Lune

INFOCOM2025Top-tier venue

Preference Profiling Attacks Against Vertical Federated Learning Over Graph Data

Yimin Liu, Peng Jiang, Liehuang Zhu

2025Year
1Citations

Abstract

Graph-based vertical federated learning (GVFL) enables a service provider (i.e., active party) who owns a labeled graph to collaborate with passive parties who possess auxiliary node features and edges to improve model performance. The labeled training graph reflects the active party's class preference, whose leakage brings about the exposure of commercial trade secrets. However, the potential for class preference leakage in GVFL has not been investigated. In this paper, we propose SGPP, a generic attack framework for profiling the active party's class preference in G VFL where the adversary is allowed to only access a trained extractor and a labeled graph from a non-training domain. SGPP generates a compatible surrogate classifier with the extractor to extract sensitivity and a preference classifier to predict its preferred class, thereby profiling the class preference. To ensure accurate sensitivity extraction and prediction, we introduce an Adversarial Correction Block (ACB) to adapt classifiers for generalizing cross-domain inputs. Evaluation with two attack scenarios on diverse graph datasets confirms the effectiveness of SGPP.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 23b43911-e50e-457e-8aac-ce1c463ceb68

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines