Inference Attacks Against Graph Neural Networks

被引:0
|
作者
Zhang, Zhikun [1 ]
Chen, Min [1 ]
Backes, Michael [1 ]
Shen, Yun [2 ]
Zhang, Yang [1 ]
机构
[1] CISPA Helmholtz Ctr Informat Secur, Berlin, Germany
[2] Norton Res Grp, Madrid, Spain
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Graph is an important data representation ubiquitously existing in the real world. However, analyzing the graph data is computationally difficult due to its non-Euclidean nature. Graph embedding is a powerful tool to solve the graph analytics problem by transforming the graph data into low-dimensional vectors. These vectors could also be shared with third parties to gain additional insights of what is behind the data. While sharing graph embedding is intriguing, the associated privacy risks are unexplored. In this paper, we systematically investigate the information leakage of the graph embedding by mounting three inference attacks. First, we can successfully infer basic graph properties, such as the number of nodes, the number of edges, and graph density, of the target graph with up to 0.89 accuracy. Second, given a subgraph of interest and the graph embedding, we can determine with high confidence that whether the subgraph is contained in the target graph. For instance, we achieve 0.98 attack AUC on the DD dataset. Third, we propose a novel graph reconstruction attack that can reconstruct a graph that has similar graph structural statistics to the target graph. We further propose an effective defense mechanism based on graph embedding perturbation to mitigate the inference attacks without noticeable performance degradation for graph classification tasks.(1)
引用
收藏
页码:4543 / 4560
页数:18
相关论文
共 50 条
  • [1] Membership Inference Attacks Against Robust Graph Neural Network
    Liu, Zhengyang
    Zhang, Xiaoyu
    Chen, Chenyang
    Lin, Shen
    Li, Jingjin
    [J]. CYBERSPACE SAFETY AND SECURITY, CSS 2022, 2022, 13547 : 259 - 273
  • [2] Model Inversion Attacks Against Graph Neural Networks
    Zhang, Zaixi
    Liu, Qi
    Huang, Zhenya
    Wang, Hao
    Lee, Chee-Kong
    Chen, Enhong
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (09) : 8729 - 8741
  • [3] Explanatory subgraph attacks against Graph Neural Networks
    Wang, Huiwei
    Liu, Tianhua
    Sheng, Ziyu
    Li, Huaqing
    [J]. NEURAL NETWORKS, 2024, 172
  • [4] Graph Structure Reshaping Against Adversarial Attacks on Graph Neural Networks
    Wang, Haibo
    Zhou, Chuan
    Chen, Xin
    Wu, Jia
    Pan, Shirui
    Li, Zhao
    Wang, Jilong
    Yu, Philip S.
    [J]. IEEE Transactions on Knowledge and Data Engineering, 2024, 36 (11) : 6344 - 6357
  • [5] Model Stealing Attacks Against Inductive Graph Neural Networks
    Shen, Yun
    He, Xinlei
    Han, Yufei
    Zhang, Yang
    [J]. 43RD IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2022), 2022, : 1175 - 1192
  • [6] GNNGUARD: Defending Graph Neural Networks against Adversarial Attacks
    Zhang, Xiang
    Zitnik, Marinka
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [7] Robust Heterogeneous Graph Neural Networks against Adversarial Attacks
    Zhang, Mengmei
    Wang, Xiao
    Zhu, Meiqi
    Shi, Chuan
    Zhang, Zhiqiang
    Zhou, Jun
    [J]. THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 4363 - 4370
  • [8] Membership Inference Attacks Against the Graph Classification
    Yang, Junze
    Li, Hongwei
    Fan, Wenshu
    Zhang, Xilin
    Hao, Meng
    [J]. IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 6729 - 6734
  • [9] HeteroGuard: Defending Heterogeneous Graph Neural Networks against Adversarial Attacks
    Kumarasinghe, Udesh
    Nabeel, Mohamed
    De Zoysa, Kasun
    Gunawardana, Kasun
    Elvitigala, Charitha
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW, 2022, : 698 - 705
  • [10] Defense against membership inference attack in graph neural networks through graph perturbation
    Kai Wang
    Jinxia Wu
    Tianqing Zhu
    Wei Ren
    Ying Hong
    [J]. International Journal of Information Security, 2023, 22 : 497 - 509