arXiv:2412.15735cs.LG2024-12AAAI被引 7

提出统一的图神经网络推理攻击框架,可从模型参数中提取私有信息。

Prompt-based Unifying Inference Attack on Graph Neural Networks

  • 利用统一提示词和图结构信息增强攻击模型背景知识。
  • 在下游攻击中引入解耦因子,适配不同任务的推理需求。
  • 适用于高风险场景下评估图模型隐私泄露风险。

图神经网络(GNN)在社交行为分析、金融风险分析等应用中展现出强大能力,但其性能依赖于特定任务的节点标签。为提升泛化能力,常通过预训练来优化模型。图提示(Graph prompting)虽能有效辅助,却可能因发布预训练模型参数而造成数据泄露。本文提出一种新型基于提示的统一推理攻击框架ProIA:在预训练阶段保留图的拓扑信息以增强攻击模型的背景知识;在下游攻击中采用统一提示并引入额外解耦因子,适应不同任务相关知识。大量实验表明,ProIA显著提升了攻击能力,并对多种推理攻击具备良好适应性。

原文摘要 · Abstract (English)

Graph neural networks (GNNs) provide important prospective insights in applications such as social behavior analysis and financial risk analysis based on their powerful learning capabilities on graph data. Nevertheless, GNNs' predictive performance relies on the quality of task-specific node labels, so it is common practice to improve the model's generalization ability in the downstream execution of decision-making tasks through pre-training. Graph prompting is a prudent choice but risky without taking measures to prevent data leakage. In other words, in high-risk decision scenarios, prompt learning can infer private information by accessing model parameters trained on private data (publishing model parameters in pre-training, i.e., without directly leaking the raw data, is a tacitly accepted trend). However, myriad graph inference attacks necessitate tailored module design and processing to enhance inference capabilities due to variations in supervision signals. In this paper, we propose a novel Prompt-based unifying Inference Attack framework on GNNs, named ProIA. Specifically, ProIA retains the crucial topological information of the graph during pre-training, enhancing the background knowledge of the inference attack model. It then utilizes a unified prompt and introduces additional disentanglement factors in downstream attacks to adapt to task-relevant knowledge. Finally, extensive experiments show that ProIA enhances attack capabilities and demonstrates remarkable adaptability to various inference attacks.

图神经网络隐私攻击提示学习推断攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。