攻击者可从图神经网络梯度重建节点特征与图结构
Gradient Inversion Attack on Graph Neural Networks
- 利用图数据特性和GNN结构设计梯度逆向攻击
- 在节点分类与图分类任务中实现高精度重构
- 适用于研究隐私泄露的GNN安全方向
图联邦学习在大型图数据集上训练时对保护数据隐私至关重要,各客户端存储局部图数据,服务器仅聚合并广播梯度。近期研究发现恶意攻击者可从神经网络梯度中窃取私有图像数据。然而,图数据及图神经网络在此类攻击下的脆弱性——即能否从泄漏的梯度中重构节点特征与图结构——仍鲜被探讨。本文针对节点分类与图分类任务,研究私有数据是否可从梯度中被重建,并提出新型攻击方法Graph Leakage from Gradients (GLG)。分析了GCN与GraphSAGE两种主流GNN框架,系统讨论不同模型设置对重构效果的影响。理论分析与实证验证表明,借助图数据与GNN的独特性质,GLG能更准确地从梯度中恢复节点特征与图结构。
原文摘要 · Abstract (English)
Graph federated learning is of essential importance for training over large graph datasets while protecting data privacy, where each client stores a subset of local graph data, while the server collects the local gradients and broadcasts only the aggregated gradients. Recent studies reveal that a malicious attacker can steal private image data from the gradient exchange of neural networks during federated learning. However, the vulnerability of graph data and graph neural networks under such attacks, i.e., reconstructing both node features and graph structure from gradients, remains largely underexplored. To answer this question, this paper studies the problem of whether private data can be reconstructed from leaked gradients in both node classification and graph classification tasks and proposes a novel attack named Graph Leakage from Gradients (GLG). Two widely used GNN frameworks are analyzed, namely GCN and GraphSAGE. The effects of different model settings on reconstruction are extensively discussed. Theoretical analysis and empirical validation demonstrate that, by leveraging the unique properties of graph data and GNNs, GLG achieves more accurate reconstruction of both nodal features and graph structure from gradients.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。