 1 (2020), 462--474.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539483"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599355"},{"key":"e_1_3_2_1_24_1","volume-title":"Li","author":"Liu Zihan","year":"2024","unstructured":"Zihan Liu, Yun Luo, Lirong Wu, Zicheng Liu, and Stan Z. Li. 2024. Towards reasonable budget allocation in untargeted graph structure attacks via gradient debias (NIPS '22). Red Hook, NY, USA, Article 2028, 12 pages."},{"key":"e_1_3_2_1_25_1","volume-title":"Onion: A simple and effective defense against textual backdoor attacks. arXiv preprint arXiv:2011.10369","author":"Qi Fanchao","year":"2020","unstructured":"Fanchao Qi, Yangyi Chen, Mukai Li, Yuan Yao, Zhiyuan Liu, and Maosong Sun. 2020. Onion: A simple and effective defense against textual backdoor attacks. arXiv preprint arXiv:2011.10369 (2020)."},{"key":"e_1_3_2_1_26_1","volume-title":"Hidden killer: Invisible textual backdoor attacks with syntactic trigger. arXiv preprint arXiv:2105.12400","author":"Qi Fanchao","year":"2021","unstructured":"Fanchao Qi, Mukai Li, Yangyi Chen, Zhengyan Zhang, Zhiyuan Liu, Yasheng Wang, and Maosong Sun. 2021. Hidden killer: Invisible textual backdoor attacks with syntactic trigger. arXiv preprint arXiv:2105.12400 (2021)."},{"key":"e_1_3_2_1_27_1","volume-title":"Collective classification in network data. AI magazine","author":"Sen Prithviraj","year":"2008","unstructured":"Prithviraj Sen, Galileo Namata, Mustafa Bilgic, Lise Getoor, Brian Galligher, and Tina Eliassi-Rad. 2008. Collective classification in network data. AI magazine, Vol. 29, 3 (2008), 93--93."},{"key":"e_1_3_2_1_28_1","volume-title":"The emerging field of signal processing on graphs: Extending high-dimensional data analysis to networks and other irregular domains","author":"Shuman David I","year":"2013","unstructured":"David I Shuman, Sunil K Narang, Pascal Frossard, Antonio Ortega, and Pierre Vandergheynst. 2013. The emerging field of signal processing on graphs: Extending high-dimensional data analysis to networks and other irregular domains. IEEE signal processing magazine, Vol. 30, 3 (2013), 83--98."},{"key":"e_1_3_2_1_29_1","first-page":"7693","article-title":"Adversarial attack and defense on graph data: A survey","volume":"35","author":"Sun Lichao","year":"2022","unstructured":"Lichao Sun, Yingtong Dou, Carl Yang, Kai Zhang, Ji Wang, S Yu Philip, Lifang He, and Bo Li. 2022. Adversarial attack and defense on graph data: A survey. IEEE Transactions on Knowledge and Data Engineering, Vol. 35, 8 (2022), 7693--7711.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482393"},{"key":"e_1_3_2_1_31_1","unstructured":"Petar Velickovic Guillem Cucurull Arantxa Casanova Adriana Romero Pietro Lio Yoshua Bengio et al. 2017. Graph attention networks. stat Vol. 1050 20 (2017) 10--48550."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635826"},{"key":"e_1_3_2_1_33_1","volume-title":"International conference on machine learning. PMLR, 6861--6871","author":"Wu Felix","year":"2019","unstructured":"Felix Wu, Amauri Souza, Tianyi Zhang, Christopher Fifty, Tao Yu, and Kilian Weinberger. 2019. Simplifying graph convolutional networks. In International conference on machine learning. PMLR, 6861--6871."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2978386"},{"key":"e_1_3_2_1_35_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Xi Zhaohan","year":"2021","unstructured":"Zhaohan Xi, Ren Pang, Shouling Ji, and Ting Wang. 2021. Graph backdoor. In 30th USENIX Security Symposium (USENIX Security 21). 1523--1540."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482161"},{"key":"e_1_3_2_1_37_1","volume-title":"Advances in Neural Information Processing Systems","volume":"31","author":"Zhang Muhan","year":"2018","unstructured":"Muhan Zhang and Yixin Chen. 2018. Link Prediction Based on Graph Neural Networks. In Advances in Neural Information Processing Systems, Vol. 31."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11782"},{"key":"e_1_3_2_1_39_1","volume-title":"Gnnguard: Defending graph neural networks against adversarial attacks. Advances in neural information processing systems","author":"Zhang Xiang","year":"2020","unstructured":"Xiang Zhang and Marinka Zitnik. 2020. Gnnguard: Defending graph neural networks against adversarial attacks. Advances in neural information processing systems, Vol. 33 (2020), 9263--9275."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671910"},{"key":"e_1_3_2_1_42_1","volume-title":"Robustness-Inspired Defense Against Backdoor Attacks on Graph Neural Networks. arXiv preprint arXiv:2406.09836","author":"Zhang Zhiwei","year":"2024","unstructured":"Zhiwei Zhang, Minhua Lin, Junjie Xu, Zongyu Wu, Enyan Dai, and Suhang Wang. 2024b. Robustness-Inspired Defense Against Backdoor Attacks on Graph Neural Networks. arXiv preprint arXiv:2406.09836 (2024)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.xinn.2021.100176"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394520"}],"event":{"name":"WWW '25: The ACM Web Conference 2025","location":"Sydney NSW Australia","acronym":"WWW '25","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM on Web Conference 2025"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714665","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3696410.3714665","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T21:18:56Z","timestamp":1750281536000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696410.3714665"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,22]]},"references-count":46,"alternative-id":["10.1145\/3696410.3714665","10.1145\/3696410"],"URL":"https:\/\/doi.org\/10.1145\/3696410.3714665","relation":{},"subject":[],"published":{"date-parts":[[2025,4,22]]},"assertion":[{"value":"2025-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}