Information Obfuscation of Graph Neural Networks
Peiyuan Liao, Han Zhao, Keyulu Xu, Tommi S. Jaakkola, Geoffrey J. Gordon, Stefanie Jegelka, Ruslan Salakhutdinov
Abstract
While the advent of Graph Neural Networks (GNNs) has greatly improved node and graph representation learning in many applications, the neighborhood aggregation scheme exposes additional vulnerabilities to adversaries seeking to extract node-level information about sensitive attributes. In this paper, we study the problem of protecting sensitive attributes by information obfuscation when learning with graph structured data. We propose a framework to locally filter out pre-determined sensitive attributes via adversarial training with the total variation and the Wasserstein distance. Our method creates a strong defense against inference attacks, while only suffering small loss in task performance. Theoretically, we analyze the effectiveness of our framework against a worst-case adversary, and characterize an inherent trade-off between maximizing predictive accuracy and minimizing information leakage. Experiments across multiple datasets from recommender systems, knowledge graphs and quantum chemistry demonstrate that the proposed approach provides a robust defense across various graph structures and tasks, while producing competitive GNN encoders for downstream tasks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 689fec00-ed7f-492f-bd27-fd5ebdce1e43Cited by top-tier papers7
- Fair Graph Representation Learning via Diverse Mixture-of-ExpertsZheyuan Liu, Chunhui Zhang, Yijun Tian, Erchi Zhang et al.WWW 2023 · 43 citations
- Pairwise Alignment Improves Graph Domain AdaptationShikun Liu, Deyu Zou, Han Zhao, Pan LiICML 2024 · 27 citations
- Task-Agnostic Privacy-Preserving Representation Learning for Federated Learning against Attribute Inference AttacksCaridad Arroyo Arevalo, Sayedeh Leila Noorbakhsh, Yun Dong, Yuan Hong et al.AAAI 2024 · 26 citations
- How does a Neural Network's Architecture Impact its Robustness to Noisy Labels?Jingling Li, Mozhi Zhang, Keyulu Xu, John Dickerson et al.NeurIPS 2021 · 25 citations
- Aligning Relational Learning with Lipschitz FairnessYaning Jia, Chunhui Zhang, Soroush VosoughiICLR 2024 · 11 citations
Builds on6
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Composition-based Multi-Relational Graph Convolutional NetworksShikhar Vashishth, Soumya Sanyal, Vikram Nitin, Partha P. TalukdarICLR 2020 · 1,105 citations
- Machine Learning with Membership Privacy using Adversarial RegularizationMilad Nasr, Reza Shokri, Amir HoumansadrCCS 2018 · 543 citations
- How Neural Networks Extrapolate: From Feedforward to Graph Neural NetworksKeyulu Xu, Mozhi Zhang, Jingling Li, Simon Shaolei Du et al.ICLR 2021 · 364 citations
- What Can Neural Networks Reason About?Keyulu Xu, Jingling Li, Mozhi Zhang, Simon S. Du et al.ICLR 2020 · 281 citations
Related papers
- Trade-offs and Guarantees of Adversarial Representation Learning for Information ObfuscationHan Zhao, Jianfeng Chi, Yuan Tian, Geoffrey J. GordonNeurIPS 2020 · 29 citations
- The Devil Within, The Cure Without: Securing Locally Private Graph Learning under PoisoningLongzhu He, Peng Tang, Li Sun, Sen SuWWW 2026
- Privacy-Preserving Representation Learning on Graphs: A Mutual Information PerspectiveBinghui Wang, Jiayi Guo, Ang Li, Yiran Chen et al.KDD 2021 · 27 citations
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu et al.CCS 2023 · 9 citations
- Locally Private Graph Neural NetworksSina Sajadmanesh, Daniel Gatica-PerezCCS 2021 · 124 citations
