Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity Verification
Bang Wu, Xingliang Yuan, Shuo Wang, Qi Li, Minhui Xue, Shirui Pan
Abstract
The deployment of Graph Neural Networks (GNNs) within Machine Learning as a Service (MLaaS) has opened up new attack surfaces and an escalation in security concerns regarding model-centric attacks. These attacks can directly manipulate the GNN model parameters during serving, causing incorrect predictions and posing substantial threats to essential GNN applications. Traditional integrity verification methods falter in this context due to the limitations imposed by MLaaS and the distinct characteristics of GNN models.In this research, we introduce a groundbreaking approach to protect GNN models in MLaaS from model-centric attacks. Our approach includes a comprehensive verification schema for GNN’s integrity, taking into account both transductive and inductive GNNs, and accommodating varying pre-deployment knowledge of the models. We propose a query-based verification technique, fortified with innovative node fingerprint generation algorithms. To deal with advanced attackers who know our mechanisms in advance, we introduce randomized fingerprint nodes within our design. The experimental evaluation demonstrates that our method can detect five representative adversarial model-centric attacks, displaying 2 to 4 times greater efficiency compared to baselines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Unraveling Privacy Risks of Individual Fairness in Graph Neural NetworksHe Zhang, Xingliang Yuan, Shirui PanICDE 2024 · 9 citations
- ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural NetworksZhan Cheng, Bolin Shen, Tianming Sha, Yuan Gao et al.KDD 2025 · 2 citations
- Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Leman Go IndifferentLorenz Kummer, Samir Moustafa, Sebastian Schrittwieser, Wilfried N. Gansterer et al.KDD 2024 · 1 citation
- Revisiting Asymmetries in Black-box Link Stealing against Graph Neural NetworksPaul Agbaje, Habeeb OlufowobiICML 2026
- CEGA: A Cost-Effective Approach for Graph-Based Model Extraction and AcquisitionZebin Wang, Menghan Lin, Bolin Shen, Ken Anderson et al.ICML 2025
Builds on24
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Graph Neural Network-Based Anomaly Detection in Multivariate Time SeriesAilin Deng, Bryan HooiAAAI 2021 · 1,306 citations
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- Iterative Deep Graph Learning for Graph Neural Networks: Better and Robust Node EmbeddingsYu Chen, Lingfei Wu, Mohammed J. ZakiNeurIPS 2020 · 559 citations
Related papers
- Defending against Model Extraction for GNNs with Model ReprogrammingYan Wen, Zhenyi Wang, Heng HuangKDD 2026
- GNNFingers: A Fingerprinting Framework for Verifying Ownerships of Graph Neural NetworksXiaoyu You, Youhe Jiang, Jianwei Xu, Mi Zhang et al.WWW 2024 · 9 citations
- GrOVe: Ownership Verification of Graph Neural Networks using EmbeddingsAsim Waheed, Vasisht Duddu, N. AsokanS&P 2024 · 19 citations
- Revisiting Black-box Ownership Verification for Graph Neural NetworksRuikai Zhou, Kang Yang, Xiuling Wang, Wendy Hui Wang et al.S&P 2024 · 5 citations
- CryptGNN: Enabling Secure Inference for Graph Neural NetworksPritam Sen, Yao Ma, Cristian BorceaCCS 2025
