Imprint of the Forgotten: Stealthy Membership Inference in Unlearned Graph Neural Networks
He Zhang, Bang Wu, Xiaoning Liu, Karin Verspoor, Xun Yi
Abstract
Graphs effectively model interactions in real-world applications such as social and trade networks, where Graph Neural Networks (GNNs) excel at tasks such as link prediction to enhance user experiences. Despite these benefits, users raise privacy concerns as user data can be exploited to improve GNN performance without consent. Accordingly, various graph unlearning methods have been developed. Prior work shows that comparing models before and after unlearning enables attackers to launch former membership inference attacks (FMIA) on unlearned data. However, the imprint of unlearned data left in the unlearned model itself remains underexplored, and existing membership inference methods mainly exploit vulnerability of training data, making them ineffective for identifying unlearned data. To this end, we conducted a theoretical analysis and proposed an attack framework targeting unlearned GNNs by learning the distribution patterns of unlearned data to distinguish them from normal test data. Extensive experiments on four real-world datasets and GNN architectures confirm our framework's effectiveness and reveal significant vulnerabilities in current graph unlearning methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 46e145cf-c4dc-4a43-97ea-a652fececce2Builds on28
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- DeepGCNs: Can GCNs Go As Deep As CNNs?Guohao Li, Matthias Müller, Ali K. Thabet, Bernard GhanemICCV 2019 · 1,586 citations
- When Machine Unlearning Jeopardizes PrivacyMin Chen, Zhikun Zhang, Tianhao Wang, Michael Backes et al.CCS 2021 · 146 citations
- On Dyadic Fairness: Exploring and Mitigating Bias in Graph ConnectionsPeizhao Li, Yifei Wang, Han Zhao, Pengyu Hong et al.ICLR 2021 · 142 citations
- GIF: A General Graph Unlearning Strategy via Influence FunctionJiancan Wu, Yi Yang, Yuchun Qian, Yongduo Sui et al.WWW 2023 · 97 citations
Related papers
- Inference Attacks Against Graph Neural NetworksZhikun Zhang, Min Chen, Michael Backes, Yun Shen et al.USENIX Security 2022
- Demystifying Uneven Vulnerability of Link Stealing Attacks against Graph Neural NetworksHe Zhang, Bang Wu, Shuo Wang, Xiangwen Yang et al.ICML 2023 · 20 citations
- Identifying Unlearned Data in LLMs via Membership Inference AttacksAdvit Deepak, Megan Mou, Jing Huang, Diyi YangEMNLP 2025
- Privacy Auditing of Multi-Domain Graph Pre-Trained Model Under Membership Inference AttacksJiayi Luo, Qingyun Sun, Yuecen Wei, Haonan Yuan et al.AAAI 2026 · 2 citations
- GraphGuard: Detecting and Counteracting Training Data Misuse in Graph Neural NetworksBang Wu, He Zhang, Xiangwen Yang, Shuo Wang et al.NDSS 2024
