Devil in Disguise: Breaching Graph Neural Networks Privacy through Infiltration
Lingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu, Wenyuan Xu, Haiqin Weng
Abstract
Graph neural networks (GNNs) have been developed to mine useful information from graph data of various applications, e.g., healthcare, fraud detection, and social recommendation. However, GNNs open up new attack surfaces for privacy attacks on graph data. In this paper, we propose Infiltrator, a privacy attack that is able to pry node-level private information based on black-box access to GNNs. Different from existing works that require prior information of the victim node, we explore the possibility of conducting the attack without any information of the victim node. Our idea is to infiltrate the graph with attacker-created nodes to befriend the victim node. More specifically, we design infiltration schemes that enable the adversary to infer the label, neighboring links, and sensitive attributes of a victim node. We evaluate Infiltrator with extensive experiments on three representative GNN models and six real-world datasets. The results demonstrate that Infiltrator can achieve an attack performance of more than 98% in all three attacks, outperforming baseline approaches. We further evaluate the defense resistance of Infiltrator against the graph homophily defender and the differentially private model.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7b3e7959-582b-4a24-a2f0-41d73d4d5db0Cited by top-tier papers8
- GRASP: Differentially Private Graph Reconstruction Defense with Structured PerturbationZhiyu Guo, Yang Liu, Xiang Ao, Qing HeKDD 2025 · 3 citations
- On provable privacy vulnerabilities of graph representationsRuofan Wu, Guanhua Fang, Mingyang Zhang, Qiying Pan et al.NeurIPS 2024 · 3 citations
- GCON: Differentially Private Graph Convolutional Network via Objective PerturbationJianxin Wei, Yizheng Zhu, Xiaokui Xiao, Ergute Bao et al.ICDE 2025 · 2 citations
- Grimm: A Plug-and-Play Perturbation Rectifier for Graph Neural Networks Defending Against Poisoning AttacksAo Liu, Wenshan Li, Beibei Li, Wengang Ma et al.AAAI 2025 · 1 citation
- Devil's Hand: Data Poisoning Attacks to Locally Private Graph Learning ProtocolsLongzhu He, Chaozhuo Li, Peng Tang, Li Sun et al.KDD 2026
Related papers
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
- Inference Attacks Against Graph Neural NetworksZhikun Zhang, Min Chen, Michael Backes, Yun Shen et al.USENIX Security 2022
- VertexSerum: Poisoning Graph Neural Networks for Link InferenceRuyi Ding, Shijin Duan, Xiaolin Xu, Yunsi FeiICCV 2023 · 6 citations
- Black-box Adversarial Attack and Defense on Graph Neural NetworksHaoyang Li, Shimin Di, Zijian Li, Lei Chen et al.ICDE 2022 · 22 citations
- GRID: Protecting Training Graph from Link Stealing Attacks on GNN ModelsJiadong Lou, Xu Yuan, Rui Zhang, Xingliang Yuan et al.S&P 2025
