跳到主要导航 跳到搜索 跳到主要内容

PriGraph: Defending Against Inference Attacks on Graph Neural Networks via Policy-Based Adversarial Perturbations

  • Meng Shen*
  • , Hao Lu
  • , Aijing Gu
  • , Qi Li
  • , Ke Xu
  • , Liehuang Zhu
  • *此作品的通讯作者
  • Beijing Institute of Technology
  • State Key Laboratory of Cryptology
  • Tsinghua University

科研成果: 期刊稿件文章同行评审

摘要

Graph-structured data have been widely used in modeling various systems, such as social networks and transportation networks. Leveraging the structure and properties of graphs, Graph Neural Networks (GNNs) have been proposed to perform in the graph domain. Previous research has shown that GNNs are vulnerable to inference attacks, which aim to infer sensitive information of training graph data, e.g., node membership and link status. Node Membership Inference Attacks (NMIAs) on GNNs infer whether a set of graph data records belongs to the training graph data of a target model. Link Status Inference Attacks (LSIAs) against GNNs aim to infer whether there exists a link between a pair of nodes in the graph used to train the target GNN model. Specifically, given black-box access to a GNN model, NMIAs and LSIAs are conducted by analyzing the outputs (e.g., confidence score vectors) from GNN models. The defense methods against these two score-based inference attacks face the challenges of achieving effective defense performance and maintaining the utility of GNN models. In this paper, we propose PriGraph, a defense mechanism to protect the node privacy and link privacy of training graph data, while maintaining the high accuracy of the target GNN models. PriGraph adds crafted adversarial perturbations to outputs of the target GNN model by deploying two key components, i.e., defense auxiliary classifier and adversarial perturbation generator, which are used to find the minimal adversarial perturbations that can reduce the attack accuracy while maintaining task performance of node classification. We evaluate PriGraph with different GNN models and multiple benchmark datasets. The results show that PriGraph can dramatically reduce the attack accuracy of NMIA and LSIA on GNNs, providing a superior trade-off between the model utility and privacy.

源语言英语
页(从-至)890-904
页数15
期刊IEEE Transactions on Dependable and Secure Computing
23
1
DOI
出版状态已出版 - 2026
已对外发布

学术指纹

探究 'PriGraph: Defending Against Inference Attacks on Graph Neural Networks via Policy-Based Adversarial Perturbations' 的科研主题。它们共同构成独一无二的学术指纹。

引用此