VLDB 2026 Research / reviewers in the wild / expert
Xiaogang Xing
dblp:272/3237
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0008-6400-1877ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Clean-label backdoor attack on link prediction taskabstractAbstract Graph Neural Networks (GNNs) have shown excellent performance as a powerful tool on link prediction task. Recent studies have shown that link prediction based on GNNs is vulnerable to backdoor attacks. However, existing backdoor attack methods on link prediction task require modification of the link state, which results in poor stealthiness of the backdoor. To address this issue, a clean-label backdoor attack method on link prediction task (CL-Link) is proposed in this paper. Specifically, CL-Link utilizes subgraphs as backdoor triggers and achieves trigger injection by attaching subgraphs to target links. In order to enhance the stealthiness of the attack, CL-Link attaches the trigger without modifying the original connection state of the target links. Instead, it utilizes the original connection state as the label, thus minimizing disturbances to the dataset. To ensure the effectiveness of the attack, the gradient information of the model and the similarity between the trigger nodes and the nodes in the graph are used to optimize the features of the trigger nodes. Extensive experiments were performed on multiple benchmark datasets (i.e., Cora, Citeseer, and Pubmed), and the proposed method achieved the highest attack success rate of 97.69% with a poisoning rate of only 5%, which validates the effectiveness of our proposed approach. Junming Mo, Ming Xu 0001, Xiaogang Xing |
Cybersecur. | 3 |
| 2025 | A graph backdoor detection method for data collection scenariosabstractAbstract Data collection is an effective way to build a better Graph Neural Network (GNN) model, but it also makes it easy for attackers to implant backdoors into the model through data poisoning. In this work, we propose a backdoor detection method of graph for data collection scenarios (CGBD). Different from most existing backdoor detection methods of Neural Network (NN) models, especially the Deep Neural Network (DNN) models, the difference in predictions of backdoor samples in clean and backdoor models is exploited for backdoor detection in CGBD. Specifically, in the backdoor model, the backdoor samples with modified labels are predicted as the target class. However, in the clean model, they are predicted as the ground-truth labels since the clean model remains unaffected by the backdoor. Due to the detection methodology of CGBD is not based on the potential forms of triggers, it can detect backdoor samples with any type of trigger. Additionally, since data is associated with its providers, CGBD can detect not only backdoor data but also malicious data providers. Extensive experiments on multiple benchmark datasets demonstrate that data with varying poisoning rates exhibit significant anomalies compared to clean data. This validates the effectiveness of our proposed method. Xiaogang Xing, Ming Xu 0001, Yujing Bai |
Cybersecur. | 1 |
| 2025 | A Data Ownership Authentication Method for Graph Neural Networks via Clean-Label BackdoorabstractGraph Neural Network(GNN) have gained extensive adoption in diverse fields, including IoT anomaly detection, social network analysis, and drug molecule prediction, due to their exceptional ability to handle graph-structured data. However, as GNN models become more widely used, the issue of dataset leakage has become increasingly prominent, posing significant risks to the rights and interests of data owners. In this paper, we propose a data ownership authentication method based on GNN backdoor watermarking, termed Graph Data Ownership Authentication(GDOA). Specifically, the data owner injects covert backdoor watermark triggers into some of the samples in the dataset. When an unauthorized user uses the data to train their own model, the model will be injected with the backdoor. The data owner can then validate the target model using samples with the same triggers to determine whether the target model was trained using the unauthorized dataset. GDOA utilizes the clean-label backdoor method to achieve ownership authentication of the dataset due to the greater stealthiness of the clean-label backdoor. Specifically, the watermark samples are selected within the target class, and the samples’ own labels are used as target labels, effectively avoiding the issue of label confusion. In addition, to improve the authentication success rate, GDOA optimizes the injection position of feature triggers in the feature vector. Our extensive experiments across multiple models and benchmark datasets demonstrate that GDOA achieves an average authentication success rate of over 90%, validating its effectiveness for graph data ownership verification. Xiaogang Xing, Ming Xu 0001, Yujing Bai, Ruifeng Zheng |
IEEE Internet Things J. | 1 |
| 2024 | A Clean-Label Graph Backdoor Attack Method in Node Classification Task
Xiaogang Xing, Ming Xu 0001, Yujing Bai |
Knowl. Based Syst. | 1 |