Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity Verification
Bang Wu, Xingliang Yuan, Shuo Wang, Qi Li, Minhui Xue, Shirui Pan
摘要
The deployment of Graph Neural Networks (GNNs) within Machine Learning as a Service (MLaaS) has opened up new attack surfaces and an escalation in security concerns regarding model-centric attacks. These attacks can directly manipulate the GNN model parameters during serving, causing incorrect predictions and posing substantial threats to essential GNN applications. Traditional integrity verification methods falter in this context due to the limitations imposed by MLaaS and the distinct characteristics of GNN models.In this research, we introduce a groundbreaking approach to protect GNN models in MLaaS from model-centric attacks. Our approach includes a comprehensive verification schema for GNN’s integrity, taking into account both transductive and inductive GNNs, and accommodating varying pre-deployment knowledge of the models. We propose a query-based verification technique, fortified with innovative node fingerprint generation algorithms. To deal with advanced attackers who know our mechanisms in advance, we introduce randomized fingerprint nodes within our design. The experimental evaluation demonstrates that our method can detect five representative adversarial model-centric attacks, displaying 2 to 4 times greater efficiency compared to baselines.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Unraveling Privacy Risks of Individual Fairness in Graph Neural NetworksHe Zhang, Xingliang Yuan, Shirui PanICDE 2024 · 被引用 9 次
- ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural NetworksZhan Cheng, Bolin Shen, Tianming Sha, Yuan Gao 等KDD 2025 · 被引用 2 次
- Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Leman Go IndifferentLorenz Kummer, Samir Moustafa, Sebastian Schrittwieser, Wilfried N. Gansterer 等KDD 2024 · 被引用 1 次
- Revisiting Asymmetries in Black-box Link Stealing against Graph Neural NetworksPaul Agbaje, Habeeb OlufowobiICML 2026
- CEGA: A Cost-Effective Approach for Graph-Based Model Extraction and AcquisitionZebin Wang, Menghan Lin, Bolin Shen, Ken Anderson 等ICML 2025
它引用的顶会 Paper24
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Graph Neural Network-Based Anomaly Detection in Multivariate Time SeriesAilin Deng, Bryan HooiAAAI 2021 · 被引用 1,306 次
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas 等USENIX Security 2018 · 被引用 832 次
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang 等KDD 2020 · 被引用 604 次
- Iterative Deep Graph Learning for Graph Neural Networks: Better and Robust Node EmbeddingsYu Chen, Lingfei Wu, Mohammed J. ZakiNeurIPS 2020 · 被引用 559 次
相关 Paper
- Defending against Model Extraction for GNNs with Model ReprogrammingYan Wen, Zhenyi Wang, Heng HuangKDD 2026
- GNNFingers: A Fingerprinting Framework for Verifying Ownerships of Graph Neural NetworksXiaoyu You, Youhe Jiang, Jianwei Xu, Mi Zhang 等WWW 2024 · 被引用 9 次
- GrOVe: Ownership Verification of Graph Neural Networks using EmbeddingsAsim Waheed, Vasisht Duddu, N. AsokanS&P 2024 · 被引用 19 次
- Revisiting Black-box Ownership Verification for Graph Neural NetworksRuikai Zhou, Kang Yang, Xiuling Wang, Wendy Hui Wang 等S&P 2024 · 被引用 5 次
- CryptGNN: Enabling Secure Inference for Graph Neural NetworksPritam Sen, Yao Ma, Cristian BorceaCCS 2025
