{"as_of":"2026-08-13T00:39:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:3bbcb2d988e38a7894fba4b1e493c958398cce58f94bd18dcc03ec63c91ab0df","coverage":[{"denominator":57,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":57,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-12T11:48:09.554667Z","state":"measured"},{"denominator":57,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":57,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-12T06:34:41.77262+00:00","state":"measured"},{"denominator":0,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"cited_works","source_observed_at":null,"state":"measured"}],"external_citation_measurements":[],"inbound":[],"links":{"evidence":"/evidence","html":"/paper/2411.18648/citation-record","integrity":"/paper/2411.18648/integrity","json":"/paper/2411.18648/citation-record.json","paper":"/paper/2411.18648"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.382743Z","title":"Graph neural networks for social recommendation,","venue":null,"work_id":"1d06e5d3-12d0-4c72-bb8a-2891f330cec9","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.304935Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:74f1b6bacfe5969596d98bd832088aa9b4a6aa5d46a2f5134725b985c2c619d5","observation_id":"7485f764-06f4-4d73-9bbc-25c6ce4dcc5d","resolution":{"observed_at":"2026-08-12T11:48:10.387173Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.369087Z","title":"Random graph models of social networks,","venue":null,"work_id":"e4b74233-f171-4f31-9ce6-0f35344c0706","year":2002},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.310053Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:3f72c85402b5c7b3f5d65185128bc50e8c75a93d954ae447020db8c437d8575e","observation_id":"3592f5eb-80fc-4b98-9a12-903285058d8d","resolution":{"observed_at":"2026-08-12T11:48:10.373485Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.355050Z","title":"Trinajstic, Chemical graph theory","venue":null,"work_id":"068deb13-cec7-4106-8aad-ef513fd7ee71","year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.314578Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:b960e39e952d6600439e8399d69d2c99fd248ac357908b1f7fa43083f7f81295","observation_id":"90b56844-6987-48ee-aaf5-27db9c96bbed","resolution":{"observed_at":"2026-08-12T11:48:10.359605Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.341251Z","title":"Beyond homophily in graph neural networks: Current limitations and effective designs,","venue":null,"work_id":"9b3b82c4-4a89-44b3-9d33-de2f7d52a1f3","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.319342Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:327d772fbfd1b0abf07cd007b32440d54f30b4777eb997770031380d0727ca7a","observation_id":"315ab3f8-a176-44fd-9e74-320d114b6108","resolution":{"observed_at":"2026-08-12T11:48:10.345730Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.326852Z","title":"Powerful graph convolutional networks with adaptive propagation mechanism for homophily and heterophily,","venue":null,"work_id":"71f47577-c8e8-4178-bbd5-88739483fff1","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.324092Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:c42a473af5f234202f0de1b2129dc5f9482448f6464fa17d05f214282b2b2208","observation_id":"5197be1e-14c4-4f3e-8646-54c357756bf3","resolution":{"observed_at":"2026-08-12T11:48:10.331556Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1609.02907","last_updated":"2017-02-22T09:55:36Z","snapshot_observed_at":"2026-07-06T05:10:16.862707Z","submitted_at":"2016-09-09T19:48:41Z","title":"Semi-Supervised Classification with Graph Convolutional Networks","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1609.02907","snapshot_observed_at":"2026-08-12T11:48:09.328783Z","title":"Semi-supervised classi- fication with graph convolutional networks,","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.328783Z"},"links":{"cited_paper":"/paper/1609.02907","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:f108986115eed4200068ec0d6698b6d941755e4af1b81386641a207b5bd87229","observation_id":"f27110b5-5bcc-401a-9a0d-5659c0afe2d2","resolution":{"observed_at":"2026-08-12T11:48:09.328783Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.334101Z","title":"Inductive representation learning on large graphs,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.334101Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:762d7068b4e23cfb27781bd6aedd1841d27441b4ef1168e0ed0ae96168fe7ee0","observation_id":"3d99f80c-faa0-4fdf-98c7-a718e040f0d4","resolution":{"observed_at":"2026-08-12T11:48:09.334101Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.302740Z","title":"Gated graph sequence neural networks,","venue":null,"work_id":"ed8ca259-d558-4264-b6b1-43d55ab11dae","year":2016},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.338497Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:93649929f5a0a3d5691a3441567bc4be9cf5fed8fef07b3282e6830aff79a39f","observation_id":"627694c8-c0aa-440a-ade1-35a28106455a","resolution":{"observed_at":"2026-08-12T11:48:10.307508Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.289101Z","title":"Predicting drug–target interaction using a novel graph neural network with 3d structure-embedded graph representation,","venue":null,"work_id":"dd460066-38a5-4214-be65-fbb5086094ac","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.342952Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:66506e85f72f3f74820455b2981651cf5c8a2c25b52391ea958e0a184cb9fd34","observation_id":"2c770ef9-cdbe-4a83-9684-e32f6f998387","resolution":{"observed_at":"2026-08-12T11:48:10.293617Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.274623Z","title":"Kgnn: Knowledge graph neural network for drug-drug interaction prediction","venue":null,"work_id":"73565906-b952-4faa-bc5b-5e435ae32cda","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.347434Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:22c8bea94b0b1ca63baac0db6350bc33d89ed9f4e125586548792d650520fb6b","observation_id":"ffe35faa-2c8c-4f66-82f3-be5a170a3520","resolution":{"observed_at":"2026-08-12T11:48:10.279363Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.260390Z","title":"Could graph neural networks learn better molecular representation for drug discovery? a comparison study of descriptor-based and graph-based models,","venue":null,"work_id":"8411052c-81f1-4be0-b86a-0f10a54bb620","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.351605Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:65a8c31f9cbf93912f3526dc2b686f90aa8edda15c47afb8b66e622ba86d014a","observation_id":"633a7e61-ac37-440d-a759-0e16316084cf","resolution":{"observed_at":"2026-08-12T11:48:10.265143Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.246340Z","title":"Graph neural network for traffic forecasting: A survey,","venue":null,"work_id":"0634cead-3a62-4edf-9237-b839b553ca65","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.356248Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ec46ece91817797877684afb4e10f70125b9881e21a96571f68441f7ed32a055","observation_id":"95bec72d-59eb-4ad5-ac9e-09ae9b1c87a6","resolution":{"observed_at":"2026-08-12T11:48:10.251041Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.232669Z","title":"Point-gnn: Graph neural network for 3d object detection in a point cloud,","venue":null,"work_id":"47906c4b-c2f0-48ed-b72d-55a744328868","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.360517Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:16d07e14677d97da48aeb951d7818a894570e77d8ac7fbb193c16b35f4705bec","observation_id":"b272f3ca-fe82-4a2e-97db-2cdb2f018d78","resolution":{"observed_at":"2026-08-12T11:48:10.237081Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.218981Z","title":"Neural graph collaborative filtering,","venue":null,"work_id":"3381e3eb-b6c1-4969-9124-7e5f6dcce194","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.365039Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:e662dbacd75a9e5dcd3211d9330783e6d3a5b38564821503d52cc1c17766b4c5","observation_id":"a9dac2d9-94ae-4da7-8844-c7a00cff9cc5","resolution":{"observed_at":"2026-08-12T11:48:10.223544Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.203580Z","title":"Scaling graph neural networks with approxi- mate pagerank,","venue":null,"work_id":"0403bf72-368c-413b-a547-29c29b7871a8","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.369292Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:05365e98110aa7d50d5236fb919c8348dbb5d4e60e8f1e5909bc8f0801f36fc5","observation_id":"5ea2f21d-3674-490c-a62d-eca1933e6311","resolution":{"observed_at":"2026-08-12T11:48:10.209031Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1810.05997","last_updated":"2022-04-05T11:39:26Z","snapshot_observed_at":"2026-07-06T07:07:56.005107Z","submitted_at":"2018-10-14T08:36:54Z","title":"Predict then Propagate: Graph Neural Networks meet Personalized PageRank","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1810.05997","snapshot_observed_at":"2026-08-12T11:48:09.373547Z","title":"Predict then propagate: Graph neural networks meet personal- ized pagerank,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.373547Z"},"links":{"cited_paper":"/paper/1810.05997","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:7f4437ad29570bbc41eb868b6af47ea0a55ce3535d7657be738e376961483c21","observation_id":"cdb881e4-ece8-4679-9f83-30728c9d9aac","resolution":{"observed_at":"2026-08-12T11:48:09.373547Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.188741Z","title":"Graph backdoor,","venue":null,"work_id":"22079345-f9c0-4f42-9998-0a4dc021bd5a","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.378062Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:27978cd4916a2428e035196f278cbc712c5936f6c19907337aec5105fd0c0e61","observation_id":"7a382b2d-d580-46fb-8215-ea15e39b95b9","resolution":{"observed_at":"2026-08-12T11:48:10.193153Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.174338Z","title":"Backdoor attacks to graph neural networks,","venue":null,"work_id":"13621dda-0751-4fee-8a7d-024d754cb049","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.382356Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:8db55bb7373e9a46eb3b9631f76264a0cf6fda5eeb13fbe6e913957d01e2a9de","observation_id":"24976171-aebd-417a-b7ea-48c509edcd4b","resolution":{"observed_at":"2026-08-12T11:48:10.178936Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.159170Z","title":"Transferable graph backdoor attack,","venue":null,"work_id":"d6c0e520-65c8-4628-a9b7-b663993bb9af","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.387512Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:f2c44b28cfa63e686b0d5973bcbc59b8561d80b75a3ec9fe9ce59668f9aabc5f","observation_id":"b1200a99-b4ae-4b61-841d-0b156d0707c7","resolution":{"observed_at":"2026-08-12T11:48:10.164148Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.144937Z","title":"Adversarial neuron pruning purifies backdoored deep models,","venue":null,"work_id":"acb4ba9a-b5b1-4eab-8f33-88dcdc0f71e5","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.391934Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:4feb1a1d162045ba1d1d63661481d3b7529a2077095061165db1ef39f87c353d","observation_id":"0a77a778-5674-48ed-8ba5-3aaf82b3eaee","resolution":{"observed_at":"2026-08-12T11:48:10.149554Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.130629Z","title":"Anti- backdoor learning: Training clean models on poisoned data,","venue":null,"work_id":"ed4e9dc9-4710-4f7e-b59a-5420dd4ac32f","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.396341Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ecea511d40e4fd578b68131ecb010d991855aa64c3bbfcc1151b8bb65f675367","observation_id":"5f0a78dc-5741-4199-ad41-9ab2e9c77006","resolution":{"observed_at":"2026-08-12T11:48:10.135419Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2212.09067","last_updated":"2022-12-18T11:30:59Z","snapshot_observed_at":"2026-08-05T17:14:24.121423Z","submitted_at":"2022-12-18T11:30:59Z","title":"Fine-Tuning Is All You Need to Mitigate Backdoor Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2212.09067","snapshot_observed_at":"2026-08-12T11:48:09.400727Z","title":"Fine-tuning is all you need to mitigate backdoor at- tacks,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.400727Z"},"links":{"cited_paper":"/paper/2212.09067","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:53c5c81354a2ad1f59fea6fd878175c65cb35463f7f311df3732448d106b5ca9","observation_id":"3bda1cc4-d3d1-44cf-b2b0-2eab37928c83","resolution":{"observed_at":"2026-08-12T11:48:09.400727Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1409.1556","last_updated":"2015-04-10T16:25:04Z","snapshot_observed_at":"2026-08-12T14:19:29.389332Z","submitted_at":"2014-09-04T19:48:04Z","title":"Very Deep Convolutional Networks for Large-Scale Image Recognition","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1409.1556","snapshot_observed_at":"2026-08-12T11:48:09.405469Z","title":"Very deep convolu- tional networks for large-scale image recognition,","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.405469Z"},"links":{"cited_paper":"/paper/1409.1556","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:fb85858886decda1cb924d2f37fb267eaf2c07ce2eeb3d9aa4613af07926a87c","observation_id":"1f0640cd-0178-490c-a9ab-dfa0dba50722","resolution":{"observed_at":"2026-08-12T11:48:09.405469Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.410415Z","title":"Deep residual learning for image recognition,","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.410415Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:b77ebd526bc172dea9916224e6ccb423045bb10a1c3b29013d1e3b09f60b5463","observation_id":"1fa5f7e3-ca9d-4d04-9532-b308ea7426a5","resolution":{"observed_at":"2026-08-12T11:48:09.410415Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.414574Z","title":"Attention is all you need,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.414574Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:d823b140802b4169397a29b51bc272865948a70905e6c30f8bae4bcc10ec9666","observation_id":"299a7c7d-a6b5-4405-a97d-fe35652c0df6","resolution":{"observed_at":"2026-08-12T11:48:09.414574Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.097196Z","title":"Spectral signatures in backdoor attacks,","venue":null,"work_id":"a1194230-ead2-452c-b557-ac333f769850","year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.418732Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:b70029363a4944244444cd9dea7b2975cf7678ae055917c0141204d3bce2d224","observation_id":"cebfe35c-1d34-4079-b531-09b7d2ef5877","resolution":{"observed_at":"2026-08-12T11:48:10.102032Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1712.05526","last_updated":"2017-12-15T04:26:26Z","snapshot_observed_at":"2026-07-06T06:14:30.795326Z","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1712.05526","snapshot_observed_at":"2026-08-12T11:48:09.422784Z","title":"Targeted backdoor attacks on deep learning systems using data poisoning,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.422784Z"},"links":{"cited_paper":"/paper/1712.05526","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:0c9f94b6445f830a84f0cb66328731f14ec9a142d95e8469ea5f001d7b6f661b","observation_id":"d6c41fb2-b5f5-4883-87bc-1c8e716ad642","resolution":{"observed_at":"2026-08-12T11:48:09.422784Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1708.06733","last_updated":"2019-03-11T20:45:33Z","snapshot_observed_at":"2026-08-12T15:43:59.037380Z","submitted_at":"2017-08-22T17:31:54Z","title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1708.06733","snapshot_observed_at":"2026-08-12T11:48:09.428229Z","title":"Badnets: Iden- tifying vulnerabilities in the machine learning model supply chain,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.428229Z"},"links":{"cited_paper":"/paper/1708.06733","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ecda30fab7845dd4076e8eb51d48e8a799637a7c8fc7f3fa382d69488be65c44","observation_id":"a2c95cc2-430a-457c-8f1a-5c843b53c272","resolution":{"observed_at":"2026-08-12T11:48:09.428229Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.083097Z","title":"Reflection backdoor: A natural backdoor attack on deep neural networks,","venue":null,"work_id":"feba8f9d-a403-4a1c-8443-f1702c448838","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.432727Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:3588c649faf867714dd696dd3743042bc684f15a285f3a4ece0245013f1e0eae","observation_id":"5bf00900-bbc4-4084-ac14-12806369dc64","resolution":{"observed_at":"2026-08-12T11:48:10.087806Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.068327Z","title":"Re- thinking the reverse-engineering of trojan triggers,","venue":null,"work_id":"79db5e2a-411d-4a67-9a20-1f09190de8b7","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.437026Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:547e86899ee14e750ac1c2100208c0477a9ad232f48b2696ac3e3206a634b505","observation_id":"0f7d6d8c-1da4-438d-9ad5-df652220cb3a","resolution":{"observed_at":"2026-08-12T11:48:10.073412Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.053781Z","title":"Few-shot backdoor defense using shapley estimation,","venue":null,"work_id":"6037001a-5514-4342-9d43-ef1cae85d852","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.441228Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:a2b9041e355c642f75a77f8a887546c9a2072348621af396025a8aac61a5825c","observation_id":"8fc8d755-3132-4057-a19e-76acc99b2e04","resolution":{"observed_at":"2026-08-12T11:48:10.058345Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.039808Z","title":"Unnotice- able backdoor attacks on graph neural networks,","venue":null,"work_id":"3997177e-722b-48f4-972b-963a3aabf520","year":2023},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.445396Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ce75f23c5af3f1945a877cb8bc03408df6bf28f24513faaec4a041f530495bec","observation_id":"1a981ac3-9aec-4644-a8e1-0d5a6644d0dd","resolution":{"observed_at":"2026-08-12T11:48:10.044211Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.026039Z","title":"Textual backdoor attack for the text classification system,","venue":null,"work_id":"a3adc045-0f8a-45d3-90b2-8441d7083527","year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.449668Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:b056d855c5317a478d9595ade3ef2e8f87224d30f416efe16f8ab249deb7ffeb","observation_id":"3897a9a8-de8a-431d-8a98-292098bf4070","resolution":{"observed_at":"2026-08-12T11:48:10.030581Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2110.07139","last_updated":"2021-10-14T03:54:16Z","snapshot_observed_at":"2026-08-11T11:12:33.970334Z","submitted_at":"2021-10-14T03:54:16Z","title":"Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style Transfer","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2110.07139","snapshot_observed_at":"2026-08-12T11:48:09.453816Z","title":"Mind the style of text! adversarial and backdoor attacks based on text style transfer,","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.453816Z"},"links":{"cited_paper":"/paper/2110.07139","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:d327f7676ca49eb79a763dc138828979b56e6b4b9eace61ef84002c6f0a17e89","observation_id":"e0ee6e92-964a-44ed-8a57-b5af50e3d613","resolution":{"observed_at":"2026-08-12T11:48:09.453816Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:10.010800Z","title":"A backdoor attack against lstm-based text classification systems,","venue":null,"work_id":"b299ae2b-9f32-4c0b-8a2e-e6df5aa63bec","year":2019},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.458363Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:f39de824f4afbef06a7885dfcf3c31d2200fa7e09c705fb19b877174d7cb77f2","observation_id":"f7e1401c-8d6c-4961-877f-6537396f7855","resolution":{"observed_at":"2026-08-12T11:48:10.015965Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.995546Z","title":"How does heterophily impact the robustness of graph neural networks? theoretical connections and practical implications,","venue":null,"work_id":"8ab48032-047f-4c64-9a6a-5c3199bed397","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.462650Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:77463941bb22e308afbb9ba5885eb51b6e602be6a6dec21306e0d45b6206c7f0","observation_id":"7aadce62-d3d1-4bb5-81df-7a8087c8b410","resolution":{"observed_at":"2026-08-12T11:48:10.000280Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.981349Z","title":"Finding global homophily in graph neural networks when meeting heterophily,","venue":null,"work_id":"e3d9f5e1-b638-4439-8b75-04b2cc34d258","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.466836Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:bf0a106f15a6e6b10406e78faec44db4baf8138e6850567345beae1a746a5181","observation_id":"bd2d5980-58da-483a-b78c-8ec28148c055","resolution":{"observed_at":"2026-08-12T11:48:09.985963Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.967127Z","title":"Grad-cam: Visual explanations from deep networks via gradient-based localization,","venue":null,"work_id":"b80e8e81-584d-4481-9d54-4c1e3b8640eb","year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.470983Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:617a1c3c18d522d44120d03ff10bcb6cd34c95ee46293e8172e8add76b1869c5","observation_id":"639457db-30ee-40c8-be47-e0472f2d8be7","resolution":{"observed_at":"2026-08-12T11:48:09.971886Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2202.10582","last_updated":"2022-02-18T05:00:08Z","snapshot_observed_at":"2026-07-06T12:40:13.028389Z","submitted_at":"2022-02-18T05:00:08Z","title":"Debiasing Backdoor Attack: A Benign Application of Backdoor Attack in Eliminating Data Bias","version":1},"cited_work":{"arxiv_id":"2202.10582","doi":null,"metadata_source":"pith","pith_arxiv_id":"2202.10582","snapshot_observed_at":"2026-08-12T11:48:09.663343Z","title":"Debiasing Backdoor Attack: A Benign Application of Backdoor Attack in Eliminating Data Bias","venue":"cs.CR","work_id":"3624557a-36b2-4f0f-9462-2f54fec06127","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.475323Z"},"links":{"cited_paper":"/paper/2202.10582","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:79d74861d035ba568833f1f7ba660f100706361882c5ea071e91f3aac8476b20","observation_id":"85587266-037b-41ef-b1ad-ed11b470026a","resolution":{"observed_at":"2026-08-12T11:48:09.670096Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.953258Z","title":"Iam graph database reposi- tory for graph based pattern recognition and machine learning,","venue":null,"work_id":"37bc6ad0-e2c7-421e-9b57-b89a3d022df0","year":2008},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.479973Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:cec909d6575f83f48ec1e169dd9d43a82b97b2295ee1b018e0c252800f1855b9","observation_id":"fc9d4e3f-ccd1-4ca8-94c4-7955d3c9ce5b","resolution":{"observed_at":"2026-08-12T11:48:09.957849Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.939048Z","title":"Protein function prediction via graph kernels,","venue":null,"work_id":"facfe6ee-94e1-4684-b7a5-973847acdfe7","year":2005},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.484128Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:2d4f90692f8cbae683ee6a0a8917e3cb1f3f3bfa7773e5e318324714ac3f37f3","observation_id":"fc33b25d-ba7a-4523-96b7-0da3ec5d5c31","resolution":{"observed_at":"2026-08-12T11:48:09.943629Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.488440Z","title":"Automating the construction of internet portals with machine learning,","venue":null,"work_id":null,"year":2000},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.488440Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:e5572b7d3fb7a93148001a490039cd838ae4353f62f3975a0e124b492862bff0","observation_id":"85d69dc5-dc92-4da4-881c-aceba0662f55","resolution":{"observed_at":"2026-08-12T11:48:09.488440Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.914957Z","title":"Collective classification in network data,","venue":null,"work_id":"198665ba-e359-43f9-9175-c49e6fe8b7e3","year":2008},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.492528Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:53ebcc5c078ad1352ccab8cadc5ec4b8218519ed1235055025fcb0171755e1ad","observation_id":"745abff6-65ad-4c80-b622-0520aa92747e","resolution":{"observed_at":"2026-08-12T11:48:09.920203Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.900791Z","title":"Open graph benchmark: Datasets for machine learning on graphs,","venue":null,"work_id":"120ffee4-d40c-4e92-a772-bffeb52c316c","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.497009Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:ab817a2e52fdc5ac70534398004b5deb663ced5019ca0c1201a3098653c683c9","observation_id":"9d3861a7-c558-4c13-9035-b89b4ad9091c","resolution":{"observed_at":"2026-08-12T11:48:09.905626Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1907.04931","last_updated":"2020-02-16T00:42:48Z","snapshot_observed_at":"2026-08-05T00:16:40.110456Z","submitted_at":"2019-07-10T21:11:13Z","title":"GraphSAINT: Graph Sampling Based Inductive Learning Method","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1907.04931","snapshot_observed_at":"2026-08-12T11:48:09.501189Z","title":"Graphsaint: Graph sampling based induc- tive learning method,","venue":null,"work_id":null,"year":1907},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.501189Z"},"links":{"cited_paper":"/paper/1907.04931","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:3dc0f70e2fd060c584c6d75f16f02dda9251221ca682d4f75950293e7509b7aa","observation_id":"d6eeae10-ca14-44fc-82a6-ca82ef42c892","resolution":{"observed_at":"2026-08-12T11:48:09.501189Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.886132Z","title":"Graph informa- tion bottleneck,","venue":null,"work_id":"f039018d-dbce-416e-838c-7d685835d162","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.505640Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:64ef1928c7d087a01af423dc8f19cf3200dc664dc27a469a5770c6c20fb14aeb","observation_id":"292197e0-1a41-4c29-b279-e26e29c36dfc","resolution":{"observed_at":"2026-08-12T11:48:09.890886Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1710.10903","last_updated":"2018-02-04T19:13:29Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2017-10-30T12:41:12Z","title":"Graph Attention Networks","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1710.10903","snapshot_observed_at":"2026-08-12T11:48:09.509714Z","title":"Graph attention networks,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.509714Z"},"links":{"cited_paper":"/paper/1710.10903","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:a180c98fb1b220107f6eff555e30710e550dcf4e682925fdddf8269b14251817","observation_id":"94f8c77a-f4d7-4f86-a0fa-bd1a1e393343","resolution":{"observed_at":"2026-08-12T11:48:09.509714Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1808.10307","last_updated":"2018-08-30T14:13:39Z","snapshot_observed_at":"2026-07-06T06:58:19.889839Z","submitted_at":"2018-08-30T14:13:39Z","title":"Backdoor Embedding in Convolutional Neural Network Models via Invisible Perturbation","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1808.10307","snapshot_observed_at":"2026-08-12T11:48:09.514129Z","title":"Backdoor embedding in convolutional neural net- work models via invisible perturbation,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.514129Z"},"links":{"cited_paper":"/paper/1808.10307","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:dd0d3e5b5ce91434126f2c8596ccc02992f019addd93e870d71af43581b71abb","observation_id":"d82b4d8d-374a-4e84-8b27-50f6a59a38ec","resolution":{"observed_at":"2026-08-12T11:48:09.514129Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.870935Z","title":"Clean-label backdoor attacks on video recognition models,","venue":null,"work_id":"264535fc-dc69-4492-9414-eea731d0df96","year":2020},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.518506Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:1f7b7b03bcb7a0cc7e5d3a92d5ce4e38f3f757820f7d7d6901ddde8d3208624c","observation_id":"65bad140-d3f6-4300-8e4b-ca2f3e8183bb","resolution":{"observed_at":"2026-08-12T11:48:09.875993Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2202.03423","last_updated":"2022-02-05T03:34:01Z","snapshot_observed_at":"2026-08-10T20:21:25.993056Z","submitted_at":"2022-02-05T03:34:01Z","title":"Backdoor Defense via Decoupling the Training Process","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2202.03423","snapshot_observed_at":"2026-08-12T11:48:09.522831Z","title":"Backdoor defense via decoupling the training process,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.522831Z"},"links":{"cited_paper":"/paper/2202.03423","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:61292dc31b72047bdc0515a8d06afe2497d8165ead1fd533ce96e160abc9c74c","observation_id":"1440e17b-67f1-4c5f-b6c5-9c2d135720e1","resolution":{"observed_at":"2026-08-12T11:48:09.522831Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2209.02902","last_updated":"2022-09-07T03:19:29Z","snapshot_observed_at":"2026-07-06T13:49:37.223049Z","submitted_at":"2022-09-07T03:19:29Z","title":"Defending Against Backdoor Attack on Graph Nerual Network by Explainability","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2209.02902","snapshot_observed_at":"2026-08-12T11:48:09.527428Z","title":"Defending against backdoor attack on graph nerual network by explainability,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.527428Z"},"links":{"cited_paper":"/paper/2209.02902","citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:8a220297b73fa09cb84d6f77fcda121db1e492c7eae45329b3ad0dacc961cb39","observation_id":"79e395ad-2347-48cf-9661-f0bccdbb6e99","resolution":{"observed_at":"2026-08-12T11:48:09.527428Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.855763Z","title":"Svd-gcn: A simpli- fied graph convolution paradigm for recommendation,","venue":null,"work_id":"32aacc8d-5eee-4a33-b1d2-45eca186a69e","year":2022},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.532309Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:155270f84e322b4aef2551f322705e274e4d3ee12dc950c7181d2dece99482dd","observation_id":"8c77ebb2-2302-42d5-95b7-c373cb296d77","resolution":{"observed_at":"2026-08-12T11:48:09.860865Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.840194Z","title":"In this paper, the experiment JOURNAL OF LATEX CLASS FILES, VOL","venue":null,"work_id":"96772a61-ae07-40bb-a423-a2ced6407a49","year":2015},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.536986Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:214de720ba327a57a0314e396c57542a33c0f533ed6bef0969a5671e5b3e763f","observation_id":"9eff147a-48c5-4e6e-bea4-c8f32cfe367a","resolution":{"observed_at":"2026-08-12T11:48:09.844923Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.824877Z","title":null,"venue":null,"work_id":"cb34e54e-1142-440b-b05b-5d7e19f4faf8","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.541005Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:496d3d76fabde9e396b868220bd039b0668bff5a66cacea74ebc09d9d75601a5","observation_id":"13456e22-de08-4569-974a-2bc8a0b361dd","resolution":{"observed_at":"2026-08-12T11:48:09.829579Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.810401Z","title":"For typical graph defense methods,","venue":null,"work_id":"38bc31fb-c470-4687-b1ed-bbdcd1f4065b","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.545763Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:a3ea1129be71d58a107a1e560fcc0e8a53f741adb55874347e91b22adc02ed13","observation_id":"146ed87f-c684-447d-994e-191c3c603bc5","resolution":{"observed_at":"2026-08-12T11:48:09.815073Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.795620Z","title":null,"venue":null,"work_id":"1a844e50-4bda-4e7c-8a81-f631a1618a90","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.550242Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:0d4df02dedc54fc68b9d307b5699cd6d5639c979b201c10a6518574c7eb5fa4f","observation_id":"7596040f-fc68-4881-8a53-967310863afe","resolution":{"observed_at":"2026-08-12T11:48:09.800475Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-12T11:48:09.780795Z","title":"This modification aims to concentrate solely on the features associated with the K-largest singular vectors, thereby enhancing the model’s robustness to perturbations","venue":null,"work_id":"c004a922-114f-4ce7-956c-87e1d09892f9","year":null},"citing_paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning","version":2},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-12T11:48:09.554667Z"},"links":{"citing_paper":"/paper/2411.18648"},"observation_digest":"sha256:854b1cc9ff8be3630572876d7a9cfc82497280d0cc447963eb2f1109170a71e6","observation_id":"6c17c3b3-fba9-474b-8eba-cf64cb53e313","resolution":{"observed_at":"2026-08-12T11:48:09.785514Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}}],"paper":{"arxiv_id":"2411.18648","last_updated":"2024-12-31T02:11:04Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-12T11:39:50.981873Z","submitted_at":"2024-11-26T22:50:53Z","title":"MADE: Graph Backdoor Defense with Masked Unlearning"},"reference_resolution":{"displayed":57,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":18,"verified_exact":1,"verified_fuzzy":38},"total_outbound_references":57},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"thesis":"As of 13 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 0 inbound Pith citation observations for arXiv:2411.18648."}