@inproceedings{b20fab4e78f34d98a17239a449d21681,
title = "GNNHacker: Adaptive Subgraph Backdoor Attacking Method with Saliency Analysis and Joint Optimization",
abstract = "Subgraph backdoor attacks reveal critical vulnerabilities in graph neural networks (GNNs). They replace GNNs{\textquoteright} nodes and edges with elaborate triggers, causing the misclassification of graph-structured data examples into target categories specified by adversaries. To overcome the high computational overhead of existing attacking methods, we propose an adaptive subgraph backdoor attack method with saliency analysis and joint optimization called GNNHacker. Specifically, GNNHacker introduces a gradient-based saliency map to identify the nodes with high saliency scores as poisoning targets. Then, it adopts a joint optimization mechanism by simultaneously optimizing trigger generation and the training of backdoor GNNs. Experimental results over five public datasets show that the proposed method significantly outperforms baselines in terms of attacking capability and efficiency.",
keywords = "Graph neural networks, saliency analysis, subgraph backdoor attack",
author = "Xiaojie Wu and Yan Luo and Shujie Li and Xiping Hu and Qiang Liu and Chengming Li",
note = "Publisher Copyright: {\textcopyright} The Author(s), under exclusive license to Springer Nature Singapore Pte Ltd. 2025.; 21st International Conference on Intelligent Computing, ICIC 2025 ; Conference date: 26-07-2025 Through 29-07-2025",
year = "2025",
doi = "10.1007/978-981-96-9849-3\_3",
language = "English",
isbn = "9789819698486",
series = "Lecture Notes in Computer Science",
publisher = "Springer Science and Business Media Deutschland GmbH",
pages = "27--43",
editor = "De-Shuang Huang and Yijie Pan and Wei Chen and Haiming Chen",
booktitle = "Advanced Intelligent Computing Technology and Applications - 21st International Conference, ICIC 2025, Proceedings",
address = "Germany",
}