← Search

Bingdao Feng

8 accepted papers

2026

Collateral Damage Constrained Backdoor Attacks on Graph Neural Networks

IJCAI 2026

Graph Neural Networks (GNNs) are vulnerable to backdoor attacks, where models behave normally on clean data but exhibit targeted misclassifications once specific triggers are activated. Existing backdoor attacks on GNNs mainly focus on enhancing trigger stealthiness or diversifying attack paradigms.

Cited by 0Scholar
2025

Backdoor Attack on Propagation-based Rumor Detectors

AAAI 2025technical

Rumor detection is critical as the spread of misinformation on social media threatens social stability. The propagation structure has garnered attention for its ability to capture discriminative information, such as crowd stance, which has led to the development of enhanced detection methods. Howeve…

Cited by 0SourcePDFScholar
2025

Exploiting Self-Refining Normal Graph Structures for Robust Defense against Unsupervised Adversarial Attacks

IJCAI 2025

Defending against adversarial attacks on graphs has become increasingly important. Graph refinement to enhance the quality and robustness of representation learning is a critical area that requires thorough investigation. We observe that representations learned from attacked graphs are often ineffec

Cited by 0SourcePDFScholar
2025

LoSplit: Loss-Guided Dynamic Split for Training-Time Defense Against Graph Backdoor Attacks

NeurIPS 2025poster

Graph Neural Networks (GNNs) are vulnerable to backdoor attacks. Existing defenses primarily rely on detecting structural anomalies, distributional outliers, or perturbation-induced prediction instability, which struggle to handle the more subtle, feature-based attacks that do not introduce obvious…

Cited by 0SourceScholar
2025

Rethinking Contrastive Learning in Graph Anomaly Detection: A Clean-View Perspective

IJCAI 2025

Graph anomaly detection aims to identify unusual patterns in graph-based data, with wide applications in fields such as web security and financial fraud detection. Existing methods typically rely on contrastive learning, assuming that a lower similarity between a node and its local subgraph indicate

Cited by 0SourcePDFScholar
2025

Single-Node Trigger Backdoor Attacks in Graph-Based Recommendation Systems

IJCAI 2025

Graph recommendation systems have been widely studied due to their ability to effectively capture the complex interactions between users and items. However, these systems also exhibit certain vulnerabilities when faced with attacks. The prevailing shilling attack methods typically manipulate recomme

Cited by 0SourcePDFScholar
2025

Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph Classification

NeurIPS 2025poster

Graph Neural Networks (GNNs) have demonstrated strong performance across tasks such as node classification, link prediction, and graph classification, but remain vulnerable to backdoor attacks that implant imperceptible triggers during training to control predictions. While node-level attacks exploi…

Cited by 0SourcecodeScholar
2023

Local-Global Defense against Unsupervised Adversarial Attacks on Graphs

AAAI 2023technical

Unsupervised pre-training algorithms for graph representation learning are vulnerable to adversarial attacks, such as first-order perturbations on graphs, which will have an impact on particular downstream applications. Designing an effective representation learning strategy against white-box attack…

Cited by 13SourcePDFScholar