Defense against membership inference attack in graph neural networks through graph perturbation

被引:6
|
作者
Wang, Kai [1 ]
Wu, Jinxia [1 ]
Zhu, Tianqing [1 ]
Ren, Wei [1 ]
Hong, Ying [2 ]
机构
[1] China Univ Geosci, Sch Comp Sci, 388 Lumo Rd, Wuhan 430074, Peoples R China
[2] Wuhan Text Univ, Sch Comp Sci & Artificial Intelligence, 1 Sunshine Ave, Wuhan 430200, Peoples R China
关键词
Graph neural network; Graph privacy-preserving; Membership inference attack; Perturbation injection; DEEP LEARNING ARCHITECTURE; PRIVACY;
D O I
10.1007/s10207-022-00646-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Graph neural networks have demonstrated remarkable performance in learning node or graph representations for various graph-related tasks. However, learning with graph data or its embedded representations may induce privacy issues when the node representations contain sensitive or private user information. Although many machine learning models or techniques have been proposed for privacy preservation of traditional non-graph structured data, there is limited work to address graph privacy concerns. In this paper, we investigate the privacy problem of embedding representations of nodes, in which an adversary can infer the user's privacy by designing an inference attack algorithm. To address this problem, we develop a defense algorithm against white-box membership inference attacks, based on perturbation injection on the graph. In particular, we employ a graph reconstruction model and inject a certain size of noise into the intermediate output of the model, i.e., the latent representations of the nodes. The experimental results obtained on real-world datasets, along with reasonable usability and privacy metrics, demonstrate that our proposed approach can effectively resist membership inference attacks. Meanwhile, based on our method, the trade-off between usability and privacy brought by defense measures can be observed intuitively, which provides a reference for subsequent research in the field of graph privacy protection.
引用
收藏
页码:497 / 509
页数:13
相关论文
共 50 条
  • [1] Defense against membership inference attack in graph neural networks through graph perturbation
    Kai Wang
    Jinxia Wu
    Tianqing Zhu
    Wei Ren
    Ying Hong
    International Journal of Information Security, 2023, 22 : 497 - 509
  • [2] Membership Inference Attack on Graph Neural Networks
    Olatunji, Iyiola E.
    Nejdl, Wolfgang
    Khosla, Megha
    2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021), 2021, : 11 - 20
  • [3] Topology modification against membership inference attack in Graph Neural Networks
    Guan, Faqian
    Zhu, Tianqing
    Tong, Hanjin
    Zhou, Wanlei
    KNOWLEDGE-BASED SYSTEMS, 2024, 305
  • [4] Membership Inference Attacks Against Robust Graph Neural Network
    Liu, Zhengyang
    Zhang, Xiaoyu
    Chen, Chenyang
    Lin, Shen
    Li, Jingjin
    CYBERSPACE SAFETY AND SECURITY, CSS 2022, 2022, 13547 : 259 - 273
  • [5] Inference Attacks Against Graph Neural Networks
    Zhang, Zhikun
    Chen, Min
    Backes, Michael
    Shen, Yun
    Zhang, Yang
    PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, 2022, : 4543 - 4560
  • [6] Pairwise Gaussian Graph Convolutional Networks: Defense Against Graph Adversarial Attack
    Lu, Guangxi
    Xiong, Zuobin
    Meng, Jing
    Li, Wei
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 4371 - 4376
  • [7] Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective
    Xu, Kaidi
    Chen, Hongge
    Liu, Sijia
    Chen, Pin-Yu
    Weng, Tsui-Wei
    Hong, Mingyi
    Lin, Xue
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 3961 - 3967
  • [8] Membership Inference Attacks Against the Graph Classification
    Yang, Junze
    Li, Hongwei
    Fan, Wenshu
    Zhang, Xilin
    Hao, Meng
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 6729 - 6734
  • [9] Imperceptible graph injection attack on graph neural networks
    Chen, Yang
    Ye, Zhonglin
    Wang, Zhaoyang
    Zhao, Haixing
    COMPLEX & INTELLIGENT SYSTEMS, 2024, 10 (01) : 869 - 883
  • [10] Imperceptible graph injection attack on graph neural networks
    Yang Chen
    Zhonglin Ye
    Zhaoyang Wang
    Haixing Zhao
    Complex & Intelligent Systems, 2024, 10 : 869 - 883