USENIX Security2022Top-tier venue
Inference Attacks Against Graph Neural Networks
Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, Yang Zhang
Abstract
Many real-world data comes in the form of graphs, such as social networks and protein structure. To fully utilize the information contained in graph data, a new family of machine learning (ML) models, namely graph neural networks (GNNs), has been introduced. Previous studies have shown that machine learning models are vulnerable to privacy attacks. However, most of the current efforts concentrate on ML models trained on data from the Euclidean space, like images and texts. On the other hand, privacy risks stemming from GNNs remain largely unstudied. In this paper, we fill the gap by performing the first comprehensive analysis of node-level membership inference attacks against GNNs. We systematically define the threat models and propose three node-level membership inference attacks based on an adversary's background knowledge. Our evaluation on three GNN structures and four benchmark datasets shows that GNNs are vulnerable to node-level membership inference even when the adversary has minimal background knowledge. Besides, we show that graph density and feature similarity have a major impact on the attack's success. We further investigate two defense mechanisms and the empirical results indicate that these defenses can reduce the attack performance but with moderate utility loss.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6398e00d-c78e-4c68-a756-3f534ac64072Cited by top-tier papers43
- Model Stealing Attacks Against Inductive Graph Neural NetworksYun Shen, Xinlei He, Yufei Han, Yang ZhangS&P 2022 · 88 citations
- Group Property Inference Attacks Against Graph Neural NetworksXiuling Wang, Wendy Hui WangCCS 2022 · 31 citations
- DPAR: Decoupled Graph Neural Networks with Node-Level Differential PrivacyQiuchen Zhang, Hong-Kyu Lee, Jing Ma, Jian Lou et al.WWW 2024 · 29 citations
- Preserving Node-level Privacy in Graph Neural NetworksZihang Xiang, Tianhao Wang, Di WangS&P 2024 · 28 citations
- On Strengthening and Defending Graph Reconstruction Attack with Markov Chain ApproximationZhanke Zhou, Chenyu Zhou, Xuan Li, Jiangchao Yao et al.ICML 2023 · 25 citations
Builds on17
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Machine Learning Models that Remember Too MuchCongzheng Song, Thomas Ristenpart, Vitaly ShmatikovCCS 2017 · 582 citations
- Spectral Clustering with Graph Neural Networks for Graph PoolingFilippo Maria Bianchi, Daniele Grattarola, Cesare AlippiICML 2020 · 528 citations
- A Fair Comparison of Graph Neural Networks for Graph ClassificationFederico Errica, Marco Podda, Davide Bacciu, Alessio MicheliICLR 2020 · 508 citations
Related papers
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
- Inference Attacks Against Graph Generative Diffusion ModelsXiuling Wang, Xin Huang, Guibo Luo, Jianliang XuUSENIX Security 2026
- Demystifying Uneven Vulnerability of Link Stealing Attacks against Graph Neural NetworksHe Zhang, Bang Wu, Shuo Wang, Xiangwen Yang et al.ICML 2023 · 20 citations
- Imprint of the Forgotten: Stealthy Membership Inference in Unlearned Graph Neural NetworksHe Zhang, Bang Wu, Xiaoning Liu, Karin Verspoor et al.AAAI 2026
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu et al.CCS 2023 · 9 citations
