Date of Award

Summer 8-2026

Document Type

Dissertation

Degree Name

Doctor of Philosophy (PhD)

Department

Computer Science

Program/Concentration

Computer Science

Committee Director

Rui Ning

Committee Member

Lusi Li

Committee Member

Chunjiang Zhu

Committee Member

Feng Yu

Abstract

Graph Neural Networks (GNNs) have demonstrated remarkable performance on graph-based learning tasks and are increasingly deployed in security-critical applications. However, recent studies have shown that they are highly vulnerable to graph backdoor attacks (GBAs), where adversaries implant malicious triggers to induce targeted misclassification during inference. Despite their effectiveness, existing GBAs are often developed under unrealistic assumptions, such as focusing exclusively on simple homogeneous graphs or assuming the adversary possesses privileged access to target nodes during inference. This dissertation aims to systematically investigate and design graph backdoor attacks under significantly more realistic graph settings and adversarial constraints.

First, we investigate the underexplored vulnerabilities of Heterogeneous Graph Neural Networks (HGNNs). We conduct the first systematic investigation of existing GBAs on HGNNs, revealing that current methods suffer from high attack budgets and unreliable backdoor activation in complex, real-world heterogeneous scenarios. To overcome these issues, we propose the Heterogeneous Graph Backdoor Attack (HGBA), which departs from traditional subgraph-based triggers by introducing a novel relation-based trigger. By leveraging backdoor metapaths, HGBA successfully confines the adversary’s influence to feasible, user-level activation behaviors, demonstrating superior robustness against feature shifts and anomaly detection.

Second, we revisit GBAs in standard node classification tasks to address the unrealistic assumption that attackers have access to target nodes or their surrounding neighborhood topologies at inference time. To strictly enforce restricted-access constraints, we propose TAGBA, a Target- Agnostic Graph Backdoor Attack. TAGBA completely eliminates the reliance on victim-specific information during inference by synthesizing a universal trigger conditioned on class-level prototypes. By introducing a Class-Concentrated Poisoned Node Selection strategy and a Distribution- Aware Trigger Generator, TAGBA ensures that the triggers are highly potent yet statistically unnoticeable.

Together, these contributions bridge the fundamental gap between attack effectiveness and threat-model realism, highlighting the severe practical security risks of deploying GNNs and driving the critical need for more robust defenses.

Rights

In Copyright. URI: http://rightsstatements.org/vocab/InC/1.0/ This Item is protected by copyright and/or related rights. You are free to use this Item in any way that is permitted by the copyright and related rights legislation that applies to your use. For other uses you need to obtain permission from the rights-holder(s).

DOI

10.25777/f9af-3s04

ISBN

9798193214533

ORCID

0009-0001-6078-0059

Share

COinS