Research Article

Feature-Based Graph Backdoor Attack in the Node Classification Task

Table 2

Comparison of the ASR and CAD of a backdoor attack. ASR represents the success rate of classifying poisoned nodes into target classes, and the larger ASR is better. CAD represents the difference between clean GCN and backdoor GCN, and the smaller CAD is better.

DatasetASRCAD
RSANFTA-woNFTANFTA-DNFTA-BWRSANFTA-woNFTANFTA-DNFTA-BW

Polblogs
 = 174.1172.9875.8385.4283.332.634.911.472.972.19
 = 282.1270.8385.4287.6286.863.466.122.014.413.30

Citeseer
 = 180.6473.0682.1498.8182.865.138.312.514.053.98
 = 289.1279.2990.4897.6290.485.157.932.774.483.89
 = 381.0277.3883.3397.6788.295.457.513.115.652.04
 = 484.6679.7685.7197.6292.864.978.173.414.423.53
 = 584.1583.3389.2993.4890.525.459.242.664.555.24
 = 687.3775.0090.4896.4391.435.646.854.505.693.44

Blogcatalog
 = 188.6471.3191.3090.8291.793.916.15−3.082.113.55
 = 285.4670.1287.4494.2094.693.645.56−2.421.442.03
 = 389.1370.0592.1496.1492.343.115.02−4.232.282.86
 = 484.2472.1388.4195.4490.675.066.06−0.031.763.94
 = 585.7969.9790.6995.7593.864.185.340.263.563.81
 = 688.4871.1690.3494.2092.823.515.48−0.092.291.04

Important experimental results are bolded.