Research Article
Feature-Based Graph Backdoor Attack in the Node Classification Task
Table 5
Transferability results of our models.
| | GAT | Chebnet | Polblogs | Citeseer | Blogcatalog | Polblogs | Citeseer | Blogcatalog |
| NFTA-wo | ASR | 75.16 | 81.48 | 82.70 | 93.13 | 96.43 | 84.61 | CAD | 3.02 | 4.46 | 3.45 | −6.01 | 3.55 | 1.34 |
| NFTA | ASR | 77.08 | 83.48 | 85.57 | 94.02 | 98.81 | 88.61 | CAD | 1.53 | 3.39 | 0.31 | −4.61 | 2.62 | −0.62 |
| NFTA-D | ASR | 82.46 | 90.12 | 91.90 | 96.10 | 96.67 | 90.27 | CAD | 2.02 | 5.48 | 4.13 | −1.54 | 3.46 | 2.15 |
| NFTA-BW | ASR | 85.11 | 87.64 | 92.49 | 96.20 | 95.02 | 93.88 | CAD | 3.54 | 4.16 | 4.50 | 1.61 | 3.07 | 4.16 |
|
|