acceptodds
Under review as a conference paper at ICLR 2027

Stealth Still Leaves Traces: Exposing and Reducing Trigger Footprints in Graph Backdoor Attacks

Abstract

Graph neural networks (GNNs) have been widely applied to various graph learning tasks, yet they remain vulnerable to backdoor attacks. By implanting specific triggers, an adversary can cause a model to misclassify nodes with attached triggers into a designated target class while preserving normal predictive performance on clean nodes. Although existing generative subgraph-based backdoor attacks have continuously improved the stealthiness of individual triggers, we find that the generated triggers still leave detectable multilevel trigger footprints. These footprints manifest as anomalous trigger node features, recurring local structures, and abnormally high feature similarity between corresponding nodes across different triggers. Based on these findings, we propose footprint reducing graph backdoor attack, which reduces these footprints by tailoring trigger generation to different types of node features, adopting a minimal single-node trigger to limit structural perturbation, and constraining excessive feature similarity across different triggers. Extensive experiments across multiple real-world graph datasets and representative GNN architectures demonstrate that the proposed attack achieves high attack success rates, exhibits robustness against multiple graph backdoor defenses, and maintains stable classification performance on clean nodes. The source code is available at https://anonymous.4open.science/r/FRGBA-702C.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.