TY - JOUR
T1 - Black-Box Verification for GNN Ownership Via Decision Boundary Fingerprints
AU - Shen, Meng
AU - Peng, Luyao
AU - Lu, Hao
AU - Qin, Yue
AU - Li, Qi
AU - Zhu, Liehuang
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - The widespread adoption and significant development costs associated with Graph Neural Networks (GNNs) increase vulnerability to model stealing attacks, posing a serious threat to intellectual property (IP). Third-party ownership verification provides an effective mechanism to protect IP of model owners while ensuring impartial verification. Current GNN fingerprint verification methods impose impractical requirements, demanding either access to internal model fingerprints (e.g., node embeddings) or detailed information about model stealing attacks. In this paper, we propose Canary, a black-box third-party GNN ownership verification protocol based on fingerprints, where verifiers access only model prediction posteriors and require no knowledge of adversaries' model stealing attacks. Specifically, we generate subgraph inputs as decision boundary fingerprints by maximizing the logits distance between the shadow surrogate and shadow independent model, effectively revealing their posterior probability discrepancies. Experiments across six datasets show that Canary effectively detects ten types of model stealing attacks, achieving a 35.68% higher negative-class F1-score than the state-of-the-art gray-box method Grove while maintaining robustness against seven types of evasion attacks.
AB - The widespread adoption and significant development costs associated with Graph Neural Networks (GNNs) increase vulnerability to model stealing attacks, posing a serious threat to intellectual property (IP). Third-party ownership verification provides an effective mechanism to protect IP of model owners while ensuring impartial verification. Current GNN fingerprint verification methods impose impractical requirements, demanding either access to internal model fingerprints (e.g., node embeddings) or detailed information about model stealing attacks. In this paper, we propose Canary, a black-box third-party GNN ownership verification protocol based on fingerprints, where verifiers access only model prediction posteriors and require no knowledge of adversaries' model stealing attacks. Specifically, we generate subgraph inputs as decision boundary fingerprints by maximizing the logits distance between the shadow surrogate and shadow independent model, effectively revealing their posterior probability discrepancies. Experiments across six datasets show that Canary effectively detects ten types of model stealing attacks, achieving a 35.68% higher negative-class F1-score than the state-of-the-art gray-box method Grove while maintaining robustness against seven types of evasion attacks.
KW - Graph neural networks
KW - model intellectual property
KW - model ownership verification
UR - https://www.scopus.com/pages/publications/105039628907
U2 - 10.1109/TDSC.2026.3695130
DO - 10.1109/TDSC.2026.3695130
M3 - Article
AN - SCOPUS:105039628907
SN - 1545-5971
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
ER -