LINKTELLER: Recovering Private Edges from Graph Neural Networks via Influence Analysis
Fan Wu, Yunhui Long, Ce Zhang, Bo Li
Abstract
Graph structured data have enabled several successful applications such as recommendation systems and traffic prediction, given the rich node features and edges information. However, these high-dimensional features and high-order adjacency information are usually heterogeneous and held by different data holders in practice. Given such vertical data partition e.g., one data holder will only own either the node features or edge information), different data holders have to develop efficient joint training protocols rather than directly transferring data to each other due to privacy concerns. In this paper, we focus on the edge privacy, and consider a training scenario where the data holder Bob with node features will first send training node features to Alice who owns the adjacency information. Alice will then train a graph neural network (GNN) with the joint information and provide an inference API to Bob. During inference time, Bob is able to provide test node features and query the API to obtain the predictions for test nodes. Under this setting, we first propose a privacy attack LINKTELLER via influence analysis to infer the private edge information held by Alice via designing adversarial queries for Bob. We then empirically show that LINKTELLER is able to recover a significant amount of private edges in different settings, both including inductive (8 datasets) and transductive (3 datasets), under different graph densities, significantly outperforming existing baselines. To further evaluate the privacy leakage for edges, we adapt an existing algorithm for differentially private graph convolutional network (DP GCN) training as well as propose a new DP GCN mechanism LAPGRAPH based on Laplacian mechanism to evaluate LINKTELLER. We show that these DP GCN mechanisms are not always resilient against LINKTELLER empirically under mild privacy guarantees . Our studies will shed light on future research towards designing more resilient privacy-preserving GCN models; in the meantime, provide an in-depth understanding about the tradeoff between GCN model utility and robustness against potential privacy attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers33
- Differentially Private Decoupled Graph Convolutions for Multigranular Topology ProtectionEli Chien, Wei-Ning Chen, Chao Pan, Pan Li et al.NeurIPS 2023 · 33 citations
- Group Property Inference Attacks Against Graph Neural NetworksXiuling Wang, Wendy Hui WangCCS 2022 · 31 citations
- Preserving Node-level Privacy in Graph Neural NetworksZihang Xiang, Tianhao Wang, Di WangS&P 2024 · 28 citations
- Quantifying and Defending against Privacy Threats on Federated Knowledge Graph EmbeddingYuke Hu, Wei Liang, Ruofan Wu, Kai Xiao et al.WWW 2023 · 21 citations
- Demystifying Uneven Vulnerability of Link Stealing Attacks against Graph Neural NetworksHe Zhang, Bang Wu, Shuo Wang, Xiangwen Yang et al.ICML 2023 · 20 citations
Builds on5
- DropEdge: Towards Deep Graph Convolutional Networks on Node ClassificationYu Rong, Wenbing Huang, Tingyang Xu, Junzhou HuangICLR 2020 · 1,599 citations
- GraphSAINT: Graph Sampling Based Inductive Learning MethodHanqing Zeng, Hongkuan Zhou, Ajitesh Srivastava, Rajgopal Kannan et al.ICLR 2020 · 1,155 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Generating Synthetic Decentralized Social Graphs with Local Differential PrivacyZhan Qin, Ting Yu, Yin Yang, Issa Khalil et al.CCS 2017 · 266 citations
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
Related papers
- LPGNet: Link Private Graph Networks for Node ClassificationAashish Kolluri, Teodora Baluta, Bryan Hooi, Prateek SaxenaCCS 2022 · 24 citations
- GCON: Differentially Private Graph Convolutional Network via Objective PerturbationJianxin Wei, Yizheng Zhu, Xiaokui Xiao, Ergute Bao et al.ICDE 2025 · 2 citations
- Can Graph Neural Networks Expose Training Data Properties? An Efficient Risk Assessment ApproachHanyang Yuan, Jiarong Xu, Renhong Huang, Mingli Song et al.NeurIPS 2024 · 3 citations
- Safeguarding Graph Neural Networks against Topology Inference AttacksJie Fu, Yuan Hong, Zhili Chen, Wendy Hui WangCCS 2025
- On Strengthening and Defending Graph Reconstruction Attack with Markov Chain ApproximationZhanke Zhou, Chenyu Zhou, Xuan Li, Jiangchao Yao et al.ICML 2023 · 25 citations
