arXiv:2503.16693cs.LGcs.CR2025-03KDD被引 11

实时检测图神经网络的模型提取攻击,提升服务安全

ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks

  • 用序列建模与强化学习动态识别攻击模式
  • 结合k-core嵌入提升检测准确率,多数据集验证有效
  • 适合部署于图机器学习即服务场景的实时防御

图神经网络(GNN)在基于图的机器学习即服务(GMLaaS)平台中广泛应用,但易受基于查询的模型提取攻击(MEAs)威胁,攻击者通过查询受害者模型重建替代模型。现有防御机制如水印、指纹技术存在实时性差、易被绕过或依赖事后验证等问题,难以应对图型MEA的动态变化。为此,我们提出ATOM,一种针对GNN的新型实时MEA检测框架。ATOM融合序列建模与强化学习,动态捕捉演化中的攻击行为,并利用k-core嵌入捕获图结构特性,提升检测精度。此外,我们提供理论分析以刻画查询行为并优化检测策略。在多个真实数据集上的大量实验表明,ATOM在检测性能上优于现有方法,且在不同时间步下保持稳定,为GMLaaS环境提供了更有效的防御机制。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) have gained traction in Graph-based Machine Learning as a Service (GMLaaS) platforms, yet they remain vulnerable to graph-based model extraction attacks (MEAs), where adversaries reconstruct surrogate models by querying the victim model. Existing defense mechanisms, such as watermarking and fingerprinting, suffer from poor real-time performance, susceptibility to evasion, or reliance on post-attack verification, making them inadequate for handling the dynamic characteristics of graph-based MEA variants. To address these limitations, we propose ATOM, a novel real-time MEA detection framework tailored for GNNs. ATOM integrates sequential modeling and reinforcement learning to dynamically detect evolving attack patterns, while leveraging $k$-core embedding to capture the structural properties, enhancing detection precision. Furthermore, we provide theoretical analysis to characterize query behaviors and optimize detection strategies. Extensive experiments on multiple real-world datasets demonstrate that ATOM outperforms existing approaches in detection performance, maintaining stable across different time steps, thereby offering a more effective defense mechanism for GMLaaS environments.

图神经网络模型安全实时检测攻击防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。