USENIX Security2024Top-tier venue
Unveiling the Secrets without Data: Can Graph Neural Networks Be Exploited through Data-Free Model Extraction Attacks?
Yuanxin Zhuang, Chuan Shi, Mengmei Zhang, Jinghui Chen, Lingjuan Lyu, Pan Zhou, Lichao Sun
Abstract
Graph neural networks (GNNs) play a crucial role in various graph applications, such as social science, biology, and molecular chemistry. Despite their popularity, GNNs are still vulnerable to intellectual property threats. Previous studies have demonstrated the susceptibility of GNN models to model extraction attacks, where attackers steal the functionality of GNNs by sending queries and obtaining model responses. However, existing model extraction attacks often assume that the attacker has access to specific information about the victim model's training data, including node attributes, connections, and the shadow dataset. This assumption is impractical in realworld scenarios. To address this issue, we propose STEAL-GNN, the first data-free model extraction attack framework against GNNs. STEALGNN advances prior GNN extraction attacks in three key aspects: 1) It is completely data-free, as it does not require actual node features or graph structures to extract GNN models. 2) It constitutes a full-rank attack that can be applied to node classification and link prediction tasks, posing significant intellectual property threats across a wide range of graph applications. 3) It can handle the most challenging hard-label attack setting, where the attacker possesses no knowledge about the target GNN model and can only obtain predicted labels through querying the victim model. Our experimental results on four benchmark graph datasets demonstrate the effectiveness of STEALGNN in attacking representative GNN models. learned different aspects of the victim model's decision criteria. By enforcing these inconsistencies and analyzing which applications trigger them, the attacker can gain insights into the victim model's complex risk assessment process.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8ff98f92-072d-4058-97b4-cd9e57d6db3dCited by top-tier papers5
- Do Explanations Increase the Risk of Decision Logic Leakage? Explanation-Guided Stealing of Graph ModelsBin Ma, Yuyuan Feng, Minhua Lin, Enyan DaiKDD 2026 · 1 citation
- Defending against Model Extraction for GNNs with Model ReprogrammingYan Wen, Zhenyi Wang, Heng HuangKDD 2026
- Query-Efficient Domain Knowledge Stealing Against Large Language ModelsZhengao Li, Xiaopeng Yuan, Bolin Shen, Kien Le et al.AAAI 2026
- On Stealing Graph Neural Network ModelsMarcin Podhajski, Jan Dubinski, Franziska Boenisch, Adam Dziedzic et al.AAAI 2026
- SLAC: Access-Driven CPU-to-GPU Side-channel Attacks via System-Level Cache on Apple SiliconTianhong Xu, Saion Kumar Roy, Ruyi Ding, A. Adam Ding et al.CCS 2026
Builds on8
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Iterative Deep Graph Learning for Graph Neural Networks: Better and Robust Node EmbeddingsYu Chen, Lingfei Wu, Mohammed J. ZakiNeurIPS 2020 · 559 citations
- SLAPS: Self-Supervision Improves Structure Learning for Graph Neural NetworksBahare Fatemi, Layla El Asri, Seyed Mehran KazemiNeurIPS 2021 · 220 citations
- Model Stealing Attacks Against Inductive Graph Neural NetworksYun Shen, Xinlei He, Yufei Han, Yang ZhangS&P 2022 · 88 citations
- DisGUIDE: Disagreement-Guided Data-Free Model ExtractionJonathan Rosenthal, Eric Enouen, Hung Viet Pham, Lin TanAAAI 2023 · 31 citations
Related papers
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
- LinkThief: Combining Generalized Structure Knowledge with Node Similarity for Link Stealing Attack against GNNYuxing Zhang, Siyuan Meng, Chunchun Chen, Mengyao Peng et al.ACM MM 2024 · 1 citation
- Revisiting Black-box Ownership Verification for Graph Neural NetworksRuikai Zhou, Kang Yang, Xiuling Wang, Wendy Hui Wang et al.S&P 2024 · 5 citations
- GNNFingers: A Fingerprinting Framework for Verifying Ownerships of Graph Neural NetworksXiaoyu You, Youhe Jiang, Jianwei Xu, Mi Zhang et al.WWW 2024 · 9 citations
- Inference Attacks Against Graph Neural NetworksZhikun Zhang, Min Chen, Michael Backes, Yun Shen et al.USENIX Security 2022
