Date of Award
Summer 8-2026
Document Type
Dissertation
Degree Name
Doctor of Philosophy (PhD)
Department
Computer Science
Program/Concentration
Computer Science
Committee Director
Rui Ning
Committee Member
Lusi Li
Committee Member
Chunjiang Zhu
Committee Member
Feng Yu
Abstract
Graph Neural Networks (GNNs) have demonstrated remarkable performance on graph-based learning tasks and are increasingly deployed in security-critical applications. However, recent studies have shown that they are highly vulnerable to graph backdoor attacks (GBAs), where adversaries implant malicious triggers to induce targeted misclassification during inference. Despite their effectiveness, existing GBAs are often developed under unrealistic assumptions, such as focusing exclusively on simple homogeneous graphs or assuming the adversary possesses privileged access to target nodes during inference. This dissertation aims to systematically investigate and design graph backdoor attacks under significantly more realistic graph settings and adversarial constraints.
First, we investigate the underexplored vulnerabilities of Heterogeneous Graph Neural Networks (HGNNs). We conduct the first systematic investigation of existing GBAs on HGNNs, revealing that current methods suffer from high attack budgets and unreliable backdoor activation in complex, real-world heterogeneous scenarios. To overcome these issues, we propose the Heterogeneous Graph Backdoor Attack (HGBA), which departs from traditional subgraph-based triggers by introducing a novel relation-based trigger. By leveraging backdoor metapaths, HGBA successfully confines the adversary’s influence to feasible, user-level activation behaviors, demonstrating superior robustness against feature shifts and anomaly detection.
Second, we revisit GBAs in standard node classification tasks to address the unrealistic assumption that attackers have access to target nodes or their surrounding neighborhood topologies at inference time. To strictly enforce restricted-access constraints, we propose TAGBA, a Target- Agnostic Graph Backdoor Attack. TAGBA completely eliminates the reliance on victim-specific information during inference by synthesizing a universal trigger conditioned on class-level prototypes. By introducing a Class-Concentrated Poisoned Node Selection strategy and a Distribution- Aware Trigger Generator, TAGBA ensures that the triggers are highly potent yet statistically unnoticeable.
Together, these contributions bridge the fundamental gap between attack effectiveness and threat-model realism, highlighting the severe practical security risks of deploying GNNs and driving the critical need for more robust defenses.
Rights
In Copyright. URI: http://rightsstatements.org/vocab/InC/1.0/ This Item is protected by copyright and/or related rights. You are free to use this Item in any way that is permitted by the copyright and related rights legislation that applies to your use. For other uses you need to obtain permission from the rights-holder(s).
DOI
10.25777/f9af-3s04
ISBN
9798193214533
Recommended Citation
Chen, Jiawei.
"Towards More Realistic and Practical Graph Backdoor Attacks"
(2026). Doctor of Philosophy (PhD), Dissertation, Computer Science, Old Dominion University, DOI: 10.25777/f9af-3s04
https://digitalcommons.odu.edu/computerscience_etds/203
ORCID
0009-0001-6078-0059