Paper deep dive
Hide and Find: A Distributed Adversarial Attack on Federated Graph Learning
Jinshan Liu, Ken Li, Jiazhe Wei, Bin Shi, Bo Dong
Intelligence
Status: succeeded | Model: google/gemini-3.1-flash-lite-preview | Prompt: intel-v1 | Confidence: 96%
Last extracted: 3/13/2026, 12:36:33 AM
Summary
FedShift is a two-stage distributed adversarial attack framework for Federated Graph Learning (FedGL). It addresses the limitations of existing backdoor and adversarial attacks by using a 'Hide and Find' strategy: first, injecting a learnable 'shifter' to subtly push poisoned graph representations toward a target class boundary (stealthy data poisoning), and second, using this shifter as an optimization starting point to efficiently generate adversarial perturbations after federated training. This approach improves attack effectiveness, stealthiness, and convergence speed while evading robust defense algorithms.
Entities (5)
Relation Signals (3)
FedShift → targets → Federated Graph Learning
confidence 100% · FedShift, a novel two-stage 'Hide and Find' distributed adversarial attack on Federated Graph Learning
Shifter Generator → implements → FedShift
confidence 95% · each malicious client trains its local adaptive shifter generator to achieve the implantation of stealthy backdoor signals.
FedShift → uses → Graph Neural Networks
confidence 90% · enables collaborative Graph Neural Networks (GNNs) training
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Federated Graph Learning (FedGL) is vulnerable to malicious attacks, yet developing a truly effective and stealthy attack method remains a significant challenge. Existing attack methods suffer from low attack success rates, high computational costs, and are easily identified and smoothed by defense algorithms. To address these challenges, we propose \textbf{FedShift}, a novel two-stage "Hide and Find" distributed adversarial attack. In the first stage, before FedGL begins, we inject a learnable and hidden "shifter" into part of the training data, which subtly pushes poisoned graph representations toward a target class's decision boundary without crossing it, ensuring attack stealthiness during training. In the second stage, after FedGL is complete, we leverage the global model information and use the hidden shifter as an optimization starting point to efficiently find the adversarial perturbations. During the final attack, we aggregate these perturbations from multiple malicious clients to form the final effective adversarial sample and trigger the attack. Extensive experiments on six large-scale datasets demonstrate that our method achieves the highest attack effectiveness compared to existing advanced attack methods. In particular, our attack can effectively evade 3 mainstream robust federated learning defense algorithms and converges with a time cost reduction of over 90\%, highlighting its exceptional stealthiness, robustness, and efficiency.
Tags
Links
- Source: https://arxiv.org/abs/2603.07743v1
- Canonical: https://arxiv.org/abs/2603.07743v1
Trouble viewing inline? Open PDF directly →
Full Text
51,953 characters extracted from source content.
Expand or collapse full text
Hide and Find: A Distributed Adversarial Attack on Federated Graph Learning Jinshan Liu1,2† Ken Li1,2† Jiazhe Wei1,3 Bin Shi1,2 Bo Dong4,3 1School of Computer Science and Technology, Xi’an Jiaotong University 2Ministry of Education Key Laboratory of Intelligent Networks and Network Security 3Shaanxi Province Key Laboratory of Big Data Knowledge Engineering 4School of Distance Education, Xi’an Jiaotong University Xi’an, China shanhe@stu.xjtu.edu.cn 2223312154@stu.xjtu.edu.cn shibin@xjtu.edu.cn wjz2930608106@stu.xjtu.edu.cn dong.bo@xjtu.edu.cn †Equal contribution Corresponding author. Abstract Federated Graph Learning (FedGL) is vulnerable to malicious attacks, yet developing a truly effective and stealthy attack method remains a significant challenge. Existing attack methods suffer from low attack success rates, high computational costs, and are easily identified and smoothed by defense algorithms. To address these challenges, we propose FedShift, a novel two-stage “Hide and Find” distributed adversarial attack. In the first stage, before FedGL begins, we inject a learnable and hidden “shifter” into part of the training data, which subtly pushes poisoned graph representations toward a target class’s decision boundary without crossing it, ensuring attack stealthiness during training. In the second stage, after FedGL is complete, we leverage the global model information and use the hidden shifter as an optimization starting point to efficiently find the adversarial perturbations. During the final attack, we aggregate these perturbations from multiple malicious clients to form the final effective adversarial sample and trigger the attack. Extensive experiments on six large-scale datasets demonstrate that our method achieves the highest attack effectiveness compared to existing advanced attack methods. In particular, our attack can effectively evade 3 mainstream robust federated learning defense algorithms and converges with a time cost reduction of over 90%, highlighting its exceptional stealthiness, robustness, and efficiency. 1 Introduction Federated Graph Learning (FedGL) (He et al., 2021; 2022; Xie et al., 2023; Liu et al., 2024) , as a novel distributed learning paradigm, enables collaborative Graph Neural Networks (GNNs) (Scarselli et al., 2008) training without direct data sharing, effectively solving real-world data privacy issues (Goddard, 2017) and finding wide applications in domains such as disease prediction (Peng et al., 2022) and recommendation systems (Wu et al., 2022; Baek et al., 2023). On FedGL, data owners serve as clients, locally train models on their own private graph data, and submit only model updates to a central server for aggregation, building a shared global model while preserving data privacy (Kairouz et al., 2021). Like ordinary graph learning, federated graph learning also faces security issues (Dai et al., 2023; Wu et al., 2024; Yang et al., 2024a). To make the model produce incorrect predictions, an attacker can control one or more malicious clients to inject various triggers (such as different subgraphs) into parts of the training data and relabel them to the attacker’s predefined target label (different from their original label), in order to jointly implant the backdoor signal into the global model (Xie et al., 2019; Xi et al., 2021; Xu et al., 2024). However, in the federated scenario, such graph backdoor attacks generally face two major challenges: Challenge 1) Malicious backdoor signals produced by malicious clients are easily smoothed out during aggregation by normal signals provided by benign clients, leading to a significant drop in attack effectiveness. Challenge 2) To resist signal smoothing, a direct approach is to increase the attack budget. However, larger-scale data poisoning leads to a decrease in the attack’s stealthiness, making it easily identified and filtered by mainstream federated defense algorithms, while also incurring higher attack costs (Xu et al., 2022; Xi et al., 2021; Yang et al., 2024b). Besides, graph adversarial attacks can also cause the model to produce incorrect predictions. However, this method also has its limitations: Challenge 3) Due to the discrete nature of graph structures and the non-convexity of the optimization objective, it often suffers from slow convergence, unstable optimization, or even failure to converge, leading to significant computational overhead and performance uncertainty (Li et al., 2025). To address the above challenges, we propose FedShift, a novel distributed adversarial attack framework that incorporates ideas from backdoor attacks into adversarial attacks, addressing the limitations that each faces when used separately. It is divided into two stages: Stage 1) Gentle Data Poisoning. Traditional backdoor attacks that inject triggers and forcibly modify labels essentially construct an additional distribution of poisoned data and compel the model to learn a shortcut—a direct sample-to-label mapping based on the trigger. However, such shortcuts are proven to be easily smoothed out by the normal signals from benign clients or identified by defense algorithms (Blanchard et al., 2017; Bagdasaryan et al., 2020), which leads to Challenge 1 and Challenge 2. In contrast, before federated training, we design an adaptive generator for each malicious client to produce a perturbation we call a “shifter”, which subtly pushes the embedding of the poisoned graph toward the decision boundary of the target class without crossing it (i.e., not enough to be classified as the target class). This gentle distributional shift makes the behavior of malicious clients almost indistinguishable from that of benign clients. Therefore, the backdoor signal it produces can effectively resist signal smoothing and ensure stealthiness, thereby solving Challenges 1 and 2. Stage 2) Adversarial Perturbation Finding. Traditional adversarial attacks perform optimization from scratch after federated training is complete, which leads to slow and unstable convergence (Li et al., 2025), i.e., Challenge 3. In contrast, after federated training, our method leverages the information from the global model, which has already been implanted with a backdoor, and uses the shifter generator trained in Stage 1 as an optimization starting point. Consequently, the process of finding the adversarial perturbation becomes both stable and efficient, thereby solving Challenge 3. During the final attack, we aggregate the different adversarial perturbations generated by multiple malicious clients to form the final adversarial sample, achieving a ‘‘1+1>2”``1+1>2" effect. We extensively evaluate our FedShift on six large-scale graph datasets, and the attack results excellently address the three major challenges mentioned above: 1) Compared to existing methods, the backdoor signal from FedShift is 80.5% to 90.6% less smoothed by the federated aggregation process, demonstrating its superior attack effectiveness in large-scale, multi-client real-world scenarios. 2) FedShift maintains the highest attack effectiveness when confronted with various mainstream defense algorithms, showcasing its remarkable robustness and stealthiness. 3) FedShift requires over 90% fewer training epochs to achieve the same Attack Success Rate (ASR) compared to the baseline method, highlighting its exceptional efficiency and stability. In summary, the contributions of this work are threefold: • We propose FedShift, a novel distributed adversarial attack with stealthiness, effectiveness, and efficiency. • We resolve the dilemmas of existing attack paradigms through a two-stage process utilizing a novel distributional shift strategy and an optimized initial state. • We pioneer an “implant-find” attack paradigm. To our knowledge, this is the first study to leverage information from the entire federated learning process within a unified framework. 2 Related Work Federated Graph Learning. Federated Graph Learning (FedGL) (He et al., 2022; Xie et al., 2023; Liu et al., 2024) is a novel paradigm that merges Federated Learning (FL) (McMahan et al., 2017) with Graph Neural Networks (GNNs) (Scarselli et al., 2008) to enable collaborative training on private graph data. However, the distributed nature of FedGL, coupled with the inherent complexity of graph data, introduces significant security vulnerabilities to malicious attacks (Dai et al., 2023; Wu et al., 2024; Yang et al., 2024a). Attacks on Federated Graph Learning. Early backdoor attacks on FedGL utilized random subgraphs as triggers (Xu et al., 2022), which later evolved to use adaptive generators for improved effectiveness (Yang et al., 2024b). To enhance stealthiness, other works employed adversarial attacks to find adversarial samples through post-hoc optimization after federated training is complete (Li et al., 2025). Nevertheless, existing paradigms are often limited by a trade-off between effectiveness, stealth, and convergence speed. In contrast, our proposed FedShift overcomes these limitations through a novel two-stage process that achieves a stealthy, robust, and efficient attack. 3 Preliminary 3.1 Federated Graph Learning (FedGL) We represent a graph as G=(,ℰ,)G=(V,E,X), with nodes V, edges ℰE, and a node feature matrix ∈||×dX ^|V|× d. We focus on graph classification, where a GNN model f learns a mapping f:G→yf:G→ y to a label y∈y . Federated Graph Learning (FedGL) is a framework where N clients (C=c1,…,cNC=\c_1,…,c_N\), each holding a private dataset iD_i, collaboratively train a global GNN model parameterized by θ. The objective is to minimize the weighted average of their local loss functions ℒi(θ)L_i(θ): minθℒ(θ)=∑i=1N|i|||ℒi(θ). _θL(θ)= _i=1^N |D_i||D|L_i(θ). (1) This is achieved through an iterative process. In each epoch t, clients first download the current global model θt _t. They then compute local updates by training on their private data, yielding local models θti _t^i. Finally, the server aggregates these local models to produce the next global model, θt+1 _t+1, often using Federated Averaging (FedAvg): θt+1=1N∑i=1Nθti _t+1= 1N _i=1^N _t^i. This repeats until convergence. 3.2 Attacks on FedGL Backdoor attacks on FedGL are centered on data poisoning. In this approach, malicious clients poison local data by injecting trigger subgraphs which can be static (Xu et al., 2022) or adaptively generated for each local graph by a trigger generator (Xi et al., 2021; Yang et al., 2024b) and relabel the graphs to the target class yty_t. Adversarial attacks on FedGL, in contrast, avoid data poisoning. Instead, attackers use their own clean data to perform post-hoc optimization after the federated training process is complete, learning to construct adversarial samples that find and exploit the inherent vulnerabilities of the converged global model (Li et al., 2025). 3.3 Threat Model Our threat model considers an attacker controlling a subset of malicious clients CM⊂C_M⊂ C to achieve a stealthy, effective, and efficient attack. We assume the following: • Attacker’s knowledge: Malicious clients only know their own local data iD_i and the global model parameters θt _t received from the server during FedGL training. • Attacker’s capability: Malicious clients can inject and continuously optimize shifters within their local training data throughout the whole federated process. • Attacker’s objective: The attacker aims to generate adversarial samples that are misclassified by the global model as the target label, without compromising the model’s classification accuracy on clean data. 4 Method To address the dilemmas of existing attacks on FedGL, we propose a novel two-stage distributed adversarial attack framework, named FedShift, whose overall workflow is illustrated in Figure 1. The goal of Stage 1, Gentle Data Poisoning, is to train an adaptive shifter generator for each malicious client before federated training begins. This generator produces a gentle distributional shift to solve the backdoor signal smoothing problem and improve attack stealthiness. Furthermore, the shifter generator can be fine-tuned online during the subsequent federated training process according to the dynamic changes of the global model. After federated training is complete, Stage 2, Adversarial Perturbation Finding, utilizes the shifter generator trained in Stage 1 as an optimization starting point to efficiently and stably optimize the shifter as an effective adversarial perturbation. During the final attack, adversarial perturbations from multiple malicious clients are aggregated to generate the adversarial sample, thereby triggering an effective attack. Figure 1: Pipeline of our two-stage adversarial attack. Training: In Stage 1, each malicious client uses local data to train a shifter generator and injects hidden shifters into the training data. During federated training, malicious clients inject the backdoor signal into the global model through the federated aggregation mechanism. In Stage 2, using the shifter generator trained in Stage 1 as a high-quality starting point, the shifter is further optimized as an effective adversarial perturbation leveraging the information from the global model. Attack: Aggregate adversarial perturbations from multiple malicious clients to generate the adversarial sample and trigger the attack. 4.1 Stage 1: Gentle Data Poisoning The core of this stage is to train an adaptive shifter generator for each malicious client and inject hidden shifters into the training data before federated training. This involves two main steps. First, each malicious client trains a local GNN model using its local data to guide the subsequent training of the shifter generator. Second, each malicious client trains its local adaptive shifter generator to achieve the implantation of stealthy backdoor signals. 4.1.1 Training the local GNN model We adopt the Graph Attention Network (GAT) (Veličković et al., 2017) as the local GNN model. Through its attention mechanism, GAT offers both powerful modeling capabilities and excellent interpretability in graph representation learning. For each client i, its local GNN model θi∗ _i^* is obtained by minimizing the loss on its local dataset iD_i: θi∗=argminθiℒ(i;θi). _i^*= argmin_ _iL(D_i; _i). (2) This pre-trained local model θi∗ _i^* will be used as a stable evaluation tool to extract high-quality graph embeddings and guide the selection of training graphs in the subsequent shifter generator training. Notably, during the federated training process, the global GNN model received from the server can be optionally utilized to fine-tune the shifter generator. This enables it to leverage the rich information aggregated by the global model in each epoch, which is similar to the method in Opt-GDBA (Yang et al., 2024b). 4.1.2 Adaptive shifter generator Our adaptive shifter generator comprises two core components: shifter position learning and shifter shape learning. The former identifies key nodes in the graph to maximize attack impact and enhance efficiency. The latter generates adaptive shifter to enable stealthy and effective backdoor implantation. 1) Shifter position learning: For a given input graph G∈iG _i, our goal is to select a subset of nodes p⊂V_p to be injected with the shifter. Specifically, we introduce an efficient and low-complexity algorithm that calculates the clustering coefficient based on the type of graph data, its internal topological structure, and the weights of nodes and edges, to measure the influence of the nodes in the graph. The specific formulas is provided in the Appendix A.2. After calculating the clustering coefficient values for all nodes in the graph, we select the set of nodes with the highest values as the subset of nodes pV_p to be injected with the hidden shifter. Algorithm 1 Adaptive Shifter Generator Training Input: Malicious client set CMC_M with local dataset ii∈CM\D_i\_i∈ C_M and pre-trained local GNN model θi∗i∈CM\ _i^*\_i∈ C_M, initial shifter generator parameters ωi0i∈CM\ _i^0\_i∈ C_M, target class yty_t. Parameter: Number of clusters k, training epochs E, learning rate η, number of nodes to perturb ntrin_tri, loss weights λdist,λhomo,λce _dist, _homo, _ce. Output: Malicious clients’ trained shifter generator parameters ωii∈CM\ _i\_i∈ C_M. 1: for each malicious client i∈CMi∈ C_M do 2: Select yt,train⊆iD_y_t,D_train _i 3: t←Enc(Gj;θi∗)∣Gj∈ytV_t←\Enc(G_j; _i^*) G_j _y_t\ 4: t←KMeans(t,k)C_t (V_t,k) 5: for each epoch e=1,…,Ee=1,…,E do 6: for each graph G∈trainG _train do 7: δ←Ggen(i)(G,p;ωi)δ← G_gen^(i)(G,V_p; _i) 8: Gp←G⊕δG_p← G δ 9: vp←Enc(Gp;θi∗)v_p (G_p; _i^*) 10: cnear←argmincj∈t‖vp−cj‖2c_near← c_j _targmin\,\|v_p-c_j\|_2 11: Ldist←1−cos(vp,cnear)L_dist← 1- (v_p,c_near) 12: Lhomo←Homogeneity(Gp,p)L_homo (G_p,V_p) 13: Lce←CrossEntropy(f(Gp;θi∗),label(G))L_ce (f(G_p; _i^*),label(G)) 14: Lstage1←λdistLdist+λhomoLhomo+λceLceL_stage1← _distL_dist+ _homoL_homo+ _ceL_ce 15: ωi←ωi−η⋅∇ωiLstage1 _i← _i-η· _ _iL_stage1 16: end for 17: end for 18: end for 19: return ωii∈CM\ _i\_i∈ C_M 2) Shifter Shape Learning: After determining the node positions pV_p for shifter injection, the objective of shape learning is to generate a specific shifter δ to achieve a stealthy attack, as outlined in Algorithm 1. i) Distributional proximity loss: Unlike existing attack methods that directly modify labels to enforce target mappings, we propose a distributional proximity loss to ensure the attack’s stealthiness. Specifically, for the i-th malicious client, we leverage its pre-trained local GNN model θi∗ _i^* to extract high-dimensional graph embeddings. We define Enc(⋅;θi∗)Enc(·; _i^*) as a function that uses the model θi∗ _i^* to extract the embedding vector from the output of the layer preceding the final classifier. We first obtain the embedding vector vpv_p of a poisoned training graph GpG_p (injected with a shifter), and the set of embedding vectors tV_t for all target-class graphs in ytD_y_t: vp=Enc(Gp;θi∗),v_p=Enc(G_p; _i^*), t=Enc(Gj;θi∗)∣Gj∈yt.V_t=\Enc(G_j; _i^*) G_j _y_t\. Next, we apply the k-means clustering111We employ the K-means algorithm for its well-established efficiency and effectiveness. Although more advanced techniques exist, our selection was guided not by the need for a superior clustering algorithm in general, but by the specific requirements of our task: learning the local trigger shape. to the set of target-class embeddings tV_t to obtain k cluster centroids t=c1,…,ckC_t=\c_1,…,c_k\. For the poisoned graph’s embedding vector vpv_p, we find the nearest cluster centroid cnearc_near in tC_t with respect to the cosine distance. Finally, we define the distributional proximity loss LdistL_dist as the cosine distance between these two vectors, thereby minimizing the angular difference between them: Ldist=1−vp⋅cnear‖vp‖2‖cnear‖2.L_dist=1- v_p· c_near\|v_p\|_2\|c_near\|_2. (3) By minimizing LdistL_dist, we guide the generation of the shifter, causing the poisoned graph to gradually approach the distribution area of the target class in the feature space. Since there is no direct label modification or forced mapping construction, this distributional shift is gentle and stealthy. It is worth noting that we only use training graphs that are correctly classified by the local GNN model θi∗ _i^* from each malicious client and prioritize poisoning the training graphs that are farthest (with the largest cosine distance) from the target-class graphs in the feature space, in order to ensure an effective distributional shift. i) Design of adaptive shifter generator: As pointed out by Ding et al. (2025), solely modifying the features of poisoned nodes without altering the graph’s edge connectivity can significantly enhance the attack stealthiness. Inspired by this insight, our adaptive shifter generator GgenG_gen’s objective is, given an original graph Gi=(i,ℰi,i)G_i=(V_i,E_i,X_i) and a determined set of poisoned node positions pV_p, to generate the optimal feature perturbation Δp _p for these nodes. Regarding the specific network architecture of GgenG_gen, we found that simpler models such as Multi-Layer Perceptrons (MLPs) and Graph Convolutional Networks (GCNs) (Kipf and Welling, 2016) are sufficient to effectively capture the local dependencies required for generating perturbations. These models have lower computational overhead and are more suitable for efficiency-sensitive scenarios like federated learning. GgenG_gen can be formally represented as: Δp=Ggen(Gi,p). _p=G_gen(G_i,V_p). (4) We define the attack pattern, which consists of the positions pV_p and the corresponding feature perturbations Δp _p, as the shifter δ=(p,Δp)δ=(V_p, _p). Ultimately, the poisoned graph GpG_p is generated by applying this shifter to the original graph GiG_i, denoted as Gp=Gi⊕δG_p=G_i δ. To further enhance stealthiness, we introduce two supplementary loss terms, Homogeneity Loss and Boundary-Balancing Cross-Entropy Loss. The Homogeneity Loss (LhomoL_homo) is based on the graph homophily assumption, which posits that connected nodes should have similar features: Lhomo=1|ℰ|∑(u,v)∈ℰmax(0,τ−sim(u,v)),L_homo= 1|E| _(u,v) (0,τ-sim(x_u,x_v)), (5) where |ℰ||E| is the number of edges in graph, sim(⋅,⋅)sim(·,·) is the cosine similarity function, and τ is a predefined similarity threshold. We also design the Boundary-Balancing Cross-Entropy Loss (LceL_ce) as a key balancing term, which can prevent the distributional shift from easily crossing the decision boundary. It calculates the cross-entropy loss of the shifter-injected graph GpG_p being predicted as its original correct label ysy_s by the local model θi∗ _i^*: Lce=CrossEntropy(f(Gp;θi∗),ys).L_ce=CrossEntropy(f(G_p; _i^*),y_s). (6) Ultimately, the optimization objective for our adaptive shifter generator model is to minimize the following loss: Lstage1=λdistLdist+λhomoLhomo+λceLce,L_stage1= _distL_dist+ _homoL_homo+ _ceL_ce, (7) where λdist _dist, λhomo _homo, and λce _ce are coefficients to balance the different objectives. 4.2 Stage 2: Adversarial Perturbation Finding After all clients have completed the FedGL training process and a converged global model θ∗θ^* is obtained, the attack enters the final adversarial perturbation finding stage. Unlike NI-GDBA (Li et al., 2025) which optimizes from scratch, we utilize the shifter generator trained in Stage 1 as a high-quality starting point and leverage the rich information aggregated in the global model to efficiently and stably fine-tune the shifter as the final effective adversarial perturbation. The specific optimization process is as follows: the attacker freezes the parameters of the final global model θ∗θ^* and continues to train (or fine-tune) the trigger generator. The optimization objective shifts to maximizing the attack success rate, to ensure that during the final attack, the embedding distribution of the adversarial example—formed by aggregating adversarial perturbations from multiple malicious clients—can cross the decision boundary in the feature space, thereby achieving an effective attack. The optimization is guided by a loss function composed of a standard cross-entropy attack loss LattackL_attack and the homogeneity loss LhomoL_homo: Lattack=CrossEntropy(f(Gp;θ∗),yt),L_attack=CrossEntropy(f(G_p;θ^*),y_t), (8) where GpG_p is a graph injected with the shifter, yty_t is the attacker’s target label. Ultimately, the optimization objective for our adversarial perturbation finding stage is to minimize the following loss: Lstage2=Lattack+λhomoLhomo,L_stage2=L_attack+ _homoL_homo, (9) During the final attack, adversarial perturbations from multiple malicious clients are aggregated to generate the adversarial sample, thereby triggering an effective attack. 5 Experiment Next, we conduct an empirical study of our FedShift to answer the following key questions: • Q1: Can FedShift resist the signal smoothing effect inherent to the FedGL training process? • Q2: Facing existing FedGL defense algorithms, can FedShift ensure attack stealthiness? • Q3: Can FedShift achieve both rapid and stable convergence during the perturbation finding stage? 5.1 Experimental Setup We implement FedShift on FedGL using the PyTorch framework. All experiments are conducted on a server equipped with 8 NVIDIA 4090 GPUs. Each experiment is repeated five times with different random seeds to obtain averaged attack results. Table 1: Statistics of the benchmark datasets used in our experiments. Datasets Graphs Classes Class Ratio Avg. Nodes Avg. Edges Node Feats. D 1,178 2 691 / 487 284.3 715.7 89 NCI109 4,127 2 2,048 / 2,079 29.7 32.1 38 Mutagenicity 4,337 2 2,401 / 1,936 30.3 30.8 14 FRANKENSTEIN 4,337 2 1,936 / 2,401 16.9 17.9 780 Eth-Phish&Hack 5,070 2 2,535 / 2,535 37.8 111.3 5,000 Gossipcop 5,464 2 2,732 / 2,732 57.5 56.5 310 Datasets and training/testing sets: Compared to existing work, we have expanded the scale of our datasets to better simulate real-world scenarios with six large-scale graph datasets that cover four common real-world domains: small compound molecules (Morris et al., 2020), bioinformatics (Morris et al., 2020), social networks (Dou et al., 2021), and finance (Zhou et al., 2022). Table 1 shows the detailed statistics of our six large-scale graphs datasets. Detailed information can be find in Appendix A.3. For each dataset, we randomly sample 80% of the data instances as the training dataset and the rest as the testing dataset. Attack baselines: We compare FedShift with current state-of-the-art backdoor attack methods, including Rand-GDBA (Xu et al., 2022), GTA (Xi et al., 2021), and Opt-GDBA (Yang et al., 2024b), as well as the adversarial attack method NI-GDBA (Li et al., 2025). Parameter settings: In all experiments, we default to set the trigger node ratio to ntri=0.1n_tri=0.1 for all attack methods. For our FedShift, we set the number of clusters to k=3k=3. The Graph Attention Network (GAT) (Veličković et al., 2017) is used as the backbone classifier for all experiments, with a total of 40 federated training epochs. For each Q, the specific attack settings are as follows: • Q1 settings: To evaluate each attack’s resilience to federated smoothing from benign clients, we adopt a low attack budget, i.e., poisoned graph ratio p=0.1p=0.1 and poisoned node feature dimension ratio f=0.1f=0.1. We fix the number of malicious clients at |CM|=4|C_M|=4 (for the D dataset, which has fewer graphs, we set |CM|=2|C_M|=2) and increase the number of benign clients to set the malicious clients proportion (|CM|/N|C_M|/N) as 0.2, 0.1, and 0.05. • Q2 settings: To test the evasion capability against FedGL defense algorithms, we fix the attack budget at a moderate intensity, i.e., p=0.2,f=0.2p=0.2,f=0.2 and a total of N=40N=40 clients with |CM|=4|C_M|=4 malicious clients (N=20,|CM|=2N=20,|C_M|=2 for the D dataset). We test against three mainstream federated defense algorithms: foolsgold (Fung et al., 2020), fedkrum (Blanchard et al., 2017), and fedbulyan (Guerraoui et al., 2018). • Q3 settings: To verify the attack efficiency under stringent conditions, we adopt a low attack budget of p=0.1,f=0.1p=0.1,f=0.1. We set N=40N=40 and |CM|=4|C_M|=4 (N=20,|CM|=2N=20,|C_M|=2 for the D dataset). We compare the convergence of both our full FedShift model and an ablation variant without federated online fine-tuning against the adversarial attack method NI-GDBA. Evaluation metrics: We use the Attack Success Rate (ASR) to evaluate the attack’s effectiveness and the Original Task Accuracy (OA) to evaluate the GNN model’s performance. We also propose the Adaptive Attack Score (AAS) to evaluate the attack’s comprehensive effectiveness: AAS=ASR⋅OAASR.AAS=ASR·OA^ASR. (10) This metric is designed to prioritize a high ASR, as an attack with only high OA is meaningless. Therefore, the model’s OA contributes significantly to the AAS score only when ASR is sufficiently high. Otherwise, the score is determined almost entirely by the ASR itself. 5.2 Experimental Results 5.2.1 Main results of the compared attacks: The main experimental results are presented in Tables 2, 3 and Figures 2, 3. For more results, please refer to the Appendix A.4.1. We derive the following key observations: Table 2: Attack results in the Q1 setting with the malicious client proportions |CM|/N=0.2|C_M|/N=0.2. Methods Rand-GDBA GTA Opt-GDBA NI-GDBA FedShift (Ours) Metrics AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA D 0.01 0.01 0.63 0.06 0.06 0.64 0.03 0.03 0.65 0.44 0.59 0.61 0.58 0.88 0.62 NCI109 0.39 0.48 0.63 0.62 0.98 0.62 0.56 0.84 0.61 0.50 0.66 0.64 0.65 0.98 0.66 Mutagenicity 0.34 0.38 0.73 0.71 0.99 0.71 0.46 0.56 0.72 0.11 0.12 0.73 0.74 0.99 0.75 FRANKENSTEIN 0.26 0.31 0.58 0.58 1.00 0.58 0.54 0.85 0.59 0.61 1.00 0.61 0.61 1.00 0.61 Eth-Phish&Hack 0.05 0.05 0.91 0.91 0.99 0.92 0.16 0.16 0.91 0.92 1.00 0.92 0.93 1.00 0.93 Gossipcop 0.58 0.79 0.68 0.68 1.00 0.68 0.67 0.94 0.70 0.68 1.00 0.68 0.76 0.99 0.76 Figure 2: Attack results in the Q1 setting under defferent malicious client proportions |CM|/N|C_M|/N. Table 3: Attack results in the Q2 setting under different defenses. Methods Rand-GDBA GTA Opt-GDBA NI-GDBA FedShift (Ours) Defenses Foo. Kru. Bul. Foo. Kru. Bul. Foo. Kru. Bul. Foo. Kru. Bul. Foo. Kru. Bul. D 0.02 0.30 0.30 0.11 0.30 0.30 0.06 0.18 0.18 0.62 0.44 0.44 0.62 0.45 0.45 NCI109 0.14 0.49 0.49 0.44 0.45 0.45 0.39 0.47 0.47 0.57 0.50 0.50 0.59 0.50 0.50 Mutagenicity 0.07 0.19 0.17 0.48 0.48 0.48 0.54 0.48 0.48 0.40 0.46 0.46 0.58 0.49 0.49 FRANKENSTEIN 0.17 0.32 0.31 0.61 0.29 0.29 0.40 0.37 0.37 0.61 0.54 0.54 0.61 0.54 0.54 Eth-Phish&Hack 0.04 0.42 0.42 0.82 0.75 0.75 0.06 0.44 0.44 0.78 0.78 0.78 0.83 0.78 0.78 Gossipcop 0.15 0.00 0.00 0.80 0.00 0.02 0.77 0.00 0.00 0.83 0.50 0.50 0.83 0.54 0.54 Figure 3: Attack results in the adversarial perturbation finding stage in the Q3 setting. 1. For Q1: FedShift effectively resists the signal smoothing inherent in the federated learning process. As shown in Table 2 and Figure 2, as the proportion of malicious clients decreases from 0.2 to 0.05, the ASR of traditional methods drops by an average of 25.6% to 53.3% due to signal smoothing. In contrast, our model’s ASR drops by less than 5% and consistently maintains the best attack effectiveness. This demonstrates our method’s strong resistance to the backdoor signal smoothing, strongly answering Q1. 2. For Q2: FedShift exhibits high stealthiness against existing federated learning defense algorithms. As shown in Table 3, after introducing defense algorithms, our model consistently maintains the best attack effectiveness with the highest AAS, outperforming the strongest baseline method in each scenario by an average of 4.9%. This demonstrates that its stealthiness can effectively evade existing defense algorithms, thereby answering Q2. 3. For Q3: FedShift converges more efficiently to a better result. As shown in Figure 3, compared to NI-GDBA, which optimizes from scratch, our model without federated tuning and our full model require 90.3% and 98.3% fewer epochs, respectively, to achieve the same ASR with an optimized starting point. The superior convergence speed of the full model demonstrates that the effectiveness of federated optimization. The whole result verifies the efficiency of our framework, providing a satisfactory answer to Q3. Figure 4: Impact of f and p of our FedShift. 5.2.2 Impact of hyperparameters on our FedShift In this set of experiments, we will study in-depth the impact of the important hyperparameters on our FedShift. Impact of the poisoned node feature dimension ratio f and the poisoned graph ratio p: As shown in Figure 4, as f increases from 0.1 to 0.3 with p=0.2p=0.2, the AAS and ASR of our method steadily improve, indicating that FedShift can effectively utilize more poisoned node features to achieve better attack effectiveness. Meanwhile, as p increases from 0.1 to 0.3 with f=0.2f=0.2, the AAS and ASR remain at a high level, demonstrating that FedShift is low in dependence on the number of poisoned samples and can be effective with only a small amount of poisoned graphs. Figure 5: Attack results of FedShift with the number of target-class clusters k ranging from 2 to 5. Figure 6: Attack results of FedShift with the trigger node ratio ntrin_tri ranging from 0.05 to 0.20. Impact of the number of clusters k: As shown in Figure 5, the sensitivity of our attack to the number of clusters k varies between datasets. For datasets such as NCI109 and Mutagenicity, the ASR fluctuates with k, suggesting that their target-class embeddings may have a complex or multi-modal structure where the choice of k crucial. In contrast, for datasets like Eth-Phish&Hack and Gossipcop, the attack effectiveness is almost unaffected by k, demonstrating our method’s robustness on datasets where the target-class embeddings likely form a single, dense cluster. Impact of the Trigger Node Ratio ntrin_tri: As shown in Figure 6, the impact of the trigger node ratio ntrin_tri varies across different datasets. For datasets D, NCI109 and Mutagenicity, the ASR shows a gradual increase as ntrin_tri is raised. This indicates that for these graphs data, our model can effectively leverage a larger set of perturbed nodes to progressively enhance the attack’s effectiveness. Conversely, for datasets FRANKENSTEIN, Eth-Phish&Hack and Gossipcop, the ASR remains consistently high and is largely unaffected by an increase in ntrin_tri. This suggests that on these datasets, our method is highly efficient, capable of achieving a near-optimal attack effect by modifying only a very limited number of nodes. 5.2.3 Ablation study Table 4: Performance comparison of different components of our FedShift. Methods Stage 1 Only Stage 1 + FL-Tune Stage 1 + Stage 2 Full FedShift Metrics AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA D 0.34 0.41 0.62 0.38 0.48 0.62 0.52 0.73 0.62 0.53 0.76 0.62 NCI109 0.33 0.42 0.56 0.38 0.51 0.57 0.49 0.77 0.56 0.47 0.69 0.57 Mutagenicity 0.49 0.63 0.66 0.49 0.64 0.66 0.52 0.69 0.66 0.51 0.67 0.66 FRANKENSTEIN 0.40 0.51 0.61 0.58 0.91 0.61 0.61 0.99 0.61 0.61 0.99 0.61 Eth-Phish&Hack 0.66 0.72 0.89 0.86 0.97 0.89 0.88 0.99 0.89 0.88 0.99 0.89 Gossipcop 0.83 0.98 0.84 0.83 0.99 0.84 0.83 0.99 0.84 0.83 1.00 0.84 In this experiment, we examine the necessity of each component in our two-stage framework of FedShift under stringent conditions with a low attack budget of p=0.1,f=0.1p=0.1,f=0.1. The results are shown in Table 4. We compare four settings: using only the first stage (Stage 1 Only), adding federated online fine-tuning (Stage 1 + FL-Tune) or adding the second stage (Stage 1 + Stage 2), and the complete two-stage method (Full FedShift). The results show that compared to Stage 1 Only, adding FL-Tune and Stage 2 increases the average AAS by 17.0% and 32.2% respectively, demonstrating the significant impact of both components, particularly Stage 2. More strikingly, the Stage 1 + Stage 2 configuration achieves a nearly identical level of effectiveness to the full model, which in turn improves upon the Stage 1 + FL-Tune setup by 12.5%. This suggests that incorporating Stage 2 is the key and sufficient step for maximizing the attack’s effectiveness. 6 Conclusion From an attacker’s perspective, we examine the security of FedGL and propose a novel, two-stage distributed adversarial attack method that is effective, stealthy, and efficient. Our method implants hidden and learnable shifters into the training graph via a distributional shift in the first stage, and subsequently uses them as a starting point in the second stage to efficiently find adversarial perturbations. During the final attack, these perturbations are aggregated from multiple clients to form the final effective adversarial sample. Our experiments demonstrate that this method can achieve high attack effectiveness and effectively evade mainstream defense algorithms. This work provides a new perspective for security and defense research on FedGL. Acknowledgments This research was partially supported by the Key Research and Development Project in Shaanxi Province No. 2023GXLH-024, the National Science Foundation of China No. 62476215, 62302380, 62037001, 62137002 and 62192781, and the China Postdoctoral Science Foundation No. 2023M742789. Ethics Statement The FedShift framework we propose reveals a novel and highly stealthy security vulnerability in Federated Graph Learning systems. The fundamental purpose of this research is to raise security awareness in the field, not to facilitate malicious activities. We firmly believe that a deep understanding of advanced attack methods is a necessary prerequisite for constructing stronger and more robust defense strategies. In line with the principles of responsible academic disclosure, we publicize our findings to inspire and aid the research community in developing defense mechanisms capable of effectively countering such two-stage attacks. We encourage our peers in the academic community to leverage the insights from this research to collectively advance Federated Graph Learning towards a more secure and trustworthy future. Reproducibility To ensure the full reproducibility of our research findings, we provide comprehensive supporting materials. The complete source code for all experiments, including model implementations and the scripts used to generate the results, will be made publicly available in a repository upon the paper’s publication. Detailed information regarding the experimental setup, including all hyperparameter configurations and model architectures, is described in the main text. All datasets used in this study are public benchmarks, and their statistics and descriptions are also provided in the Appendix. We hope these resources will facilitate the verification and replication of our work by the research community and encourage further exploration in this area. References J. Baek, W. Jeong, J. Jin, J. Yoon, and S. J. Hwang (2023) Personalized subgraph federated learning. In International conference on machine learning, p. 1396–1415. Cited by: §1. E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov (2020) How to backdoor federated learning. In International conference on artificial intelligence and statistics, p. 2938–2948. Cited by: §1. P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer (2017) Machine learning with adversaries: byzantine tolerant gradient descent. Advances in neural information processing systems 30. Cited by: §1, 2nd item. E. Dai, M. Lin, X. Zhang, and S. Wang (2023) Unnoticeable backdoor attacks on graph neural networks. In Proceedings of the ACM Web Conference 2023, p. 2263–2273. Cited by: §1, §2. Y. Ding, Y. Liu, Y. Ji, W. Wen, Q. He, and X. Ao (2025) SPEAR: a structure-preserving manipulation method for graph backdoor attacks. In Proceedings of the ACM on Web Conference 2025, p. 1237–1247. Cited by: §4.1.2. Y. Dou, K. Shu, C. Xia, P. S. Yu, and L. Sun (2021) User preference-aware fake news detection. In Proceedings of the 44th international ACM SIGIR conference on research and development in information retrieval, p. 2051–2055. Cited by: §5.1. C. Fung, C. J. Yoon, and I. Beschastnikh (2020) The limitations of federated learning in sybil settings. In 23rd International symposium on research in attacks, intrusions and defenses (RAID 2020), p. 301–316. Cited by: 2nd item. M. Goddard (2017) The eu general data protection regulation (gdpr): european regulation that has a global impact. International Journal of Market Research 59 (6), p. 703–705. Cited by: §1. R. Guerraoui, S. Rouault, et al. (2018) The hidden vulnerability of distributed learning in byzantium. In International conference on machine learning, p. 3521–3530. Cited by: 2nd item. C. He, K. Balasubramanian, E. Ceyani, C. Yang, H. Xie, L. Sun, L. He, L. Yang, P. S. Yu, Y. Rong, et al. (2021) Fedgraphnn: a federated learning system and benchmark for graph neural networks. arXiv preprint arXiv:2104.07145. Cited by: §1. C. He, E. Ceyani, K. Balasubramanian, M. Annavaram, and S. Avestimehr (2022) Spreadgnn: decentralized multi-task federated learning for graph neural networks on molecular data. In Proceedings of the AAAI conference on artificial intelligence, Vol. 36, p. 6865–6873. Cited by: §1, §2. P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, M. Bennis, A. N. Bhagoji, K. Bonawitz, Z. Charles, G. Cormode, R. Cummings, et al. (2021) Advances and open problems in federated learning. Foundations and trends® in machine learning 14 (1–2), p. 1–210. Cited by: §1. T. N. Kipf and M. Welling (2016) Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907. Cited by: §4.1.2. K. Li, B. Shi, J. Wei, and B. Dong (2025) NI-gdba: non-intrusive distributed backdoor attack based on adaptive perturbation on federated graph learning. In Proceedings of the ACM on Web Conference 2025, p. 852–862. Cited by: §1, §1, §2, §3.2, §4.2, §5.1. R. Liu, P. Xing, Z. Deng, A. Li, C. Guan, and H. Yu (2024) Federated graph neural networks: overview, techniques, and challenges. IEEE transactions on neural networks and learning systems. Cited by: §1, §2. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas (2017) Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics, p. 1273–1282. Cited by: §2. C. Morris, N. M. Kriege, F. Bause, K. Kersting, P. Mutzel, and M. Neumann (2020) TUDataset: a collection of benchmark datasets for learning with graphs. In ICML 2020 Workshop on Graph Representation Learning and Beyond (GRL+ 2020), External Links: 2007.08663, Link Cited by: §5.1. L. Peng, N. Wang, N. Dvornek, X. Zhu, and X. Li (2022) Fedni: federated graph learning with network inpainting for population-based disease prediction. IEEE Transactions on Medical Imaging 42 (7), p. 2032–2043. Cited by: §1. F. Scarselli, M. Gori, A. C. Tsoi, M. Hagenbuchner, and G. Monfardini (2008) The graph neural network model. IEEE transactions on neural networks 20 (1), p. 61–80. Cited by: §1, §2. P. Veličković, G. Cucurull, A. Casanova, A. Romero, P. Lio, and Y. Bengio (2017) Graph attention networks. arXiv preprint arXiv:1710.10903. Cited by: §4.1.1, §5.1. C. Wu, F. Wu, L. Lyu, T. Qi, Y. Huang, and X. Xie (2022) A federated graph neural network framework for privacy-preserving personalization. Nature Communications 13 (1), p. 3091. Cited by: §1. J. Wu, N. Lu, Z. Dai, K. Wang, W. Fan, S. Liu, Q. Li, and K. Tang (2024) Backdoor graph condensation. arXiv preprint arXiv:2407.11025. Cited by: §1, §2. Z. Xi, R. Pang, S. Ji, and T. Wang (2021) Graph backdoor. In 30th USENIX security symposium (USENIX Security 21), p. 1523–1540. Cited by: §1, §1, §3.2, §5.1. C. Xie, K. Huang, P. Chen, and B. Li (2019) Dba: distributed backdoor attacks against federated learning. In International conference on learning representations, Cited by: §1. H. Xie, L. Xiong, and C. Yang (2023) Federated node classification over graphs with latent link-type heterogeneity. In Proceedings of the ACM Web Conference 2023, p. 556–566. Cited by: §1, §2. J. Xu, S. Koffas, and S. Picek (2024) Unveiling the threat: investigating distributed and centralized backdoor attacks in federated graph neural networks. Digital Threats: Research and Practice 5 (2), p. 1–29. Cited by: §1. J. Xu, R. Wang, S. Koffas, K. Liang, and S. Picek (2022) More is better (mostly): on the backdoor attacks in federated graph neural networks. In Proceedings of the 38th Annual Computer Security Applications Conference, p. 684–698. Cited by: §1, §2, §3.2, §5.1. X. Yang, G. Li, and J. Li (2024a) Graph neural backdoor: fundamentals, methodologies, applications, and future directions. arXiv preprint arXiv:2406.10573. Cited by: §1, §2. Y. Yang, Q. Li, J. Jia, Y. Hong, and B. Wang (2024b) Distributed backdoor attacks on federated graph learning and certified defenses. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, p. 2829–2843. Cited by: §1, §2, §3.2, §4.1.1, §5.1. J. Zhou, C. Hu, J. Chi, J. Wu, M. Shen, and Q. Xuan (2022) Behavior-aware account de-anonymization on ethereum interaction graph. IEEE Transactions on Information Forensics and Security 17, p. 3433–3448. Cited by: §5.1. Appendix A Appendix A.1 The Use of Large Language Models During the writing process of this paper, we used a Large Language Model (LLM) as a writing assistance tool. Its use was limited to language polishing, style optimization, and grammar checks. We explicitly state that all core research ideas, theoretical derivations, experimental design, and result analysis were conducted independently by the human authors. We take full responsibility for the entire content of the paper and have carefully reviewed and verified the accuracy and originality of all of its statements. A.2 Clustering Coefficient Calculation In our work, the influence of nodes within a graph is measured by the clustering coefficient. The formulas are detailed below: • For unweighted graphs: The clustering coefficient c(u)c(u) of a node u is the fraction of possible triangles through the node that exist. It is calculated as: c(u)=2⋅(u)d(u)(d(u)−1),c(u)= 2·T(u)d(u)(d(u)-1), (11) where (u)T(u) denotes the number of triangles through node u, and d(u)d(u) is the degree of node u. When d(u)<2d(u)<2, the value of c(u)c(u) is set to 0. • For weighted graphs: The clustering coefficient is defined as the geometric average of the subgraph edge weights: c(u)=1d(u)(d(u)−1)∑v,w(ω^uvω^uwω^vw)1/3,c(u)= 1d(u)(d(u)-1) _v,w( ω_uv ω_uw ω_vw)^1/3, (12) where ω^uv ω_uv is the edge weight ωuv _uv normalized by the maximum weight in the network. • For directed graphs: The clustering coefficient considers the directionality of edges as: c(u)=2⋅d(u)dtot(u)(dtot(u)−1)−2d↔(u),c(u)= 2·T_d(u)d^tot(u)(d^tot(u)-1)-2d (u), (13) where d(u)T_d(u) is the number of directed triangles through node u, dtot(u)d^tot(u) is the sum of the in-degree and out-degree of u, and d↔(u)d (u) is the reciprocal degree of u. A.3 Dataset Statistics and Descriptions Table 1 shows the detailed statistics of our six large-scale graphs datasets. The descriptions of these datasets are as below: D: It is a dataset of protein structures, where each protein is represented as a graph. The task is to classify each structure as either an enzyme or a non-enzyme. NCI109: It consists of chemical compounds screened for activity against ovarian cancer cell lines. Each graph represents a compound, and the task is to classify whether it is active in an anti-cancer screen. Mutagenicity: It is a toxicology dataset where each graph represents a molecular structure. The task is to classify each molecule as mutagenic or non-mutagenic. FRANKENSTEIN: It consists of molecular graphs with a binary label indicating their toxicological properties. Each vertex is labeled by the chemical atom symbol and edges by the bond type. Eth-Phish&Hack: It derives from Ethereum transactions. Each graph represents an account’s transaction subgraph, and the task is to identify accounts associated with phishing or hacking activities. Due to GPU memory constraints, we only select 5,000 node feature dimensions for our experiments. Gossipcop: This dataset is used for the detection of fake news in the social networks domain. Each graph represents the propagation network of a news story on Twitter, and the task is to classify the news as either real or fake. A.4 Additional Experimental Results A.4.1 More Attack Results Table 5: Attack results in the Q1 setting with the malicious client proportions |CM|/N=0.1|C_M|/N=0.1. Methods Rand-GDBA GTA Opt-GDBA NI-GDBA FedShift (Ours) Metrics AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA D 0.02 0.02 0.63 0.02 0.02 0.64 0.05 0.05 0.66 0.48 0.65 0.63 0.57 0.86 0.62 NCI109 0.15 0.16 0.60 0.31 0.37 0.61 0.30 0.35 0.60 0.44 0.59 0.60 0.64 0.96 0.66 Mutagenicity 0.07 0.07 0.65 0.53 0.73 0.65 0.09 0.09 0.65 0.26 0.29 0.65 0.72 0.97 0.74 FRANKENSTEIN 0.18 0.20 0.61 0.53 0.79 0.61 0.28 0.33 0.61 0.61 1.00 0.61 0.61 0.99 0.61 Eth-Phish&Hack 0.04 0.04 0.87 0.70 0.78 0.87 0.05 0.05 0.87 0.87 1.00 0.87 0.88 1.00 0.89 Gossipcop 0.23 0.24 0.83 0.81 0.99 0.82 0.65 0.75 0.83 0.82 1.00 0.82 0.83 1.00 0.84 Table 6: Attack results in the Q1 setting with the malicious client proportions |CM|/N=0.05|C_M|/N=0.05. Methods Rand-GDBA GTA Opt-GDBA NI-GDBA FedShift (Ours) Metrics AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA AAS ASR OA D 0.02 0.02 0.64 0.02 0.02 0.65 0.08 0.09 0.68 0.52 0.71 0.65 0.57 0.85 0.62 NCI109 0.16 0.18 0.59 0.25 0.29 0.60 0.28 0.33 0.59 0.46 0.65 0.59 0.64 0.95 0.66 Mutagenicity 0.06 0.06 0.63 0.43 0.56 0.63 0.07 0.08 0.63 0.71 0.95 0.74 0.71 0.95 0.74 FRANKENSTEIN 0.16 0.17 0.60 0.24 0.28 0.60 0.22 0.25 0.60 0.60 1.00 0.60 0.59 0.99 0.60 Eth-Phish&Hack 0.04 0.04 0.86 0.45 0.49 0.86 0.04 0.04 0.86 0.86 0.99 0.87 0.86 0.99 0.87 Gossipcop 0.14 0.14 0.81 0.69 0.83 0.80 0.33 0.36 0.80 0.80 1.00 0.80 0.81 1.00 0.81 Tables 5 and 6 present the attack results for the Q1 setting with lower malicious client proportions (|CM|/N=0.1|C_M|/N=0.1 and |CM|/N=0.05|C_M|/N=0.05). The results show that when the proportion of malicious clients is low, the ASR and AAS values of the baseline methods drop significantly. In contrast, our method maintains high ASR and AAS, demonstrating its strong resistance to backdoor signal smoothing and further answering Q1.