arXiv:2505.15140cs.LGcs.CR2025-05中稿 · 2025 IEEE Internat…被引 2

提出新型标签分布攻击EC-LDA,通过压缩嵌入提升隐私泄露风险

EC-LDA : Label Distribution Inference Attack against Federated Graph Learning with Embedding Compression

  • 利用节点嵌入方差特性,压缩嵌入增强攻击效果
  • 在6个数据集上实现高达1.0的余弦相似度,超越现有方法
  • 揭示联邦图学习隐私漏洞,适合关注隐私安全的研究者

图神经网络广泛用于图分析。联邦图学习(FGL)是一种新兴框架,允许多客户端协作训练图数据。尽管客户端数据保持本地化,恶意服务器仍可通过上传梯度窃取私有信息。本文首次提出针对FGL的标签分布攻击(LDAs),旨在推断客户端数据的标签分布。首先观察到攻击有效性与节点嵌入方差密切相关;随后分析其关系并提出新攻击方法EC-LDA,通过压缩节点嵌入显著提升攻击效果。在六个常用图数据集上的节点分类和链接预测任务中,实验表明EC-LDA优于当前最优攻击方法,几乎所有情况下余弦相似度均达1.0。最后,探讨了差分隐私保护下的鲁棒性,并讨论潜在防御策略。代码已开源。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) have been widely used for graph analysis. Federated Graph Learning (FGL) is an emerging learning framework to collaboratively train graph data from various clients. Although FGL allows client data to remain localized, a malicious server can still steal client private data information through uploaded gradient. In this paper, we for the first time propose label distribution attacks (LDAs) on FGL that aim to infer the label distributions of the client-side data. Firstly, we observe that the effectiveness of LDA is closely related to the variance of node embeddings in GNNs. Next, we analyze the relation between them and propose a new attack named EC-LDA, which significantly improves the attack effectiveness by compressing node embeddings. Then, extensive experiments on node classification and link prediction tasks across six widely used graph datasets show that EC-LDA outperforms the SOTA LDAs. Specifically, EC-LDA can achieve the Cos-sim as high as 1.0 under almost all cases. Finally, we explore the robustness of EC-LDA under differential privacy protection and discuss the potential effective defense methods to EC-LDA. Our code is available at https://github.com/cheng-t/EC-LDA.

联邦学习隐私攻击图神经网络嵌入压缩

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。