跳到主要导航 跳到搜索 跳到主要内容

Black-Box Verification for GNN Ownership Via Decision Boundary Fingerprints

  • Beijing Institute of Technology
  • Central University of Finance and Economics
  • Tsinghua University

科研成果: 期刊稿件文章同行评审

摘要

The widespread adoption and significant development costs associated with Graph Neural Networks (GNNs) increase vulnerability to model stealing attacks, posing a serious threat to intellectual property (IP). Third-party ownership verification provides an effective mechanism to protect IP of model owners while ensuring impartial verification. Current GNN fingerprint verification methods impose impractical requirements, demanding either access to internal model fingerprints (e.g., node embeddings) or detailed information about model stealing attacks. In this paper, we propose Canary, a black-box third-party GNN ownership verification protocol based on fingerprints, where verifiers access only model prediction posteriors and require no knowledge of adversaries' model stealing attacks. Specifically, we generate subgraph inputs as decision boundary fingerprints by maximizing the logits distance between the shadow surrogate and shadow independent model, effectively revealing their posterior probability discrepancies. Experiments across six datasets show that Canary effectively detects ten types of model stealing attacks, achieving a 35.68% higher negative-class F1-score than the state-of-the-art gray-box method Grove while maintaining robustness against seven types of evasion attacks.

源语言英语
期刊IEEE Transactions on Dependable and Secure Computing
DOI
出版状态已接受/待刊 - 2026
已对外发布

指纹

探究 'Black-Box Verification for GNN Ownership Via Decision Boundary Fingerprints' 的科研主题。它们共同构成独一无二的指纹。

引用此