Abstract
The widespread adoption and significant development costs associated with Graph Neural Networks (GNNs) increase vulnerability to model stealing attacks, posing a serious threat to intellectual property (IP). Third-party ownership verification provides an effective mechanism to protect IP of model owners while ensuring impartial verification. Current GNN fingerprint verification methods impose impractical requirements, demanding either access to internal model fingerprints (e.g., node embeddings) or detailed information about model stealing attacks. In this paper, we propose Canary, a black-box third-party GNN ownership verification protocol based on fingerprints, where verifiers access only model prediction posteriors and require no knowledge of adversaries' model stealing attacks. Specifically, we generate subgraph inputs as decision boundary fingerprints by maximizing the logits distance between the shadow surrogate and shadow independent model, effectively revealing their posterior probability discrepancies. Experiments across six datasets show that Canary effectively detects ten types of model stealing attacks, achieving a 35.68% higher negative-class F1-score than the state-of-the-art gray-box method Grove while maintaining robustness against seven types of evasion attacks.
| Original language | English |
|---|---|
| Journal | IEEE Transactions on Dependable and Secure Computing |
| DOIs | |
| Publication status | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- Graph neural networks
- model intellectual property
- model ownership verification
Fingerprint
Dive into the research topics of 'Black-Box Verification for GNN Ownership Via Decision Boundary Fingerprints'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver