Preference Profiling Attacks Against Vertical Federated Learning Over Graph Data
Yimin Liu, Peng Jiang, Liehuang Zhu
Abstract
Graph-based vertical federated learning (GVFL) enables a service provider (i.e., active party) who owns a labeled graph to collaborate with passive parties who possess auxiliary node features and edges to improve model performance. The labeled training graph reflects the active party's class preference, whose leakage brings about the exposure of commercial trade secrets. However, the potential for class preference leakage in GVFL has not been investigated. In this paper, we propose SGPP, a generic attack framework for profiling the active party's class preference in G VFL where the adversary is allowed to only access a trained extractor and a labeled graph from a non-training domain. SGPP generates a compatible surrogate classifier with the extractor to extract sensitivity and a preference classifier to predict its preferred class, thereby profiling the class preference. To ensure accurate sensitivity extraction and prediction, we introduce an Adversarial Correction Block (ACB) to adapt classifiers for generalizing cross-domain inputs. Evaluation with two attack scenarios on diverse graph datasets confirms the effectiveness of SGPP.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 23b43911-e50e-457e-8aac-ce1c463ceb68Related papers
- Generic Adversarial Attack Framework Against Graph-based Vertical Federated LearningYimin Liu, Peng Jiang, Qi Liu, Liehuang ZhuAAAI 2026
- Federated Graph Learning under Domain Shift with Generalizable PrototypesGuancheng Wan, Wenke Huang, Mang YeAAAI 2024 · 70 citations
- FedSSP: Federated Graph Learning with Spectral Knowledge and Personalized PreferenceZihan Tan, Guancheng Wan, Wenke Huang, Mang YeNeurIPS 2024 · 40 citations
- PPA: Preference Profiling Attack Against Federated LearningChunyi Zhou, Yansong Gao, Anmin Fu, Kai Chen et al.NDSS 2023
- GuardFGL: Similarity-driven Federated Graph Learning with Adversarial Robustness and Membership PrivacyLuying Zhong, Xuan Lai, Junjie Zhang, Zhiqin Huang et al.KDD 2025
