{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:NP427IBVLKDIGQ6TSKIEACZ3ZV","short_pith_number":"pith:NP427IBV","schema_version":"1.0","canonical_sha256":"6bf9afa0355a868343d39290400b3bcd4aba6495031ed994324faa90159fc8e5","source":{"kind":"arxiv","id":"2605.16815","version":1},"attestation_state":"computed","paper":{"title":"Universal Graph Backdoor Defense: A Feature-based Homophily Perspective","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors.","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chen Chen, Fan Li, Mengting Pan, Xiaoyang Wang","submitted_at":"2026-05-16T05:15:36Z","abstract_excerpt":"Graph neural networks (GNNs) have achieved remarkable success in relational learning. However, their vulnerability to graph backdoor attacks (GBAs) poses a significant barrier to broader adoption in high-stakes applications. Despite recent advances in graph backdoor defense (GBD), existing methods primarily focus on subgraph-based GBAs, relying on the assumption that poisoned target nodes are explicitly connected to subgraph triggers. Our empirical results reveal that such structure-centric approaches fail to defend against emerging feature-based GBAs that preserve graph topology. Therefore, i"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":true,"formal_links_present":true},"canonical_record":{"source":{"id":"2605.16815","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-16T05:15:36Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"f110fecc48bb828ecbe5ae4c517e5a106ad5bfbaed2f091c9c264d159b34ea31","abstract_canon_sha256":"1817769733c0fbcbf8ece0b86f45e84cd424d0f24fbf2e465514dc87d6b7bce0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:03:23.949556Z","signature_b64":"5ht92rHtuUL7tPYgVEx5EV33eDMa6DT4tSj/DD1OqjnjBbHaMq2DnhiKaXPO1QYL36nSdT5tCHncpHchFpmOAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6bf9afa0355a868343d39290400b3bcd4aba6495031ed994324faa90159fc8e5","last_reissued_at":"2026-05-20T00:03:23.948587Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:03:23.948587Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Universal Graph Backdoor Defense: A Feature-based Homophily Perspective","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors.","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chen Chen, Fan Li, Mengting Pan, Xiaoyang Wang","submitted_at":"2026-05-16T05:15:36Z","abstract_excerpt":"Graph neural networks (GNNs) have achieved remarkable success in relational learning. However, their vulnerability to graph backdoor attacks (GBAs) poses a significant barrier to broader adoption in high-stakes applications. Despite recent advances in graph backdoor defense (GBD), existing methods primarily focus on subgraph-based GBAs, relying on the assumption that poisoned target nodes are explicitly connected to subgraph triggers. Our empirical results reveal that such structure-centric approaches fail to defend against emerging feature-based GBAs that preserve graph topology. Therefore, i"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Regardless of trigger mechanisms, backdoors induced by GBAs exhibit lower feature-based homophily than clean nodes, indicating a discrepancy in local feature similarity that can be leveraged for detection.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The assumption that node-level local feature consistency modeled by a neighbor-aware reconstruction loss can reliably distinguish backdoors from clean nodes without excessive false positives or noise that the robust training cannot mitigate.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"The paper proposes a universal defense against subgraph-based and feature-based graph backdoor attacks on GNNs by exploiting lower feature-based homophily in backdoored nodes via neighbor-aware reconstruction loss and robust training.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"b60f3f4b7fa095155e5624edf0c9981f39014e1f85b175baf25737e7e774fe13"},"source":{"id":"2605.16815","kind":"arxiv","version":1},"verdict":{"id":"e6359633-d8b0-4bb8-9afc-e1f85c7a3c52","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-19T21:07:25.367222Z","strongest_claim":"Regardless of trigger mechanisms, backdoors induced by GBAs exhibit lower feature-based homophily than clean nodes, indicating a discrepancy in local feature similarity that can be leveraged for detection.","one_line_summary":"The paper proposes a universal defense against subgraph-based and feature-based graph backdoor attacks on GNNs by exploiting lower feature-based homophily in backdoored nodes via neighbor-aware reconstruction loss and robust training.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The assumption that node-level local feature consistency modeled by a neighbor-aware reconstruction loss can reliably distinguish backdoors from clean nodes without excessive false positives or noise that the robust training cannot mitigate.","pith_extraction_headline":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.16815/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"doi_title_agreement","ran_at":"2026-05-19T21:31:19.257123Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_compliance","ran_at":"2026-05-19T21:21:17.239303Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"claim_evidence","ran_at":"2026-05-19T19:01:56.274020Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-19T18:33:26.413781Z","status":"skipped","version":"1.0.0","findings_count":0}],"snapshot_sha256":"68d2c76840276fa645d6c86709d4d9518a30ae13694aaeac4a0bf2b4e5d57392"},"references":{"count":55,"sample":[{"doi":"","year":2018,"title":"Relational inductive biases, deep learning, and graph networks","work_id":"858410c0-7a66-4b27-b4e5-49aee9725be0","ref_index":1,"cited_arxiv_id":"1806.01261","is_internal_anchor":true},{"doi":"","year":2021,"title":"Pietro Bongini, Monica Bianchini, and Franco Scarselli. 2021. Molecular gen- erative graph neural networks for drug discovery.Neurocomputing450 (2021), 242–252","work_id":"d9326a33-57bf-46af-806d-890d3b205f25","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2017,"title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","work_id":"bb1fb326-f0f6-4c72-a4d2-eb7f0707b971","ref_index":3,"cited_arxiv_id":"1712.05526","is_internal_anchor":true},{"doi":"","year":null,"title":"Yang Chen, Zhonglin Ye, Haixing Zhao, Ying Wang, and Subrata Kumar Sarker","work_id":"a724736d-4217-4816-a76f-566e8df05b5b","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2023,"title":"Feature-Based Graph Backdoor Attack in the Node Classification Task.Int. J. Intell. Syst.2023 (Jan. 2023), 13 pages","work_id":"368af145-5515-4792-9f02-b6e14f4bb9b9","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":55,"snapshot_sha256":"167d54753a1058a9ae03b05ea35c83785bbdd9de95c0efb7d84f4ab79d58390b","internal_anchors":2},"formal_canon":{"evidence_count":2,"snapshot_sha256":"cfb4ad46b469227129b24144046851b412c2ee94aa16a4d6db721f2f77f3dba1"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.16815","created_at":"2026-05-20T00:03:23.948774+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.16815v1","created_at":"2026-05-20T00:03:23.948774+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.16815","created_at":"2026-05-20T00:03:23.948774+00:00"},{"alias_kind":"pith_short_12","alias_value":"NP427IBVLKDI","created_at":"2026-05-20T00:03:23.948774+00:00"},{"alias_kind":"pith_short_16","alias_value":"NP427IBVLKDIGQ6T","created_at":"2026-05-20T00:03:23.948774+00:00"},{"alias_kind":"pith_short_8","alias_value":"NP427IBV","created_at":"2026-05-20T00:03:23.948774+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":2,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV","json":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV.json","graph_json":"https://pith.science/api/pith-number/NP427IBVLKDIGQ6TSKIEACZ3ZV/graph.json","events_json":"https://pith.science/api/pith-number/NP427IBVLKDIGQ6TSKIEACZ3ZV/events.json","paper":"https://pith.science/paper/NP427IBV"},"agent_actions":{"view_html":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV","download_json":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV.json","view_paper":"https://pith.science/paper/NP427IBV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.16815&json=true","fetch_graph":"https://pith.science/api/pith-number/NP427IBVLKDIGQ6TSKIEACZ3ZV/graph.json","fetch_events":"https://pith.science/api/pith-number/NP427IBVLKDIGQ6TSKIEACZ3ZV/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV/action/timestamp_anchor","attest_storage":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV/action/storage_attestation","attest_author":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV/action/author_attestation","sign_citation":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV/action/citation_signature","submit_replication":"https://pith.science/pith/NP427IBVLKDIGQ6TSKIEACZ3ZV/action/replication_record"}},"created_at":"2026-05-20T00:03:23.948774+00:00","updated_at":"2026-05-20T00:03:23.948774+00:00"}