Federated Graph Learning (FedGL) enables multiple data owners to collaboratively train a Graph Neural Network (GNN) without sharing their raw data. While this paradigm is designed to preserve privacy, its distributed nature exposes it to data poisoning attacks, including backdoor attacks. Existing studies on backdoor attacks in FedGL focus exclusively on dirty-label settings. Although effective, these approaches either rely on complex trigger generation networks, thereby increasing attack complexity, or require collaboration among multiple compromised clients, limiting their applicability when only a single malicious client is available. In this work, we introduce Clean Label Federated Graph Backdoor Attack (CFGBA), the first clean-label backdoor attack specifically designed for FedGL in the node classification setting. CFGBA injects the trigger by modifying a selected subset of features in target nodes and assigning them predefined values. Furthermore, the attack leverages GraphLIME to identify the most relevant features to serve as trigger components. Unlike prior approaches, CFGBA does not require client collusion. Owing to the inherent stealthiness of clean-label attacks compared to dirty-label ones, the proposed method can be effectively executed even when only a single client is compromised. Experimental results on three widely adopted benchmark datasets demonstrate the effectiveness of CFGBA, achieving an Attack Success Rate (ASR) above 96% in most evaluated configurations. Moreover, we show that CFGBA successfully bypasses three State-of-the-Art (SotA) server-side defenses and that its impact persists over time.
Il paradigma del Federated Graph Learning (FedGL) consente a più enti detentori di dati di collaborare all’addestramento di modelli di Graph Neural Network (GNN) senza condividere i dati grezzi. Sebbene tale approccio sia progettato per preservare la privacy, la sua natura distribuita lo rende vulnerabile ad attacchi di data poisoning, inclusi gli attacchi backdoor. Nello stato dell’arte del FedGL sono stati proposti esclusivamente attacchi backdoor di tipo dirty-label. Sebbene efficaci, tali approcci richiedono o l’impiego di reti complesse per la generazione del trigger, con conseguente aumento della complessità dell’attacco, oppure la collaborazione tra più client compromessi, limitandone l’applicabilità in scenari in cui sia disponibile un solo client malevolo. In questa tesi introduciamo Clean Label Federated Graph Backdoor Attack (CFGBA), il primo attacco backdoor di tipo clean-label progettato per FedGL nel contesto della node classification. CFGBA inietta il trigger modificando un sottoinsieme selezionato di feature nei nodi target e assegnando loro valori predefiniti. Inoltre, l’attacco sfrutta GraphLIME per identificare le feature più rilevanti da utilizzare come componenti del trigger. A differenza delle soluzioni precedenti, CFGBA non richiede collaborazione tra client, poiché gli attacchi clean-label risultano intrinsecamente più evasivi rispetto a quelli dirty-label. Di conseguenza, l’attacco può essere condotto efficacemente anche controllando un singolo client. I risultati sperimentali, ottenuti su tre dataset ampiamente adottati in letteratura, dimostrano l’elevata efficacia di CFGBA, che raggiunge un Attack Success Rate (ASR) superiore al 96% nella maggior parte delle configurazioni analizzate. Inoltre, mostriamo che CFGBA è in grado di eludere tre difese lato server allo State-of-the-Art (SotA) e che i suoi effetti permangono nel tempo.
Clean-label backdoor attack against Federated Graph Learning for node classification
Fiorentino, Luigi
2024/2025
Abstract
Federated Graph Learning (FedGL) enables multiple data owners to collaboratively train a Graph Neural Network (GNN) without sharing their raw data. While this paradigm is designed to preserve privacy, its distributed nature exposes it to data poisoning attacks, including backdoor attacks. Existing studies on backdoor attacks in FedGL focus exclusively on dirty-label settings. Although effective, these approaches either rely on complex trigger generation networks, thereby increasing attack complexity, or require collaboration among multiple compromised clients, limiting their applicability when only a single malicious client is available. In this work, we introduce Clean Label Federated Graph Backdoor Attack (CFGBA), the first clean-label backdoor attack specifically designed for FedGL in the node classification setting. CFGBA injects the trigger by modifying a selected subset of features in target nodes and assigning them predefined values. Furthermore, the attack leverages GraphLIME to identify the most relevant features to serve as trigger components. Unlike prior approaches, CFGBA does not require client collusion. Owing to the inherent stealthiness of clean-label attacks compared to dirty-label ones, the proposed method can be effectively executed even when only a single client is compromised. Experimental results on three widely adopted benchmark datasets demonstrate the effectiveness of CFGBA, achieving an Attack Success Rate (ASR) above 96% in most evaluated configurations. Moreover, we show that CFGBA successfully bypasses three State-of-the-Art (SotA) server-side defenses and that its impact persists over time.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_03_Fiorentino_Tesi.pdf
solo utenti autorizzati a partire dal 23/02/2029
Dimensione
1.19 MB
Formato
Adobe PDF
|
1.19 MB | Adobe PDF | Visualizza/Apri |
|
2026_03_Fiorentino_Executive Summary.pdf
solo utenti autorizzati a partire dal 23/02/2029
Dimensione
487.86 kB
Formato
Adobe PDF
|
487.86 kB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/252862