{"id":"https://openalex.org/W4414360010","doi":"https://doi.org/10.24963/ijcai.2025/342","title":"Single-Node Trigger Backdoor Attacks in Graph-Based Recommendation Systems","display_name":"Single-Node Trigger Backdoor Attacks in Graph-Based Recommendation Systems","publication_year":2025,"publication_date":"2025-09-01","ids":{"openalex":"https://openalex.org/W4414360010","doi":"https://doi.org/10.24963/ijcai.2025/342"},"language":"en","primary_location":{"id":"doi:10.24963/ijcai.2025/342","is_oa":false,"landing_page_url":"https://doi.org/10.24963/ijcai.2025/342","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-Fourth International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100721408","display_name":"Runze Li","orcid":"https://orcid.org/0000-0002-0154-2202"},"institutions":[{"id":"https://openalex.org/I162868743","display_name":"Tianjin University","ror":"https://ror.org/012tb2g32","country_code":"CN","type":"education","lineage":["https://openalex.org/I162868743"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Runze Li","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University","Guangdong Laboratory of Artificial Intelligence and Digital Economy(SZ)"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University","institution_ids":["https://openalex.org/I162868743"]},{"raw_affiliation_string":"Guangdong Laboratory of Artificial Intelligence and Digital Economy(SZ)","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012455357","display_name":"Di Jin","orcid":"https://orcid.org/0000-0002-7445-9936"},"institutions":[{"id":"https://openalex.org/I162868743","display_name":"Tianjin University","ror":"https://ror.org/012tb2g32","country_code":"CN","type":"education","lineage":["https://openalex.org/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Di Jin","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University","institution_ids":["https://openalex.org/I162868743"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103015888","display_name":"Xiaobao Wang","orcid":"https://orcid.org/0000-0001-5086-4964"},"institutions":[{"id":"https://openalex.org/I162868743","display_name":"Tianjin University","ror":"https://ror.org/012tb2g32","country_code":"CN","type":"education","lineage":["https://openalex.org/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaobao Wang","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University","Guangdong Laboratory of Artificial Intelligence and Digital Economy(SZ)"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University","institution_ids":["https://openalex.org/I162868743"]},{"raw_affiliation_string":"Guangdong Laboratory of Artificial Intelligence and Digital Economy(SZ)","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009013876","display_name":"Dongxiao He","orcid":"https://orcid.org/0000-0002-1915-4179"},"institutions":[{"id":"https://openalex.org/I162868743","display_name":"Tianjin University","ror":"https://ror.org/012tb2g32","country_code":"CN","type":"education","lineage":["https://openalex.org/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dongxiao He","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University","institution_ids":["https://openalex.org/I162868743"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102529066","display_name":"Bingdao Feng","orcid":null},"institutions":[{"id":"https://openalex.org/I162868743","display_name":"Tianjin University","ror":"https://ror.org/012tb2g32","country_code":"CN","type":"education","lineage":["https://openalex.org/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bingdao Feng","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University","institution_ids":["https://openalex.org/I162868743"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100401102","display_name":"Zheng Wang","orcid":"https://orcid.org/0000-0002-4814-1115"},"institutions":[{"id":"https://openalex.org/I17145004","display_name":"Northwestern Polytechnical University","ror":"https://ror.org/01y0j0j86","country_code":"CN","type":"education","lineage":["https://openalex.org/I17145004"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhen Wang","raw_affiliation_strings":["School of Cybersecurity, Northwestern Polytechnical University"],"affiliations":[{"raw_affiliation_string":"School of Cybersecurity, Northwestern Polytechnical University","institution_ids":["https://openalex.org/I17145004"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5100721408"],"corresponding_institution_ids":["https://openalex.org/I162868743"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.38442252,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"3072","last_page":"3080"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10203","display_name":"Recommender Systems and Techniques","score":0.9958000183105469,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10203","display_name":"Recommender Systems and Techniques","score":0.9958000183105469,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.9930999875068665,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12488","display_name":"Mental Health via Writing","score":0.9603000283241272,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9093000292778015},{"id":"https://openalex.org/keywords/recommender-system","display_name":"Recommender system","score":0.609000027179718},{"id":"https://openalex.org/keywords/covert","display_name":"Covert","score":0.48980000615119934},{"id":"https://openalex.org/keywords/constraint","display_name":"Constraint (computer-aided design)","score":0.4530999958515167},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.3172999918460846},{"id":"https://openalex.org/keywords/disinformation","display_name":"Disinformation","score":0.3172000050544739}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9093000292778015},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7822999954223633},{"id":"https://openalex.org/C557471498","wikidata":"https://www.wikidata.org/wiki/Q554950","display_name":"Recommender system","level":2,"score":0.609000027179718},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5949000120162964},{"id":"https://openalex.org/C2779338814","wikidata":"https://www.wikidata.org/wiki/Q5179285","display_name":"Covert","level":2,"score":0.48980000615119934},{"id":"https://openalex.org/C2776036281","wikidata":"https://www.wikidata.org/wiki/Q48769818","display_name":"Constraint (computer-aided design)","level":2,"score":0.4530999958515167},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.3172999918460846},{"id":"https://openalex.org/C2776552730","wikidata":"https://www.wikidata.org/wiki/Q189656","display_name":"Disinformation","level":3,"score":0.3172000050544739},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.31119999289512634},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.2985999882221222},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.29809999465942383},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.2727999985218048},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.26919999718666077},{"id":"https://openalex.org/C2780741293","wikidata":"https://www.wikidata.org/wiki/Q4818019","display_name":"Attack patterns","level":3,"score":0.2587999999523163},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2533000111579895}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.24963/ijcai.2025/342","is_oa":false,"landing_page_url":"https://doi.org/10.24963/ijcai.2025/342","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Thirty-Fourth International Joint Conference on Artificial Intelligence","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Graph":[0],"recommendation":[1,39,145,174],"systems":[2,23],"have":[3],"been":[4],"widely":[5],"studied":[6],"due":[7],"to":[8,11,79,86,113,136],"their":[9],"ability":[10],"effectively":[12,108],"capture":[13],"the":[14,81,87,114,130,138,144,152,155,166,170,173],"complex":[15],"interactions":[16],"between":[17,129],"users":[18],"and":[19,49,61,133],"items.":[20],"However,":[21,51],"these":[22,66],"also":[24],"exhibit":[25],"certain":[26],"vulnerabilities":[27],"when":[28],"faced":[29],"with":[30],"attacks.":[31],"The":[32],"prevailing":[33],"shilling":[34],"attack":[35,53,75],"methods":[36],"typically":[37],"manipulate":[38],"results":[40,149],"by":[41,117],"injecting":[42],"a":[43,71,91,102],"large":[44],"number":[45],"of":[46,83,140,154,165],"fake":[47,121,141],"nodes":[48,132,135,142],"edges.":[50],"such":[52],"strategies":[54],"face":[55],"two":[56],"primary":[57],"challenges:":[58],"low":[59],"stealth":[60],"high":[62],"destructiveness.":[63],"To":[64],"address":[65],"challenges,":[67],"this":[68],"paper":[69],"proposes":[70],"novel":[72],"graph":[73],"backdoor":[74],"method":[76],"that":[77,151],"aims":[78],"enhance":[80],"exposure":[82,153],"target":[84,88,111,115,131,156,167],"items":[85,112,157],"user":[89,116,122],"in":[90,163],"covert":[92],"manner,":[93],"without":[94],"affecting":[95],"other":[96],"unrelated":[97],"nodes.":[98],"Specifically,":[99],"we":[100,125],"design":[101],"single-node":[103],"trigger":[104],"generator,":[105],"which":[106],"can":[107],"expose":[109],"multiple":[110],"inserting":[118],"only":[119],"one":[120],"node.":[123],"Additionally,":[124],"introduce":[126],"constraint":[127],"conditions":[128],"irrelevant":[134],"mitigate":[137],"impact":[139,171],"on":[143,172],"system's":[146,175],"performance.":[147],"Experimental":[148],"show":[150],"reaches":[158],"no":[159],"less":[160],"than":[161],"50%":[162],"99%":[164],"users,":[168],"while":[169],"performance":[176],"is":[177],"controlled":[178],"within":[179],"approximately":[180],"5%.":[181]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-10-10T00:00:00"}
