Revisiting Asymmetries in Black-box Link Stealing against Graph Neural Networks
Paul Agbaje, Habeeb Olufowobi
Abstract
Graph Neural Networks (GNNs) are increasingly deployed on sensitive relational data, from social networks to healthcare records. However, their outputs can leak private graph structure, enabling link-stealing attacks that infer whether a connection between two entities existed in the training graph. While prior work demonstrates high average performance for such attacks, privacy is fundamentally a worst-case property, not an average one. The key question is whether an adversary can reliably compromise even a small set of critical links under strict precision constraints. We revisit posterior-only link-stealing attacks in a strict black-box setting and show that they remain effective at extremely low false-positive rates, revealing tail-risk vulnerabilities that current evaluations overlook. We further find that intra-class vulnerabilities are suppressed by geometric bottlenecks that collapse discriminative directions in posterior space. Building on this insight, we propose a geometry-aware reconditioning method that reshapes intra-class distances, substantially improving separability without harming reliability. Across multiple real-world graphs and GNNs, this diagnostic correction achieves up to higher success on intra-class pairs than generic attacks, redefining link-privacy evaluation as a tail-risk problem and revealing that posterior leakage remains substantially under-measured in current GNN deployments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0135b0f6-a932-47ad-98b9-808d9b30d4eeBuilds on6
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
- Demystifying Uneven Vulnerability of Link Stealing Attacks against Graph Neural NetworksHe Zhang, Bang Wu, Shuo Wang, Xiangwen Yang et al.ICML 2023 · 20 citations
- Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity VerificationBang Wu, Xingliang Yuan, Shuo Wang, Qi Li et al.S&P 2024 · 13 citations
Related papers
- LPGNet: Link Private Graph Networks for Node ClassificationAashish Kolluri, Teodora Baluta, Bryan Hooi, Prateek SaxenaCCS 2022 · 24 citations
- VertexSerum: Poisoning Graph Neural Networks for Link InferenceRuyi Ding, Shijin Duan, Xiaolin Xu, Yunsi FeiICCV 2023 · 6 citations
- GRID: Protecting Training Graph from Link Stealing Attacks on GNN ModelsJiadong Lou, Xu Yuan, Rui Zhang, Xingliang Yuan et al.S&P 2025
- LinkThief: Combining Generalized Structure Knowledge with Node Similarity for Link Stealing Attack against GNNYuxing Zhang, Siyuan Meng, Chunchun Chen, Mengyao Peng et al.ACM MM 2024 · 1 citation
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu et al.CCS 2023 · 9 citations
