Pith. sign in

REVIEW 4 major objections 6 minor 100 references

OpenGU: A Comprehensive Benchmark for Graph Unlearning

T0 review · 4 major / 6 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read OpenGU is presented as the first graph-unlearning benchmark to unify 16 algorithms and 37 datasets, enabling eight conclusions about which methods generalize, forget, scale, and survive noise to be drawn fairly.

desk verdict A badly needed graph-unlearning benchmark that undercuts its own claims by omitting the retrain-from-scratch baseline it defines as the reference point. read the letter →

arxiv 2501.02728 v1 pith:XYFIG44A submitted 2025-01-06 cs.LG cs.AI

classification cs.LGcs.AI
keywords graphunlearningbenchmarkneuralnetworksmachineprivacynodeclassificationlinkprediction
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Graph unlearning — removing specified nodes, edges, or features from an already-trained graph neural network without retraining from scratch — is needed for privacy compliance, but the field has evaluated its methods so inconsistently that results across papers cannot be compared. This paper works to fix that by building OpenGU, a benchmark that integrates 16 existing graph-unlearning algorithms and 37 datasets behind one unified interface, so any method can in principle be tested on any combination of unlearning request (node, edge, or feature) and downstream task (node classification, link prediction, or graph classification). Running this common testbed, the authors draw eight conclusions about the field as a whole: which algorithm families generalize across tasks, which are specialized, which genuinely forget, which scale, and which survive noise and sparsity. A fair reader should care because OpenGU supplies the first standardized yardstick for graph unlearning, and its conclusions are the first cross-method evidence about what current unlearning methods can and cannot do.

What carries the argument

The load-bearing object is the benchmark framework itself, whose operative mechanism is the 3x3 cross-over design: three unlearning request types (node-level $\Delta V$, edge-level $\Delta E$, feature-level $\Delta X$) are crossed with three downstream tasks (node classification, link prediction, graph classification) through a unified API, so every algorithm can be run in every cell of the grid. Unification is enforced by fixing one representative GNN backbone per task — SGC for node-node, GraphSAGE for edge-edge, GCN for graph-feature — with standardized 80/20 splits and 10% deletion rates. The second mechanism is two-sided effectiveness checking: reasoning quality on retained data via F1/AUC/accuracy, and forgetting quality on deleted data via membership inference attack (AUC near 0.5 means the model behaves as if the data was never seen) and poisoning attack (AUC recovery after removing poisoned heterophilic edges). Together these mechanisms convert 'does this method forget?' into a measurable, comparable quantity across all 16 methods.

What would settle it

Re-run the node-node comparison of Table 4 with a different backbone, such as GCN or GAT in place of SGC, keeping splits and deletion rates unchanged, and compare the method ranking. If the same learning-based methods still top the table, the benchmark's conclusions are backbone-independent; if the ranking shifts substantially — for example, an influence-function method catching or passing SGU and D2DGN — then the reported ordering, and conclusions C1 and C2 drawn from it, are artifacts of the single-backbone assignment rather than properties of the methods.

Watch

Extended reading notes

Core claim

The paper claims that OpenGU is the first comprehensive benchmark for graph unlearning, and that a standardized platform is what makes fair cross-method comparison possible. It integrates 16 state-of-the-art unlearning algorithms across five families — partition-based, influence-function-based, learning-based, projection-based, and structure-based — with 37 datasets spanning citation, co-author, social, image, protein, movie, and molecular domains, standardizing splits, inference settings, and metrics. The defining design choice is a 3x3 cross-over: three unlearning requests (node-level $\Delta V$, edge-level $\Delta E$, feature-level $\Delta X$) crossed with three downstream tasks (node classification, link prediction, graph classification), with the reported experiments covering three representative cells under unified APIs and one representative backbone per cell (SGC, GraphSAGE, and GCN respectively). Effectiveness is measured doubly — reasoning quality on retained data via F1-score, AUC-ROC, and accuracy, and genuine forgetting on deleted data via membership inference attack (target AUC near 0.5) and poisoning attack — while efficiency is assessed through theoretical and empirical time and memory and robustness through deletion intensity, noise, and sparsity. From this battery the authors derive eight conclusions, including that partition-based and influence-function methods transfer broadly while learning-based methods win when specialized, that forgetting quality depends more on strategy design than method category, that the forgetting–reasoning trade-off remains unresolved, and that current methods fail to scale to million-node graphs and degrade sharply under label noise.

Load-bearing premise

The benchmark assigns every method to one fixed backbone per task — SGC for node classification, GraphSAGE for link prediction, GCN for graph classification — and assumes this assignment treats all 16 methods fairly, even those originally designed for different architectures.

Editorial extensions

If this is right

  • Learning-based methods such as SGU and D2DGN achieve the strongest reasoning performance on node classification with node unlearning, making them the reference point that new node-level methods must beat.
  • Influence-function methods GIF and IDEA retain near-top accuracy when transplanted to link prediction and graph classification, marking that family as the most task-general among current approaches.
  • Under the benchmark's standardized edge-unlearning protocol, most learning-based methods fall behind on link prediction, with GNNDelete as the main exception.
  • On the million-node ogbn-products dataset only 6 of 16 methods finish without out-of-memory or timeout, so scalability, not accuracy, is the binding constraint for large graphs.
  • Membership-inference checks place most methods near the random baseline (AUC ≈ 0.5), while CGU under-forgets and Projector exceeds 0.9, so genuine forgetting is achieved by most but not all methods.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Because every method is pinned to one backbone per task, the published rankings are rankings under a specific architectural assignment; conclusions C1 and C2 would need re-testing with each method's native backbone before being treated as intrinsic properties of the methods.
  • The 3x3 grid stops at single-type requests, yet real privacy demands often combine node and feature deletion or delete whole subgraphs; extending the framework to mixed requests is a natural next test consistent with the authors' own future-work list.
  • The robustness results isolate label noise as the dominant failure mode for all methods, which suggests a standardized, task-agnostic forgetting metric — measuring 'forgot enough' the same way everywhere — would be the benchmark's most valuable addition.
  • Projector's behavior under membership inference (AUC above 0.9 despite exact parameter-space removal) hints that mathematically exact deletion can be counterproductive against inference attacks, a caution that generalizes beyond graph unlearning.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 6 minor

Summary. The paper presents OpenGU, described as the first comprehensive benchmark for graph unlearning (GU). It integrates 16 existing GU algorithms and 37 datasets, supports three unlearning request types (node, edge, feature) and three downstream tasks (node classification, link prediction, graph classification), and claims a 3x3 cross-product evaluation. The main experiments report utility metrics (F1, AUC-ROC, accuracy), membership inference and poisoning attacks, efficiency analyses, and robustness studies, from which the authors draw eight conclusions (C1-C8) about the effectiveness, efficiency, and robustness of current GU methods. The paper also provides a taxonomy of GU methods and releases code at the stated repository.

Significance. If the evaluation were properly anchored, OpenGU would be a valuable community asset: the artifact is open-sourced, the benchmark standardizes dataset splits, reports mean and standard deviation over 10 runs, and spans a far larger combination of tasks and unlearning requests than prior work. The taxonomy and the 3x3 cross-over design are useful contributions. However, the central claims of 'fair comparison' and 'effective unlearning' are not yet supported: the benchmark lacks any retrain-from-scratch baseline, and the main conclusions rest on single-backbone-per-task experiments. These are fixable within the scope of a revision.

major comments (4)
  1. [2.3, Tables 4-6, Figures 2-4] Section 2.3 defines the goal of GU as minimizing the discrepancy between the unlearned model M' and the retrained model M_hat, yet no retrained-from-scratch baseline is reported anywhere. The effectiveness conclusions C1-C4 compare GU methods only against each other, never against the exact-unlearning reference specified by the paper itself. Without a 'Retrain' row, an MIA value near 0.5 cannot be interpreted as successful selective forgetting rather than model collapse, and the utility numbers alone cannot separate selective unlearning from utility collapse. Adding retrained baselines to Tables 4-6 and to the MIA/poisoning figures is required to support the benchmark's core claim.
  2. [4.1] The main experiments assign a single GNN backbone per task: SGC for node-node, GraphSAGE for edge-edge, and GCN for graph-feature. Despite the abstract and Table 1 advertising 13 GNN backbones, the eight conclusions are drawn from this single-backbone design. Because each GU method was originally developed and tuned for a particular architecture (commonly GCN or GAT), the relative performance measured here may be an artifact of the backbone choice, so the generalizability claims in C1 and C2 are not supported. The authors should either include at least one additional backbone per task in the main comparisons or explicitly qualify all conclusions as backbone-specific.
  3. [4.2] The forgetting evaluation is extremely narrow: MIA results are reported only for Citeseer (Figure 2) and poisoning results only for Cora (Figure 3). Conclusion C3, which asserts that privacy protection depends more on strategy design than on relational categories, is a general claim but rests on just two datasets. Moreover, unlike Tables 4-6, Figures 2-3 do not report standard deviations or multiple runs, so the observed differences cannot be assessed for stability. Additional datasets and error bars are needed before C3 can be drawn.
  4. [4.5, Table 7] The efficiency conclusions C5-C6 report unlearning time and memory but never compare with the cost of retraining from scratch. Since the practical motivation for GU is to avoid retraining, the measured time and memory savings have no reference point: a method could be faster than other GU methods yet still slower than a simple retrain. The authors should include training time and memory for the retrained model (M_hat) in the efficiency experiments, or explicitly state that the efficiency comparison is only among GU methods and does not validate the retraining-avoidance motivation.
minor comments (6)
  1. [2.4] The reference for SGU is missing: the taxonomy lists 'SGU []' with an empty citation; please provide the proper reference.
  2. [Table 6] The dataset name 'DHRF' in Table 6 is a typo for 'DHFR', and the same error appears in the appendix dataset description.
  3. [Figures 2-8] Several figures (e.g., Figures 2-8) contain axis labels and legends rendered as corrupted hexadecimal strings such as '/uni00000013/uni00000011/...', making them unreadable; the figures should be regenerated with clear text labels.
  4. [4.2] In the poisoning attack paragraph, the sentence 'For convenience, UtU is presented in IF-based' conflicts with the taxonomy in Table 1 and Section 2.4, where UtU is a structure-based method; this needs to be rewritten for clarity.
  5. [1] The abstract and introduction claim '13 GNN backbones' are integrated, but the main experiments use only one backbone per task; please clarify where the 13 backbones are actually used (e.g., only in robustness or intensity experiments).
  6. [3.1] The phrase 'a detailed overview is showed' should be corrected to 'is shown'; there are several other grammar and typo issues that a careful proofread would catch.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the benchmark conclusions are empirical observations from the implemented framework, not derivations from their own inputs.

full rationale

OpenGU is an empirical benchmark paper rather than a mathematical derivation, and its central claims (first GU benchmark, 16 integrated algorithms, 37 datasets, 3x3 task/request combinations, and eight conclusions) are supported by the released artifact, the reproduced methods, and the reported tables and figures. The inclusion of the authors' own MEGU method creates a mild conflict of interest, but it is not load-bearing: MEGU does not drive any of conclusions C1-C8, and those conclusions are supported by the experimental comparisons and independent citations. The choice of a single backbone per task (SGC for node-node, GraphSAGE for edge-edge, GCN for graph-feature) and the absence of a retrain-from-scratch row are evaluation-design limitations that may affect fairness or completeness, but they are not circular steps: no result is defined in terms of a fitted parameter, no equation reduces to its input, and no 'prediction' is statistically forced by a self-citation chain. The closest concern is that the paper defines the GU goal via the retrained model M_hat in Section 2.3 but never reports a retrain baseline, which weakens some effectiveness and efficiency conclusions; however, this is an omitted reference point, not a circular reduction. The paper's conclusions are externally checkable against its own benchmark code and data, so the honest finding is no significant circularity.

Assumptions & free parameters 4 free parameters · 4 assumptions · 0 invented entities

The benchmark relies on several hand-chosen experimental settings (unlearning ratio, split ratio, backbone assignments, attack settings) rather than fitted model parameters. The core axioms are that the reimplemented algorithms represent the originals, that the proxy attacks measure forgetting, that the fixed backbone assignment is fair, and that the datasets are representative. No new physical or conceptual entities are introduced.

free parameters (4)
  • unlearning ratio = 10% of nodes/edges; 50% of graphs with 10% features zeroed
    The amount of data removed is fixed across all main experiments; relative method rankings could change with different unlearning intensities.
  • train/test split = 80%/20%
    A fixed split ratio is chosen to unify prior inconsistent settings; results may be sensitive to this choice.
  • backbone per task = SGC for node classification, GraphSAGE for link prediction, GCN for graph classification
    Each task uses a single backbone; methods designed for other backbones may be disadvantaged, influencing comparative conclusions.
  • MIA and poisoning attack settings = MIA AUC-ROC; 10% heterophilic poisoned edges
    Forgetting effectiveness is measured using these specific attack configurations; conclusions about forgetting depend on these choices.
assumptions (4)
  • domain assumption The reproduced GU algorithm implementations faithfully match their original papers.
    The benchmark's fair comparison relies on correct reimplementation of 16 methods; any deviation could bias rankings.
  • domain assumption Membership Inference Attack and Poisoning Attack are valid proxies for unlearning effectiveness.
    The forgetting conclusions assume MIA AUC near 0.5 and poisoning recovery actually measure information removal; no retrained reference is used to validate these proxies.
  • ad hoc to paper The single-backbone-per-task design is a fair basis for cross-method comparison.
    The choice of SGC, GraphSAGE, and GCN for the three tasks is arbitrary; methods designed for other backbones may be systematically disadvantaged.
  • domain assumption The 37 selected datasets are representative of graph unlearning scenarios.
    The multi-domain datasets are assumed to cover the relevant range of graph structures and tasks; selection could bias the conclusions.

how reviews work

0 comments
Cite this review

Pith. "Pith review of OpenGU: A Comprehensive Benchmark for Graph Unlearning." pith.science (2026). https://pith.science/paper/XYFIG44A

@misc{pith2026250102728,
  author       = {Pith},
  title        = {Pith review of: OpenGU: A Comprehensive Benchmark for Graph Unlearning},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/XYFIG44A}},
  note         = {Machine review of arXiv:2501.02728}
}
abstract

Graph Machine Learning is essential for understanding and analyzing relational data. However, privacy-sensitive applications demand the ability to efficiently remove sensitive information from trained graph neural networks (GNNs), avoiding the unnecessary time and space overhead caused by retraining models from scratch. To address this issue, Graph Unlearning (GU) has emerged as a critical solution, with the potential to support dynamic graph updates in data management systems and enable scalable unlearning in distributed data systems while ensuring privacy compliance. Unlike machine unlearning in computer vision or other fields, GU faces unique difficulties due to the non-Euclidean nature of graph data and the recursive message-passing mechanism of GNNs. Additionally, the diversity of downstream tasks and the complexity of unlearning requests further amplify these challenges. Despite the proliferation of diverse GU strategies, the absence of a benchmark providing fair comparisons for GU, and the limited flexibility in combining downstream tasks and unlearning requests, have yielded inconsistencies in evaluations, hindering the development of this domain. To fill this gap, we present OpenGU, the first GU benchmark, where 16 SOTA GU algorithms and 37 multi-domain datasets are integrated, enabling various downstream tasks with 13 GNN backbones when responding to flexible unlearning requests. Based on this unified benchmark framework, we are able to provide a comprehensive and fair evaluation for GU. Through extensive experimentation, we have drawn $8$ crucial conclusions about existing GU methods, while also gaining valuable insights into their limitations, shedding light on potential avenues for future research.

Figures

Figures reproduced from arXiv: 2501.02728 by the authors.

Figure 1
Figure 1. An overview of the OpenGU framework, illustrating the key components and methodologies involved in GU. [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 3
Figure 3. AUC-ROC comparison under PA for edge-edge task [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗
Figure 4
Figure 4. Trade-off between forgetting and reasoning on Cora, Citeseer, PubMed and in Average performance. [PITH_FULL_IMAGE:figures/full_fig_p009_4.png] view at source ↗
Figures from the paper (4 more)
Figure 5
Figure 5. Figure 5: Unlearning Time Performance on Cora, PubMed, ogbn-arxiv and ogbn-products. [PITH_FULL_IMAGE:figures/full_fig_p011_5.png]
Figure 6
Figure 6. Figure 6: Memory Usage Performance on Various Datasets. [PITH_FULL_IMAGE:figures/full_fig_p011_6.png]
Figure 7
Figure 7. Figure 7: Performance under Different Unlearning Intensities with GraphSAINT, Cluster-gcn, GAT, and GCN. [PITH_FULL_IMAGE:figures/full_fig_p012_7.png]
Figure 8
Figure 8. Figure 8: Performance under Different Noise and Sparsity Ratios at Label and Feature Levels. [PITH_FULL_IMAGE:figures/full_fig_p012_8.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

100 extracted references · 50 canonical work pages

  1. [1]

    OpenGU Technical Report

    2025. OpenGU Technical Report. In https://github.com/bwfan-bit/OpenGU

  2. [2]

    Charu C Aggarwal and Haixun Wang. 2010. Graph data management and mining: A survey of algorithms and applications.Managing and mining graph data (2010), 13–68

  3. [3]

    Renzo Angles and Claudio Gutierrez. 2018. An introduction to graph data man- agement. Graph Data Management: Fundamental Issues and Recent Developments (2018), 1–32

  4. [4]

    Pablo Barceló Baeza. 2013. Querying graph databases. In Proceedings of the 32nd ACM SIGMOD-SIGACT-SIGAI symposium on Principles of database systems . 175–188

  5. [5]

    Alaa Bessadok, Mohamed Ali Mahjoub, and Islem Rekik. 2022. Graph neural networks in network neuroscience. IEEE Transactions on Pattern Analysis and Machine Intelligence 45, 5 (2022), 5833–5848

  6. [6]

    Maciej Besta, Patrick Iff, Florian Scheidl, Kazuki Osawa, Nikoli Dryden, Michal Podstawski, Tiancheng Chen, and Torsten Hoefler. 2022. Neural graph databases. In Learning on Graphs Conference . PMLR, 31–1

  7. [7]

    Choquette-Choo, Hen- grui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot

    Lucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hen- grui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. 2021. Machine Unlearning. In 2021 IEEE Symposium on Security and Privacy (SP) . 141– 159

  8. [8]

    Shaked Brody, Uri Alon, and Eran Yahav. 2022. How attentive are graph attention networks? International Conference on Learning Representations, ICLR (2022)

Show all 100 references
  1. [9]

    Xuheng Cai, Chao Huang, Lianghao Xia, and Xubin Ren. 2023. LightGCL: Simple Yet Effective Graph Contrastive Learning for Recommendation. In International Conference on Learning Representations, ICLR

  2. [10]

    Yinzhi Cao and Junfeng Yang. 2015. Towards Making Systems Forget with Machine Unlearning. In 2015 IEEE Symposium on Security and Privacy . 463–480

  3. [11]

    Chuan Chen, Ziyue Xu, Weibo Hu, Zibin Zheng, and Jie Zhang. 2024. FedGL: Federated graph learning framework with global self-supervision. Information Sciences 657 (2024), 119976

  4. [12]

    Jiaao Chen and Diyi Yang. 2023. Unlearn what you want to forget: Efficient unlearning for llms. arXiv preprint arXiv:2310.20150 (2023)

  5. [13]

    Ming Chen, Zhewei Wei, Zengfeng Huang, Bolin Ding, and Yaliang Li. 2020. Simple and deep graph convolutional networks. In International Conference on Machine Learning, ICML

  6. [14]

    Min Chen, Zhikun Zhang, Tianhao Wang, Michael Backes, Mathias Humbert, and Yang Zhang. 2021. When machine unlearning jeopardizes privacy. InProceedings of the 2021 ACM SIGSAC conference on computer and communications security . 896–911

  7. [15]

    Min Chen, Zhikun Zhang, Tianhao Wang, Michael Backes, Mathias Humbert, and Yang Zhang. 2022. Graph unlearning. In Proceedings of ACM SIGSAC Conference on Computer and Communications Security, CCS

  8. [16]

    Jiali Cheng, George Dasoulas, Huan He, Chirag Agarwal, and Marinka Zitnik

  9. [17]

    Wei-Lin Chiang, Xuanqing Liu, Si Si, Yang Li, Samy Bengio, and Cho-Jui Hsieh

  10. [18]

    Eli Chien, Chao Pan, and Olgica Milenkovic. 2022. Certified Graph Unlearning. In NeurIPS 2022 Workshop: New Frontiers in Graph Learning

  11. [19]

    Dasol Choi and Dongbin Na. 2024. Distribution-Level Feature Distancing for Machine Unlearning: Towards a Better Trade-off Between Model Utility and Forgetting. arXiv:2409.14747 [cs.CV]

  12. [20]

    Somnath Basu Roy Chowdhury, Krzysztof Choromanski, Arijit Sehanobish, Avinava Dubey, and Snigdha Chaturvedi. 2024. Towards Scalable Exact Machine Unlearning Using Parameter-Efficient Fine-Tuning. arXiv:2406.16257 [cs.LG]

  13. [21]

    Weilin Cong and Mehrdad Mahdavi. 2023. Efficiently Forgetting What You Have Learned in Graph Representation Learning via Projection. In International Conference on Artificial Intelligence and Statistics, AISTATS

  14. [22]

    Milan Cvitkovic. 2020. Supervised learning on relational databases with graph neural networks. arXiv preprint arXiv:2002.02046 (2020)

  15. [23]

    Lopez de Compadre, Gargi Debnath, Alan J

    Asim Kumar Debnath, Rosa L. Lopez de Compadre, Gargi Debnath, Alan J. Shus- terman, and Corwin Hansch. 1991. Structure-activity relationship of mutagenic aromatic and heteroaromatic nitro compounds. Correlation with molecular or- bital energies and hydrophobicity. Journal of M...

  16. [24]

    Bresson, and P

    Michal Defferrard, X. Bresson, and P. Vandergheynst. 2016. Convolutional Neural Networks on Graphs with Fast Localized Spectral Filtering. Advances in Neural Information Processing Systems, NeurIPS (2016)

  17. [25]

    Dobson and Andrew J

    Paul D. Dobson and Andrew J. Doig. 2003. Distinguishing enzyme structures from non-enzymes without alignments. Journal of molecular biology 330 4 (2003), 771–83

  18. [26]

    Yushun Dong, Binchi Zhang, Zhenyu Lei, Na Zou, and Jundong Li. 2024. IDEA: A Flexible Framework of Certified Unlearning for Graph Neural Networks. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. Association for Computing Machinery, 621–630

  19. [27]

    Alex Fout, Jonathon Byrd, Basir Shariat, and Asa Ben-Hur. 2017. Protein Inter- face Prediction using Graph Convolutional Networks. In Advances in Neural Information Processing Systems, Vol. 30. Curran Associates, Inc

  20. [28]

    Fabrizio Frasca, Emanuele Rossi, Davide Eynard, Ben Chamberlain, Michael Bronstein, and Federico Monti. 2020. Sign: Scalable inception graph neural networks. arXiv preprint arXiv:2004.11198 (2020)

  21. [29]

    Tao Guo, Song Guo, Jiewei Zhang, Wenchao Xu, and Junxiao Wang. 2022. Efficient attribute unlearning: Towards selective removal of input attributes from feature representations. arXiv preprint arXiv:2202.13295 (2022)

  22. [30]

    Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in Neural Information Processing Systems, NeurIPS (2017)

  23. [31]

    Xiangnan He, Kuan Deng, Xiang Wang, Yan Li, YongDong Zhang, and Meng Wang. 2020. LightGCN: Simplifying and Powering Graph Convolution Network for Recommendation. In Proceedings of the 43rd International ACM SIGIR Con- ference on Research and Development in Information Retrieva...

  24. [32]

    King, Stefan Kramer, and Ashwin Srinivasan

    Christoph Helma, Ross D. King, Stefan Kramer, and Ashwin Srinivasan. 2001. The Predictive Toxicology Challenge 2000-2001. Bioinform. 17 (2001), 107–108

  25. [33]

    Helma, R

    C. Helma, R. D. King, S. Kramer, and A. Srinivasan. 2001. The Predictive Toxicol- ogy Challenge 2000–2001. Bioinformatics 17, 1 (01 2001), 107–108

  26. [34]

    Weihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong, Hongyu Ren, Bowen Liu, Michele Catasta, and Jure Leskovec. 2020. Open graph benchmark: Datasets for machine learning on graphs. Advances in Neural Information Processing Systems, NeurIPS (2020)

  27. [35]

    Wei Jin. 2021. Graph Mining with Graph Neural Networks. In Proceedings of the 14th ACM International Conference on Web Search and Data Mining . Association for Computing Machinery, 1119–1120

  28. [36]

    Thomas N Kipf and Max Welling. 2017. Semi-supervised classification with graph convolutional networks. In International Conference on Learning Representations, ICLR

  29. [37]

    Klicpera, A

    J. Klicpera, A. Bojchevski, and S Günnemann. 2019. Predict then Propagate: Graph Neural Networks meet Personalized PageRank. In International Conference on Learning Representations, ICLR

  30. [38]

    Chanhee Kwak, Junyeong Lee, Kyuhong Park, and Heeseok Lee. 2017. Let machines unlearn–machine unlearning and the right to be forgotten. (2017)

  31. [39]

    Jure Leskovec, Jon Kleinberg, and Christos Faloutsos. 2005. Graphs over time: densification laws, shrinking diameters and possible explanations. Association for Computing Machinery, 177–187

  32. [40]

    Quentin Lhoest, Albert Villanova del Moral, Yacine Jernite, Abhishek Thakur, Patrick von Platen, Suraj Patil, Julien Chaumond, Mariama Drame, Julien Plu, Lewis Tunstall, et al. 2021. Datasets: A community library for natural language processing. arXiv preprint arXiv:2109.02846 (2021)

  33. [41]

    Wenqin Li, Xinrong Zheng, Ruihong Huang, Mingwei Lin, Jun Shen, and Jiayin Lin. 2024. Enhancing Privacy Protection for Online Learning Resource Recom- mendation with Machine Unlearning. In 2024 27th International Conference on Computer Supported Cooperative Work in Design (CSC...

  34. [42]

    Xuefeng Li, Yang Xin, Chensu Zhao, Yixian Yang, and Yuling Chen. 2020. Graph Convolutional Networks for Privacy Metrics in Online Social Networks. Applied Sciences 10, 4 (2020)

  35. [43]

    Xunkai Li, Yulin Zhao, Zhengyu Wu, Wentao Zhang, Rong-Hua Li, and Guoren Wang. 2024. Towards Effective and General Graph Unlearning via Mutual Evolution. Proceedings of the AAAI Conference on Artificial Intelligence 38, 12 (Mar. 2024), 13682–13690

  36. [44]

    Daniil Likhobaba, Nikita Pavlichenko, and Dmitry Ustalov. 2023. Toloker Graph: Interaction of Crowd Annotators. https://doi.org/10.5281/zenodo.7620795

  37. [45]

    Jiaqi Liu, Jian Lou, Zhan Qin, and Kui Ren. 2023. Certified Minimax Unlearning with Generalization Rates and Deletion Capacity. In Advances in Neural Informa- tion Processing Systems, A. Oh, T. Naumann, A. Globerson, K. Saenko, M. Hardt, and S. Levine (Eds.), Vol. 36. Curran A...

  38. [46]

    Ximeng Liu, Lehui Xie, Yaopeng Wang, Jian Zou, Jinbo Xiong, Zuobin Ying, and Athanasios V Vasilakos. 2020. Privacy and security issues in deep learning: A survey. IEEE Access 9 (2020), 4566–4593

  39. [47]

    Zheyuan Liu, Guangyao Dou, Eli Chien, Chunhui Zhang, Yijun Tian, and Ziwei Zhu. 2024. Breaking the trilemma of privacy, utility, and efficiency via controllable machine unlearning. In Proceedings of the ACM on Web Conference 2024 . 1260– 1271

  40. [48]

    Yuankai Luo, Lei Shi, and Xiao-Ming Wu. 2024. Classic GNNs are Strong Base- lines: Reassessing GNNs for Node Classification. arXiv preprint arXiv:2406.08993 (2024)

  41. [49]

    Bronstein

    Federico Monti, Davide Boscaini, Jonathan Masci, Emanuele Rodolà, Jan Svoboda, and Michael M. Bronstein. 2016. Geometric Deep Learning on Graphs and Manifolds Using Mixture Model CNNs. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2016), 5425–5434

  42. [50]

    Chao Pan, Eli Chien, and Olgica Milenkovic. 2023. Unlearning Graph Classifiers with Limited Data Resources. In Proceedings of the ACM Web Conference, WWW

  43. [51]

    Stuart L Pardau. 2018. The california consumer privacy act: Towards a european- style privacy regime in the united states. J. Tech. L. & Pol’y 23 (2018), 68. 13

  44. [52]

    Hongbin Pei, Bingzhe Wei, Kevin Chen-Chuan Chang, Yu Lei, and Bo Yang. 2020. Geom-gcn: Geometric graph convolutional networks. In International Conference on Learning Representations, ICLR

  45. [53]

    Oleg Platonov, Denis Kuznedelev, Michael Diskin, Artem Babenko, and Liud- mila Prokhorenkova. 2023. A critical look at the evaluation of GNNs under heterophily: are we really making progress?International Conference on Learning Representations, ICLR (2023)

  46. [54]

    Wei Qian, Chenxu Zhao, Wei Le, Meiyi Ma, and Mengdi Huai. 2023. Towards understanding and enhancing robustness of deep learning models against mali- cious unlearning attacks. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 1932–1942

  47. [55]

    Zongshuai Qu, Tao Yao, Xinghui Liu, and Gang Wang. 2023. A Graph Con- volutional Network Based on Univariate Neurodegeneration Biomarker for Alzheimer’s Disease Diagnosis. IEEE Journal of Translational Engineering in Health and Medicine (2023)

  48. [56]

    General Data Protection Regulation. 2018. General data protection regula- tion (GDPR). ntersoft Consulting. Obtenido de https://www. epsu. org/sites/> default/files/article/files/GDPR_FINAL_EPSU. pdf (2018)

  49. [57]

    Saif Ur Rehman, Asmat Ullah Khan, and Simon Fong. 2012. Graph mining: A survey of graph mining techniques. InSeventh International Conference on Digital Information Management (ICDIM 2012) . 88–92

  50. [58]

    Kaspar Riesen and Horst Bunke. 2008. IAM Graph Database Repository for Graph Based Pattern Recognition and Machine Learning. In Proceedings of the 2008 Joint IAPR International Workshop on Structural, Syntactic, and Statistical Pattern Recognition (Orlando, Florida) (SSPR & SP...

  51. [59]

    O’Reilly Media, Inc

    Ian Robinson, Jim Webber, and Emil Eifrem. 2015. Graph databases: new opportu- nities for connected data . " O’Reilly Media, Inc. "

  52. [60]

    Oleksandr Shchur, Maximilian Mumme, Aleksandar Bojchevski, and Stephan Günnemann. 2018. Pitfalls of graph neural network evaluation. arXiv preprint arXiv:1811.05868 (2018)

  53. [61]

    Yash Sinha, Murari Mandal, and Mohan Kankanhalli. 2024. Distill to Delete: Unlearning in Graph Networks with Knowledge Distillation. arXiv:2309.16173 [cs.LG]

  54. [62]

    Daohan Su, Bowen Fan, Zhi Zhang, Haoyan Fu, and Zhida Qin. 2024. DCL: Di- versified Graph Recommendation With Contrastive Learning. IEEE Transactions on Computational Social Systems (2024)

  55. [63]

    Henan Sun, Xunkai Li, Zhengyu Wu, Daohan Su, Rong-Hua Li, and Guoren Wang. 2023. Breaking the Entanglement of Homophily and Heterophily in Semi-supervised Node Classification. arXiv preprint arXiv:2312.04111 (2023)

  56. [64]

    Sutherland, Lee A

    Jeffrey J. Sutherland, Lee A. O’Brien, and Donald F. Weaver. 2003. Spline-Fitting with a Genetic Algorithm: A Method for Developing Classification Structure Activity Relationships. Journal of Chemical Information and Computer Sciences 43, 6 (2003), 1906–1915

  57. [65]

    Jiajun Tan, Fei Sun, Ruichen Qiu, Du Su, and Huawei Shen. 2024. Unlink to Unlearn: Simplifying Edge Unlearning in GNNs. In Companion Proceedings of the ACM Web Conference 2024. Association for Computing Machinery, 489–492

  58. [66]

    Harry Chandra Tanuwidjaja, Rakyong Choi, Seunggeun Baek, and Kwangjo Kim

  59. [67]

    Ayush K Tarun, Vikram S Chundawat, Murari Mandal, and Mohan Kankanhalli

  60. [68]

    Petar Veličković, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, and Yoshua Bengio. 2018. Graph attention networks. In International Con- ference on Learning Representations, ICLR

  61. [69]

    Nikil Wale and George Karypis. 2006. Comparison of Descriptor Spaces for Chemical Compound Retrieval and Classification. In Proceedings of the Sixth International Conference on Data Mining (ICDM ’06) . IEEE Computer Society, USA, 678–689

  62. [70]

    Cheng-Long Wang, Mengdi Huai, and Di Wang. 2023. Inductive Graph Unlearn- ing. arXiv preprint arXiv:2304.03093 (2023)

  63. [71]

    Fast yet effective machine unlearning.IEEE Transactions on Neural Networks and Learning Systems (2023)

  64. [72]

    Zhouxia Wang, Tianshui Chen, Jimmy Ren, Weihao Yu, Hui Cheng, and Liang Lin. 2018. Deep Reasoning with Knowledge Graph for Social Relationship Un- derstanding. In Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence, IJCAI-18. Internation...

  65. [73]

    Bingzhe Wu, Jintang Li, Junchi Yu, Yatao Bian, Hengtong Zhang, CHaochao Chen, Chengbin Hou, Guoji Fu, Liang Chen, Tingyang Xu, et al. 2022. A survey of trustworthy graph learning: Reliability, explainability, and privacy protection. arXiv preprint arXiv:2205.10014 (2022)

  66. [74]

    Felix Wu, Amauri Souza, Tianyi Zhang, Christopher Fifty, Tao Yu, and Kilian Weinberger. 2019. Simplifying graph convolutional networks. In International Conference on Machine Learning, ICML

  67. [75]

    Kuansan Wang, Zhihong Shen, Chiyuan Huang, Chieh-Han Wu, Yuxiao Dong, and Anshul Kanakia. 2020. Microsoft academic graph: When experts are not enough. Quantitative Science Studies 1, 1 (2020), 396–413

  68. [76]

    Kun Wu, Jie Shen, Yue Ning, Ting Wang, and Wendy Hui Wang. 2023. Certified Edge Unlearning for Graph Neural Networks. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . Association for Computing Machinery, 2606–2617

  69. [77]

    Tao Wu, Xinwen Cao, Chao Wang, Shaojie Qiao, Xingping Xian, Lin Yuan, Canyixing Cui, and Yanbing Liu. 2024. GraphMU: Repairing Robustness of Graph Neural Networks via Machine Unlearning. arXiv:2406.13499 [cs.SI]

  70. [78]

    Zonghan Wu, Shirui Pan, Fengwen Chen, Guodong Long, Chengqi Zhang, and S Yu Philip. 2020. A comprehensive survey on graph neural networks. IEEE Transactions on Neural Networks and Learning Systems 32, 1 (2020), 4–24

  71. [79]

    Jiancan Wu, Yi Yang, Yuchun Qian, Yongduo Sui, Xiang Wang, and Xiangnan He. 2023. GIF: A General Graph Unlearning Strategy via Influence Function. In Proceedings of the ACM Web Conference, WWW

  72. [80]

    Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2019. How powerful are graph neural networks? International Conference on Learning Representa- tions, ICLR

  73. [81]

    Haonan Yan, Xiaoguang Li, Ziyao Guo, Hui Li, Fenghua Li, and Xiaodong Lin

  74. [82]

    Vishwanathan

    Pinar Yanardag and S.V.N. Vishwanathan. 2015. Deep Graph Kernels. In Proceed- ings of the 21th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. Association for Computing Machinery, 1365–1374

  75. [83]

    Heng Xu, Tianqing Zhu, Lefeng Zhang, Wanlei Zhou, and Philip S. Yu. 2023. Machine Unlearning: A Survey. ACM Comput. Surv. 56, 1, Article 9 (Aug. 2023)

  76. [84]

    Cohen, and Ruslan Salakhutdinov

    Zhilin Yang, William W. Cohen, and Ruslan Salakhutdinov. 2016. Revisiting Semi-Supervised Learning with Graph Embeddings. In International Conference on Machine Learning, ICML

  77. [85]

    Kim, Duygu Ceylan, I-Chao Shen, Mengyan Yan, Hao Su, Cewu Lu, Qixing Huang, Alla Sheffer, and Leonidas Guibas

    Li Yi, Vladimir G. Kim, Duygu Ceylan, I-Chao Shen, Mengyan Yan, Hao Su, Cewu Lu, Qixing Huang, Alla Sheffer, and Leonidas Guibas. 2016. A scalable active framework for region annotation in 3D shape collections. ACM Trans. Graph. 35, 6, Article 210 (2016)

  78. [86]

    Lu Yi and Zhewei Wei. 2024. Scalable and Certifiable Graph Unlearning: Over- coming the Approximation Error Barrier. arXiv:2408.09212 [cs.LG]

  79. [87]

    Seongjun Yun, Minbyul Jeong, Raehyun Kim, Jaewoo Kang, and Hyunwoo J. Kim. 2019. Graph transformer networks. Curran Associates Inc

  80. [88]

    Tzu-Hsuan Yang and Cheng-Te Li. 2023. When Contrastive Learning Meets Graph Unlearning: Graph Contrastive Unlearning for Link Prediction. In 2023 IEEE International Conference on Big Data (BigData) . 6025–6032

  81. [89]

    Jiahao Zhang. 2024. Graph Unlearning with Efficient Partial Retraining. In Com- panion Proceedings of the ACM Web Conference 2024 . Association for Computing Machinery, 1218–1221

  82. [90]

    Zhexin Zhang, Junxiao Yang, Pei Ke, Shiyao Cui, Chujie Zheng, Hongning Wang, and Minlie Huang. 2024. Safe Unlearning: A Surprisingly Effective and General- izable Solution to Defend Against Jailbreak Attacks. arXiv:2407.02855 [cs.CR]

  83. [91]

    Wenyue Zheng, Ximeng Liu, Yuyang Wang, and Xuanwei Lin. 2023. Graph Unlearning Using Knowledge Distillation. In Information and Communications Security: 25th International Conference, ICICS 2023, Tianjin, China, November 18–20, 2023, Proceedings. Springer-Verlag, 485–501

  84. [92]

    Yu Zhou, Haixia Zheng, Xin Huang, Shufeng Hao, Dengao Li, and Jumin Zhao

  85. [93]

    Hanqing Zeng, Hongkuan Zhou, Ajitesh Srivastava, Rajgopal Kannan, and Viktor Prasanna. 2020. Graphsaint: Graph sampling based inductive learning method. In International conference on learning representations, ICLR

  86. [94]

    Marinka Zitnik, Monica Agrawal, and Jure Leskovec. 2018. Modeling polyphar- macy side effects with graph convolutional networks. Bioinformatics 34, 13 (06 2018), i457–i466. 14 A OUTLINE The appendix is organized as follows: A.1 Dataset Details A.2 Backbone Details A.3 GU Metho...

  87. [98]

    ACM Transac- tions on Intelligent Systems and TechnoLoGy 13, 1 (2022), 1–54

    Graph Neural Networks: Taxonomy, Advances, and Trends. ACM Transac- tions on Intelligent Systems and TechnoLoGy 13, 1 (2022), 1–54

  88. [99]

    Hao Zhu and Piotr Koniusz. 2021. Simple spectral graph convolution. In Interna- tional Conference on Learning Representations, ICLR

  89. [2019]

    In Proceedings of the ACM SIGKDD Conference on Knowledge Discovery and Data Mining, KDD

    Cluster-gcn: An efficient algorithm for training deep and large graph con- volutional networks. In Proceedings of the ACM SIGKDD Conference on Knowledge Discovery and Data Mining, KDD

  90. [2020]

    IEEE Access 8 (2020), 167425–167447

    Privacy-preserving deep learning on machine learning as a service—a comprehensive survey. IEEE Access 8 (2020), 167425–167447

  91. [2022]

    In IJCAI, Vol

    ARCANE: An Efficient Architecture for Exact Machine Unlearning.. In IJCAI, Vol. 6. 19

  92. [2023]

    In International Conference on Learning Representations, ICLR

    GNNDelete: A General Strategy for Unlearning in Graph Neural Networks. In International Conference on Learning Representations, ICLR

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.