{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/robustness-inspired-defense-against-backdoor","title":"Robustness Inspired Graph Backdoor Defense","arxiv_id":"2406.09836","date":"2024-06-14","proceeding":null,"authors":["Zhiwei Zhang","Minhua Lin","Junjie Xu","Zongyu Wu","Enyan Dai","Suhang Wang"],"abstract":"Graph Neural Networks (GNNs) have achieved promising results in tasks such as node classification and graph classification. However, recent studies reveal that GNNs are vulnerable to backdoor attacks, posing a significant threat to their real-world adoption. Despite initial efforts to defend against specific graph backdoor attacks, there is no work on defending against various types of backdoor attacks where generated triggers have different properties. Hence, we first empirically verify that prediction variance under edge dropping is a crucial indicator for identifying poisoned nodes. With this observation, we propose using random edge dropping to detect backdoors and theoretically show that it can efficiently distinguish poisoned nodes from clean ones. Furthermore, we introduce a novel robust training strategy to efficiently counteract the impact of the triggers. Extensive experiments on real-world datasets show that our framework can effectively identify poisoned nodes, significantly degrade the attack success rate, and maintain clean accuracy when defending against various types of graph backdoor attacks with different properties.","url_abs":"https://arxiv.org/abs/2406.09836v2","url_pdf":"https://arxiv.org/pdf/2406.09836v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[],"tasks":[{"task_slug":"graph-classification","task_name":"Graph Classification"},{"task_slug":"node-classification","task_name":"Node Classification"},{"task_slug":"backdoor-defense","task_name":"backdoor defense"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2406.09836","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2406.09836"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/zzwjames/RIGBD","reach":{"status":"ok"}}],"summary":{"ran":3},"by_repo_kind":{"found_in_text":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"17e5f0c32d079478","entry":"clu_prune_unrelated_edge","repo":"zzwjames/RIGBD","repo_kind":"found_in_text","path":"help_funcs.py","file_url":"https://github.com/zzwjames/RIGBD/blob/HEAD/help_funcs.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"17e5f0c32d079478"}},{"code_sha256_prefix":"6146c5fcef9e81f3","entry":"edge_sim_analysis","repo":"zzwjames/RIGBD","repo_kind":"found_in_text","path":"help_funcs.py","file_url":"https://github.com/zzwjames/RIGBD/blob/HEAD/help_funcs.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"6146c5fcef9e81f3"}},{"code_sha256_prefix":"e3c6ff9b9c469f8c","entry":"prune_unrelated_edge","repo":"zzwjames/RIGBD","repo_kind":"found_in_text","path":"help_funcs.py","file_url":"https://github.com/zzwjames/RIGBD/blob/HEAD/help_funcs.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e3c6ff9b9c469f8c"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}