Hiding in Plain Sight: Reliable Backdoor Attack Against Vertical Federated Graph Learning via Reconstruction Consistency
Abstract
Vertical federated graph neural networks (VFGNNs) enable collaborative learning from distributed graph data, but remain vulnerable to backdoor attacks. Unlike Euclidean data, graph data contain interconnected nodes, and message propagation may dilute trigger features, making backdoor attack methods developed for conventional vertical federated learning less effective when applied directly. In this paper, we propose Graph Camouflage (GraphCamo), a backdoor attack that combines structure-guided trigger learning and masked reconstruction-based backdoor consolidation. Its core idea is to select trigger support nodes based on graph topology and use masked feature reconstruction to preserve relevant information during graph aggregation. Experiments on four datasets and three GNN models show that, with only four anchor nodes, GraphCamo achieves an average attack success rate of 99.24% and an average standard deviation across configurations of 0.75%, while maintaining competitive main-task accuracy. Further experiments demonstrate its resistance to different defense mechanisms, while analyses of embeddings and gradients indicate that GraphCamo is less detectable.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.