A Unified Framework of Graph Information Bottleneck for Robustness and Membership Privacy
Enyan Dai, Limeng Cui, Zhengyang Wang, Xianfeng Tang, Yinghan Wang, Monica Xiao Cheng, Bing Yin, Suhang Wang
Abstract
Graph Neural Networks (GNNs) have achieved great success in modeling graph-structured data. However, recent works show that GNNs are vulnerable to adversarial attacks which can fool the GNN model to make desired predictions of the attacker. In addition, training data of GNNs can be leaked under membership inference attacks. This largely hinders the adoption of GNNs in high-stake domains such as e-commerce, finance and bioinformatics. Though investigations have been made in conducting robust predictions and protecting membership privacy, they generally fail to simultaneously consider the robustness and membership privacy. Therefore, in this work, we study a novel problem of developing robust and membership privacy-preserving GNNs. Our analysis shows that Information Bottleneck (IB) can help filter out noisy information and regularize the predictions on labeled samples, which can benefit robustness and membership privacy. However, structural noises and lack of labels in node classification challenge the deployment of IB on graph-structured data. To mitigate these issues, we propose a novel graph information bottleneck framework that can alleviate structural noises with neighbor bottleneck. Pseudo labels are also incorporated in the optimization to minimize the gap between the predictions on the labeled set and unlabeled set for membership privacy. Extensive experiments on real-world datasets demonstrate that our method can give robust predictions and simultaneously preserve membership privacy. CCS CONCEPTS • Computing methodologies → Machine learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d08065c0-13c3-4cf7-82ff-79c8c0f25056Cited by top-tier papers7
- Certifiably Robust Graph Contrastive LearningMinhua Lin, Teng Xiao, Enyan Dai, Xiang Zhang et al.NeurIPS 2023 · 16 citations
- Federated Graph Condensation with Information Bottleneck PrinciplesBo Yan, Sihao He, Cheng Yang, Shang Liu et al.AAAI 2025 · 11 citations
- Prompt-based Unifying Inference Attack on Graph Neural NetworksYuecen Wei, Xingcheng Fu, Lingyun Liu, Qingyun Sun et al.AAAI 2025 · 6 citations
- UniZyme: A Unified Protein Cleavage Site Predictor Enhanced with Enzyme Active-Site KnowledgeChenao Li, Shuo Yan, Enyan DaiNeurIPS 2025 · 4 citations
- Stealing Training Graphs from Graph Neural NetworksMinhua Lin, Enyan Dai, Junjie Xu, Jinyuan Jia et al.KDD 2025 · 3 citations
Builds on20
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- GraphSAINT: Graph Sampling Based Inductive Learning MethodHanqing Zeng, Hongkuan Zhou, Ajitesh Srivastava, Rajgopal Kannan et al.ICLR 2020 · 1,155 citations
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang et al.NDSS 2019 · 1,141 citations
- GCC: Graph Contrastive Coding for Graph Neural Network Pre-TrainingJiezhong Qiu, Qibin Chen, Yuxiao Dong, Jing Zhang et al.KDD 2020 · 755 citations
Related papers
- GuardFGL: Similarity-driven Federated Graph Learning with Adversarial Robustness and Membership PrivacyLuying Zhong, Xuan Lai, Junjie Zhang, Zhiqin Huang et al.KDD 2025
- Graph Information BottleneckTailin Wu, Hongyu Ren, Pan Li, Jure LeskovecNeurIPS 2020 · 366 citations
- Inference Attacks Against Graph Neural NetworksZhikun Zhang, Min Chen, Michael Backes, Yun Shen et al.USENIX Security 2022
- Privacy Risks of Securing Machine Learning Models against Adversarial ExamplesLiwei Song, Reza Shokri, Prateek MittalCCS 2019 · 293 citations
- Combating Bilateral Edge Noise for Robust Link PredictionZhanke Zhou, Jiangchao Yao, Jiaxu Liu, Xiawei Guo et al.NeurIPS 2023 · 28 citations
