Fetching the paper…
Reading the bibliography…
Backdoor attacks have been widely studied to hide the misclassification rules in the normal models, which are only activated when the model is aware of the specific inputs (i.e., the trigger).
2007
Earlier work this paper cites.
P. Sen, G. Namata, M. Bilgic, L. Getoor, B. Gallagher, and T. Eliassi-Rad, “Collective classification in network data,” AI Mag. , vol. 29, no. 3, pp. 93–106, 2008
2008
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in ICLR , 2015
2015
Earlier work this paper cites.
J. Li, X. Hu, J. Tang, and H. Liu, “Unsupervised streaming feature selection in social media,” in CIKM , J. Bailey, A. Moffat, C. C. Aggarwal, M. de Rijke, R. Kumar, V. Murdock, T. K. Sellis, and J. X. Yu, Eds. ACM, 2015, pp. 1041–1050
2015
Earlier work this paper cites.
P. Velickovic, G. Cucurull, A. Casanova, A. Romero, P. Liò, and Y. Bengio, “Graph attention networks,” in ICLR , 2018
2015
Earlier work this paper cites.
M. Abadi, P. Barham, J. Chen, Z. Chen, A. Davis, J. Dean, M. Devin, S. Ghemawat, G. Irving, M. Isard, M. Kudlur, J. Levenberg, R. Monga, S. Moore, D. G. Murray, B. Steiner, P. A. Tucker, V. Vasudevan, P. Warden, M. Wicke, Y. Yu, and X. Zheng, “Tensorflow: A system for large-scale machine learning,” in OSDI , 2016, pp. 265–283
2016
Earlier work this paper cites.
T. N. Kipf and M. Welling, “Semi-supervised classification with graph convolutional networks,” in ICLR , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
W. L. Hamilton, Z. Ying, and J. Leskovec, “Inductive representation learning on large graphs,” in NIPS , 2017, pp. 1024–1034
2017
Earlier work this paper cites.
D. Zügner, A. Akbarnejad, and S. Günnemann, “Adversarial attacks on neural networks for graph data,” in KDD , 2018, pp. 2847–2856
2018
Earlier work this paper cites.
H. Dai, H. Li, T. Tian, X. Huang, L. Wang, J. Zhu, and L. Song, “Adversarial attack on graph structured data,” in ICML , 2018, pp. 1123–1132
2018
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in ICLR , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in NeurIPS , 2018, pp. 8011–8021
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
X. Wang, X. He, M. Wang, F. Feng, and T. Chua, “Neural graph collaborative filtering,” in SIGIR , 2019, pp. 165–174
2019
Cited alongside, same era.
M. Dong, B. Zheng, N. Q. V. Hung, H. Su, and G. Li, “Multiple rumor source detection with graph convolutional networks,” in CIKM , 2019, pp. 569–578
2019
Cited alongside, same era.
D. Zügner and S. Günnemann, “Adversarial attacks on graph neural networks via meta learning,” in ICLR , 2019
2019
Cited alongside, same era.
H. Wu, C. Wang, Y. Tyshetskiy, A. Docherty, K. Lu, and L. Zhu, “Adversarial examples for graph data: Deep insights into attack and defense,” in IJCAI , 2019, pp. 4816–4823
2019
Cited alongside, same era.
K. Xu, H. Chen, S. Liu, P. Chen, T. Weng, M. Hong, and X. Lin, “Topology attack and defense for graph neural networks: An optimization perspective,” in IJCAI , 2019, pp. 3961–3967
2019
R. Tang, M. Du, N. Liu, F. Yang, and X. Hu, “An embarrassingly simple approach for trojan attack in deep neural networks,” in KDD , 2020, pp. 218–228
2020
Later among the works it cites.
H. Chang, Y. Rong, T. Xu, W. Huang, H. Zhang, P. Cui, W. Zhu, and J. Huang, “A restricted black-box adversarial framework towards attacking graph embedding models,” in AAAI , 2020, pp. 3389–3396
2020
Later among the works it cites.
J. Li, H. Zhang, Z. Han, Y. Rong, H. Cheng, and J. Huang, “Adversarial attack on community detection by hiding individuals,” in WWW , 2020, pp. 917–927
2020
Later among the works it cites.
Y. Sun, S. Wang, X. Tang, T. Hsieh, and V. G. Honavar, “Adversarial attacks on graph neural networks via node injections: A hierarchical reinforcement learning approach,” in WWW , 2020, pp. 673–683
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
D. Zügner and S. Günnemann, “Certifiable robustness and robust training for graph convolutional networks,” in KDD , 2019, pp. 246–256
2019
Cited alongside, same era.
A. Bojchevski and S. Günnemann, “Certifiable robustness to graph perturbations,” in NeurIPS , 2019, pp. 8317–8328
2019
Cited alongside, same era.
S. Hou, Y. Fan, Y. Zhang, Y. Ye, J. Lei, W. Wan, J. Wang, Q. Xiong, and F. Shao, “ α \alpha Cyber : Enhancing robustness of android malware detection system against adversarial attacks on heterogeneous graph based model,” in CIKM , 2019, pp. 609–618
2019
Cited alongside, same era.
T. Takahashi, “Indirect adversarial attacks via poisoning neighbors for graph convolutional networks,” in Bigdata . IEEE, 2019, pp. 1395–1400
2019
Cited alongside, same era.
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,” IEEE Access , vol. 7, pp. 47 230–47 244, 2019
2019
Cited alongside, same era.
J. Dai, C. Chen, and Y. Li, “A backdoor attack against lstm-based text classification systems,” IEEE Access , vol. 7, pp. 138 872–138 878, 2019
2019
Cited alongside, same era.
2019
Cited alongside, same era.
2020
Later among the works it cites.
Z. Xi, R. Pang, S. Ji, and T. Wang, “Graph backdoor,” CoRR , vol. abs/2006.11890, 2020
2020
Later among the works it cites.
——, “Certifiable robustness of graph convolutional networks under structure perturbations,” in KDD , 2020, pp. 1656–1665
2020
Later among the works it cites.
2020
Later among the works it cites.
J. Wang, M. Luo, F. Suya, J. Li, Z. Yang, and Q. Zheng, “Scalable attack on graph data by injecting vicious nodes,” Data Min. Knowl. Discov. , pp. 1363–1389, 2020
2020
Later among the works it cites.
Y. Sun, S. Wang, X. Tang, T. Hsieh, and V. G. Honavar, “Adversarial attacks on graph neural networks via node injections: A hierarchical reinforcement learning approach,” in WWW , 2020, pp. 673–683
2020
Later among the works it cites.
A. S. Rakin, Z. He, and D. Fan, “TBT: targeted neural network attack with bit trojan,” in CVPR , 2020, pp. 13 195–13 204
2020
Later among the works it cites.
K. Kurita, P. Michel, and G. Neubig, “Weight poisoning attacks on pretrained models,” in ACL , 2020, pp. 2793–2806
2020
Later among the works it cites.
S. Tao, Q. Cao, H. Shen, J. Huang, Y. Wu, and X. Cheng, “Single node injection attack against graph neural networks,” 2021
2021
Later among the works it cites.
Y. Yao, H. Li, H. Zheng, and B. Y. Zhao, “Latent backdoor attacks on deep neural networks,” in CCS , 2019, pp. 2041–2055
2055
Closest in time.