{"id":"https://openalex.org/W7125925049","doi":"https://doi.org/10.1109/tifs.2026.3659045","title":"A Wolf in Sheep\u2019s Clothing: Unveiling a Stealthy Backdoor Attack in Subgraph Federated Learning","display_name":"A Wolf in Sheep\u2019s Clothing: Unveiling a Stealthy Backdoor Attack in Subgraph Federated Learning","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7125925049","doi":"https://doi.org/10.1109/tifs.2026.3659045"},"language":null,"primary_location":{"id":"doi:10.1109/tifs.2026.3659045","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2026.3659045","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5124071016","display_name":"Hao Yu","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Hao Yu","raw_affiliation_strings":["College of Computer Science and Technology, National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0001-9044-4841","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124064973","display_name":"Wenjing Yang","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenjing Yang","raw_affiliation_strings":["College of Computer Science and Technology, National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0002-6997-0406","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124093306","display_name":"Chuan Ma","orcid":null},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chuan Ma","raw_affiliation_strings":["College of Computer Science, Chongqing University, Chongqing, China"],"raw_orcid":"https://orcid.org/0000-0001-6198-9498","affiliations":[{"raw_affiliation_string":"College of Computer Science, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124053169","display_name":"Lingyuan Meng","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lingyuan Meng","raw_affiliation_strings":["College of Computer Science and Technology, National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0002-2489-573X","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Liang Du","orcid":"https://orcid.org/0000-0002-3294-5071"},"institutions":[{"id":"https://openalex.org/I181877577","display_name":"Shanxi University","ror":"https://ror.org/03y3e3s17","country_code":"CN","type":"education","lineage":["https://openalex.org/I181877577"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Liang Du","raw_affiliation_strings":["School of Computer and Information Technology, Shanxi University, Taiyuan, Shanxi, China"],"raw_orcid":"https://orcid.org/0000-0002-3294-5071","affiliations":[{"raw_affiliation_string":"School of Computer and Information Technology, Shanxi University, Taiyuan, Shanxi, China","institution_ids":["https://openalex.org/I181877577"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124129654","display_name":"Tao Xiang","orcid":null},"institutions":[{"id":"https://openalex.org/I158842170","display_name":"Chongqing University","ror":"https://ror.org/023rhb549","country_code":"CN","type":"education","lineage":["https://openalex.org/I158842170"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tao Xiang","raw_affiliation_strings":["College of Computer Science, Chongqing University, Chongqing, China"],"raw_orcid":"https://orcid.org/0000-0002-9439-4623","affiliations":[{"raw_affiliation_string":"College of Computer Science, Chongqing University, Chongqing, China","institution_ids":["https://openalex.org/I158842170"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124128993","display_name":"Xinwang Liu","orcid":null},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinwang Liu","raw_affiliation_strings":["College of Computer Science and Technology, National University of Defense Technology, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0001-9066-1475","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5104432716","display_name":"Kunlun He","orcid":null},"institutions":[{"id":"https://openalex.org/I2802939634","display_name":"Chinese PLA General Hospital","ror":"https://ror.org/04gw3ra78","country_code":"CN","type":"healthcare","lineage":["https://openalex.org/I2802939634"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kunlun He","raw_affiliation_strings":["Medical Big Data Research Center, Chinese PLA General Hospital, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-3335-5700","affiliations":[{"raw_affiliation_string":"Medical Big Data Research Center, Chinese PLA General Hospital, Beijing, China","institution_ids":["https://openalex.org/I2802939634"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5124071016"],"corresponding_institution_ids":["https://openalex.org/I170215575"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.17756679,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"21","issue":null,"first_page":"1842","last_page":"1857"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.5091000199317932,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.5091000199317932,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.3871000111103058,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.021800000220537186,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9822999835014343},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6362000107765198},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.4867999851703644},{"id":"https://openalex.org/keywords/node","display_name":"Node (physics)","score":0.4526999890804291},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.37470000982284546},{"id":"https://openalex.org/keywords/subgraph-isomorphism-problem","display_name":"Subgraph isomorphism problem","score":0.3158999979496002}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9822999835014343},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7613999843597412},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6362000107765198},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.4867999851703644},{"id":"https://openalex.org/C62611344","wikidata":"https://www.wikidata.org/wiki/Q1062658","display_name":"Node (physics)","level":2,"score":0.4526999890804291},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.37470000982284546},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37400001287460327},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.33340001106262207},{"id":"https://openalex.org/C131992880","wikidata":"https://www.wikidata.org/wiki/Q2528185","display_name":"Subgraph isomorphism problem","level":3,"score":0.3158999979496002},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3125999867916107},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.27639999985694885},{"id":"https://openalex.org/C2780741293","wikidata":"https://www.wikidata.org/wiki/Q4818019","display_name":"Attack patterns","level":3,"score":0.27239999175071716},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.25940001010894775},{"id":"https://openalex.org/C113238511","wikidata":"https://www.wikidata.org/wiki/Q1071612","display_name":"k-nearest neighbors algorithm","level":2,"score":0.25589999556541443}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2026.3659045","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2026.3659045","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1813241943","display_name":null,"funder_award_id":"CSTB2025TIAD-STX0032","funder_id":"https://openalex.org/F4320336740","funder_display_name":"Chongqing Municipality Key Research and Development Program of China"},{"id":"https://openalex.org/G2455478723","display_name":null,"funder_award_id":"62276271","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2822742771","display_name":null,"funder_award_id":"62572083","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5737921325","display_name":null,"funder_award_id":"62325604","funder_id":"https://openalex.org/F4320336125","funder_display_name":"National Science Fund for Distinguished Young Scholars"},{"id":"https://openalex.org/G6130330936","display_name":null,"funder_award_id":"62572079","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6562299470","display_name":null,"funder_award_id":"62441618","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320336125","display_name":"National Science Fund for Distinguished Young Scholars","ror":null},{"id":"https://openalex.org/F4320336740","display_name":"Chongqing Municipality Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":38,"referenced_works":["https://openalex.org/W2027731328","https://openalex.org/W2099438806","https://openalex.org/W2131681506","https://openalex.org/W2153959628","https://openalex.org/W2616247523","https://openalex.org/W2744999500","https://openalex.org/W2753783305","https://openalex.org/W2949208225","https://openalex.org/W2964583308","https://openalex.org/W3167334189","https://openalex.org/W3175919946","https://openalex.org/W3198375173","https://openalex.org/W4220768948","https://openalex.org/W4281686206","https://openalex.org/W4320013936","https://openalex.org/W4323066547","https://openalex.org/W4360825594","https://openalex.org/W4380303532","https://openalex.org/W4382237515","https://openalex.org/W4385187226","https://openalex.org/W4388723845","https://openalex.org/W4388845104","https://openalex.org/W4388856889","https://openalex.org/W4391547484","https://openalex.org/W4391724758","https://openalex.org/W4391724779","https://openalex.org/W4391725340","https://openalex.org/W4397000111","https://openalex.org/W4399995632","https://openalex.org/W4401023496","https://openalex.org/W4402264237","https://openalex.org/W4403600947","https://openalex.org/W4405170795","https://openalex.org/W4405181861","https://openalex.org/W4406949434","https://openalex.org/W4407468113","https://openalex.org/W4411726016","https://openalex.org/W4414065104"],"related_works":[],"abstract_inverted_index":{"Subgraph":[0],"Federated":[1],"Learning":[2],"(FL)":[3],"has":[4],"emerged":[5],"as":[6,136],"a":[7,18,56,75,98,116,125,151],"promising":[8],"paradigm":[9],"for":[10,106],"node":[11],"classification":[12,205],"tasks":[13],"wherein":[14],"subgraphs":[15],"derived":[16],"from":[17,43],"global":[19],"graph":[20,204],"are":[21],"distributed":[22],"across":[23,167,172],"multiple":[24],"devices":[25],"to":[26,32,59,70,202],"mitigate":[27],"data":[28,196],"leakage":[29],"risks.":[30],"Similar":[31],"other":[33],"FL":[34,37,168],"systems,":[35],"subgraph":[36,64],"faces":[38],"significant":[39,79],"security":[40],"challenges,":[41],"particularly":[42],"backdoor":[44,158],"attacks,":[45,179],"an":[46,102],"area":[47],"that":[48,138],"remains":[49],"extensively":[50],"underexplored.":[51],"Existing":[52],"attacks":[53,67],"typically":[54],"follow":[55],"two-phase":[57],"strategy":[58],"implant":[60],"backdoors.":[61],"However,":[62],"in":[63,187],"FL,":[65],"such":[66],"often":[68],"lead":[69],"<italic":[71],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[72],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">Divergence":[73],"Amplification</i>,":[74],"phenomenon":[76],"characterized":[77],"by":[78,149],"parameter":[80],"discrepancies":[81],"between":[82],"normal":[83,195],"and":[84,109,164,180,210],"backdoored":[85,126],"models,":[86,176],"thereby":[87],"compromising":[88],"attack":[89,100],"stealthiness.":[90],"To":[91,128],"tackle":[92],"this":[93],"challenge,":[94],"we":[95,199],"propose":[96],"BEEF,":[97],"Backdoor":[99],"with":[101,124,157],"End-to-End":[103],"Framework":[104],"designed":[105],"effectiveness,":[107],"stealth,":[108],"durability.":[110],"Unlike":[111],"conventional":[112],"methods,":[113],"BEEF":[114,132,160,201],"incorporates":[115],"dedicated":[117],"trigger":[118],"generator,":[119],"which":[120],"is":[121],"jointly":[122],"trained":[123],"model.":[127],"increase":[129],"its":[130,208],"stealthiness,":[131],"crafts":[133],"adversarial":[134],"perturbations":[135],"triggers":[137],"provoke":[139],"misclassification":[140],"while":[141,190],"leaving":[142],"the":[143],"model\u2019s":[144],"parameters":[145,155],"entirely":[146],"untouched.":[147],"Furthermore,":[148],"calibrating":[150],"subset":[152],"of":[153],"low-salience":[154],"associated":[156],"activation,":[159],"ensures":[161],"stable":[162],"performance":[163],"sustained":[165],"effectiveness":[166,186],"rounds.":[169],"Comprehensive":[170],"evaluations":[171],"eight":[173],"datasets,":[174],"four":[175],"five":[177],"state-of-the-art":[178],"six":[181],"aggregation":[182],"methods":[183],"demonstrate":[184],"BEEF\u2019s":[185],"deceiving":[188],"GNNs":[189],"maintaining":[191],"minimal":[192],"impact":[193],"on":[194],"performance.":[197],"Additionally,":[198],"adapt":[200],"federated":[203],"tasks,":[206],"broadening":[207],"applicability":[209],"practicality.":[211]},"counts_by_year":[],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2026-01-29T00:00:00"}
