Group Property Inference Attacks Against Graph Neural Networks
Xiuling Wang, Wendy Hui Wang
Abstract
With the fast adoption of machine learning (ML) techniques, sharing of ML models is becoming popular. However, ML models are vulnerable to privacy attacks that leak information about the training data. In this work, we focus on a particular type of privacy attacks named property inference attack (PIA) which infers the sensitive properties of the training data through the access to the target ML model. In particular, we consider Graph Neural Networks (GNNs) as the target model, and distribution of particular groups of nodes and links in the training graph as the target property. While the existing work has investigated PIAs that target at graph-level properties, no prior works have studied the inference of node and link properties at group level yet. In this work, we perform the first systematic study of group property inference attacks (GPIA) against GNNs. First, we consider a taxonomy of threat models under both black-box and white-box settings with various types of adversary knowledge, and design six different attacks for these settings. We evaluate the effectiveness of these attacks through extensive experiments on three representative GNN models and three real-world graphs. Our results demonstrate the effectiveness of these attacks whose accuracy outperforms the baseline approaches. Second, we analyze the underlying factors that contribute to GPIA's success, and show that the target model trained on the graphs with or without the target property represents some dissimilarity in model parameters and/or model outputs, which enables the adversary to infer the existence of the property. Further, we design a set of defense mechanisms against the GPIA attacks, and demonstrate that these mechanisms can reduce attack accuracy effectively with small loss on GNN model accuracy. CCS CONCEPTS • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 27c7b2f3-c724-4a20-9cbe-7ab69e8c05faCited by top-tier papers13
- GrOVe: Ownership Verification of Graph Neural Networks using EmbeddingsAsim Waheed, Vasisht Duddu, N. AsokanS&P 2024 · 19 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Inf2Guard: An Information-Theoretic Framework for Learning Privacy-Preserving Representations against Inference AttacksSayedeh Leila Noorbakhsh, Binghui Zhang, Yuan Hong, Binghui WangUSENIX Security 2024 · 17 citations
- Turning Privacy-preserving Mechanisms against Federated LearningMarco Arazzi, Mauro Conti, Antonino Nocera, Stjepan PicekCCS 2023 · 12 citations
- Prompt-based Unifying Inference Attack on Graph Neural NetworksYuecen Wei, Xingcheng Fu, Lingyun Liu, Qingyun Sun et al.AAAI 2025 · 6 citations
Builds on16
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant RepresentationsKaran Ganju, Qi Wang, Wei Yang, Carl A. Gunter et al.CCS 2018 · 574 citations
Related papers
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
- Inference Attacks Against Graph Neural NetworksZhikun Zhang, Min Chen, Michael Backes, Yun Shen et al.USENIX Security 2022
- Demystifying Uneven Vulnerability of Link Stealing Attacks against Graph Neural NetworksHe Zhang, Bang Wu, Shuo Wang, Xiangwen Yang et al.ICML 2023 · 20 citations
- Can Graph Neural Networks Expose Training Data Properties? An Efficient Risk Assessment ApproachHanyang Yuan, Jiarong Xu, Renhong Huang, Mingli Song et al.NeurIPS 2024 · 3 citations
- Inference Attacks Against Graph Generative Diffusion ModelsXiuling Wang, Xin Huang, Guibo Luo, Jianliang XuUSENIX Security 2026
