REVIEW 9 cited by
Node-Level Membership Inference Attacks Against Graph Neural Networks
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Many real-world data comes in the form of graphs, such as social networks and protein structure. To fully utilize the information contained in graph data, a new family of machine learning (ML) models, namely graph neural networks (GNNs), has been introduced. Previous studies have shown that machine learning models are vulnerable to privacy attacks. However, most of the current efforts concentrate on ML models trained on data from the Euclidean space, like images and texts. On the other hand, privacy risks stemming from GNNs remain largely unstudied. In this paper, we fill the gap by performing the first comprehensive analysis of node-level membership inference attacks against GNNs. We systematically define the threat models and propose three node-level membership inference attacks based on an adversary's background knowledge. Our evaluation on three GNN structures and four benchmark datasets shows that GNNs are vulnerable to node-level membership inference even when the adversary has minimal background knowledge. Besides, we show that graph density and feature similarity have a major impact on the attack's success. We further investigate two defense mechanisms and the empirical results indicate that these defenses can reduce the attack performance but with moderate utility loss.
Forward citations
Cited by 9 Pith papers
-
Impact of Graph Structure on Membership-Inference Risk for Graph Neural Networks
Graph construction and inference-time edge access modulate node-level membership-inference advantage in GNNs, and the generalization gap is an incomplete proxy.
-
Who Owns This Sample: Cross-Client Membership Inference Attack in Federated Graph Neural Networks
A malicious client in federated graph learning can infer which client owns a node by combining gradient eavesdropping, graph reconstruction, and class-prototype matching.
-
GRID: Protecting Training Graph from Link Stealing Attacks on GNN Models
GRID adds crafted noise to prediction vectors of selected core nodes so linked node pairs look like n-hop unlinked pairs, while preserving predicted labels.
-
GraphTheft: Quantifying Privacy Risks in Graph Prompt Learning
An empirical study showing that graph prompt learning exposes node attributes and links to inference attacks, with prompt tuning adding little extra risk over frozen GNN baselines.
-
Stealing Training Graphs from Graph Neural Networks
A white-box attack called GraphSteal reconstructs exact training molecules from a trained GNN by generating candidates with a diffusion model and selecting those whose gradients best explain the model parameters.
-
SoK: Data Reconstruction Attacks Against Machine Learning Models: Definition, Metrics, and Benchmark
The authors define data reconstruction attacks and measure them with dataset-level FID, sample-level distance and coverage, and an LLM visual judge, finding reconstruction quality tracks memorization.
-
An Out-Of-Distribution Membership Inference Attack Approach for Cross-Domain Graph Attacks
GOOD-MIA combines invariant risk minimization, a graph information bottleneck, and risk extrapolation to run membership inference attacks against graph neural networks across different data domains.
-
Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses
A systematic review that organizes graph-ML IP protection into model-level and data-level attacks and defenses, and ships a benchmark library, PyGIP.
-
Large Language Models Merging for Enhancing the Link Stealing Attack on Graph Neural Networks
A softmax-weighted model merging method combines multiple LLM-based link stealing attack models into one model that beats existing merging baselines across four graph datasets.
Discussion (0). Continue with ORCID to comment.