{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:NP427IBVLKDIGQ6TSKIEACZ3ZV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1817769733c0fbcbf8ece0b86f45e84cd424d0f24fbf2e465514dc87d6b7bce0","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-16T05:15:36Z","title_canon_sha256":"f110fecc48bb828ecbe5ae4c517e5a106ad5bfbaed2f091c9c264d159b34ea31"},"schema_version":"1.0","source":{"id":"2605.16815","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.16815","created_at":"2026-05-20T00:03:23Z"},{"alias_kind":"arxiv_version","alias_value":"2605.16815v1","created_at":"2026-05-20T00:03:23Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.16815","created_at":"2026-05-20T00:03:23Z"},{"alias_kind":"pith_short_12","alias_value":"NP427IBVLKDI","created_at":"2026-05-20T00:03:23Z"},{"alias_kind":"pith_short_16","alias_value":"NP427IBVLKDIGQ6T","created_at":"2026-05-20T00:03:23Z"},{"alias_kind":"pith_short_8","alias_value":"NP427IBV","created_at":"2026-05-20T00:03:23Z"}],"graph_snapshots":[{"event_id":"sha256:6af7dbd2817fe88027f6beb4b2db18e5aa93262c3f2df575e05b3afd32f25bc3","target":"graph","created_at":"2026-05-20T00:03:23Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Regardless of trigger mechanisms, backdoors induced by GBAs exhibit lower feature-based homophily than clean nodes, indicating a discrepancy in local feature similarity that can be leveraged for detection."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The assumption that node-level local feature consistency modeled by a neighbor-aware reconstruction loss can reliably distinguish backdoors from clean nodes without excessive false positives or noise that the robust training cannot mitigate."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"The paper proposes a universal defense against subgraph-based and feature-based graph backdoor attacks on GNNs by exploiting lower feature-based homophily in backdoored nodes via neighbor-aware reconstruction loss and robust training."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors."}],"snapshot_sha256":"b60f3f4b7fa095155e5624edf0c9981f39014e1f85b175baf25737e7e774fe13"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"cfb4ad46b469227129b24144046851b412c2ee94aa16a4d6db721f2f77f3dba1"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"doi_title_agreement","ran_at":"2026-05-19T21:31:19.257123Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T21:21:17.239303Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-19T19:01:56.274020Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T18:33:26.413781Z","status":"skipped","version":"1.0.0"}],"endpoint":"/pith/2605.16815/integrity.json","findings":[],"snapshot_sha256":"68d2c76840276fa645d6c86709d4d9518a30ae13694aaeac4a0bf2b4e5d57392","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Graph neural networks (GNNs) have achieved remarkable success in relational learning. However, their vulnerability to graph backdoor attacks (GBAs) poses a significant barrier to broader adoption in high-stakes applications. Despite recent advances in graph backdoor defense (GBD), existing methods primarily focus on subgraph-based GBAs, relying on the assumption that poisoned target nodes are explicitly connected to subgraph triggers. Our empirical results reveal that such structure-centric approaches fail to defend against emerging feature-based GBAs that preserve graph topology. Therefore, i","authors_text":"Chen Chen, Fan Li, Mengting Pan, Xiaoyang Wang","cross_cats":["cs.LG"],"headline":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-16T05:15:36Z","title":"Universal Graph Backdoor Defense: A Feature-based Homophily Perspective"},"references":{"count":55,"internal_anchors":2,"resolved_work":55,"sample":[{"cited_arxiv_id":"1806.01261","doi":"","is_internal_anchor":true,"ref_index":1,"title":"Relational inductive biases, deep learning, and graph networks","work_id":"858410c0-7a66-4b27-b4e5-49aee9725be0","year":2018},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Pietro Bongini, Monica Bianchini, and Franco Scarselli. 2021. Molecular gen- erative graph neural networks for drug discovery.Neurocomputing450 (2021), 242–252","work_id":"d9326a33-57bf-46af-806d-890d3b205f25","year":2021},{"cited_arxiv_id":"1712.05526","doi":"","is_internal_anchor":true,"ref_index":3,"title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","work_id":"bb1fb326-f0f6-4c72-a4d2-eb7f0707b971","year":2017},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Yang Chen, Zhonglin Ye, Haixing Zhao, Ying Wang, and Subrata Kumar Sarker","work_id":"a724736d-4217-4816-a76f-566e8df05b5b","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Feature-Based Graph Backdoor Attack in the Node Classification Task.Int. J. Intell. Syst.2023 (Jan. 2023), 13 pages","work_id":"368af145-5515-4792-9f02-b6e14f4bb9b9","year":2023}],"snapshot_sha256":"167d54753a1058a9ae03b05ea35c83785bbdd9de95c0efb7d84f4ab79d58390b"},"source":{"id":"2605.16815","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-19T21:07:25.367222Z","id":"e6359633-d8b0-4bb8-9afc-e1f85c7a3c52","model_set":{"reader":"grok-4.3"},"one_line_summary":"The paper proposes a universal defense against subgraph-based and feature-based graph backdoor attacks on GNNs by exploiting lower feature-based homophily in backdoored nodes via neighbor-aware reconstruction loss and robust training.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Backdoors from any graph attack type reduce local feature similarity between nodes and their neighbors.","strongest_claim":"Regardless of trigger mechanisms, backdoors induced by GBAs exhibit lower feature-based homophily than clean nodes, indicating a discrepancy in local feature similarity that can be leveraged for detection.","weakest_assumption":"The assumption that node-level local feature consistency modeled by a neighbor-aware reconstruction loss can reliably distinguish backdoors from clean nodes without excessive false positives or noise that the robust training cannot mitigate."}},"verdict_id":"e6359633-d8b0-4bb8-9afc-e1f85c7a3c52"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4c76054dda90ca68d2ddcb7f40cf88253927da5c97e622916bdba2014a31b128","target":"record","created_at":"2026-05-20T00:03:23Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1817769733c0fbcbf8ece0b86f45e84cd424d0f24fbf2e465514dc87d6b7bce0","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-16T05:15:36Z","title_canon_sha256":"f110fecc48bb828ecbe5ae4c517e5a106ad5bfbaed2f091c9c264d159b34ea31"},"schema_version":"1.0","source":{"id":"2605.16815","kind":"arxiv","version":1}},"canonical_sha256":"6bf9afa0355a868343d39290400b3bcd4aba6495031ed994324faa90159fc8e5","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"6bf9afa0355a868343d39290400b3bcd4aba6495031ed994324faa90159fc8e5","first_computed_at":"2026-05-20T00:03:23.948587Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:03:23.948587Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"5ht92rHtuUL7tPYgVEx5EV33eDMa6DT4tSj/DD1OqjnjBbHaMq2DnhiKaXPO1QYL36nSdT5tCHncpHchFpmOAA==","signature_status":"signed_v1","signed_at":"2026-05-20T00:03:23.949556Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.16815","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4c76054dda90ca68d2ddcb7f40cf88253927da5c97e622916bdba2014a31b128","sha256:6af7dbd2817fe88027f6beb4b2db18e5aa93262c3f2df575e05b3afd32f25bc3"],"state_sha256":"d8da91422b2c4f5098bb9b975cbaf1606738e4342ccb0dbcb493c1ed291d5d7f"}