arXiv:2505.24089cs.LGcs.CR2025-05NeurIPS被引 7

提出高效且理论严谨的成员推断攻击,适用于图像与图数据。

Practical Bayes-Optimal Membership Inference Attacks

  • 基于贝叶斯决策框架,推导图神经网络节点级成员推断最优规则。
  • 新方法G-BASE在图数据上表现优于现有攻击,BASE在非图数据中效率更高。
  • 揭示了已有攻击RMIA的贝叶斯最优性,为其实现提供理论支撑。

我们针对独立同分布(i.i.d.)数据和图结构数据,开发了实用且理论严谨的成员推断攻击(MIAs)。基于Sablayrolles等人的贝叶斯决策理论框架,推导出图神经网络节点级成员推断的贝叶斯最优规则,解决了图场景下最优查询策略的关键开放问题。提出可计算的近似方法BASE和G-BASE,分别适用于非图与图数据。G-BASE在节点级成员推断任务中性能优于先前基于分类器的攻击方法。BASE在非图数据上性能媲美甚至超过当前最优攻击如LiRA和RMIA,同时计算成本显著降低。最后证明,在特定超参数设置下,BASE与RMIA等价,为RMIA攻击提供了贝叶斯最优的理论解释。

原文摘要 · Abstract (English)

We develop practical and theoretically grounded membership inference attacks (MIAs) against both independent and identically distributed (i.i.d.) data and graph-structured data. Building on the Bayesian decision-theoretic framework of Sablayrolles et al., we derive the Bayes-optimal membership inference rule for node-level MIAs against graph neural networks, addressing key open questions about optimal query strategies in the graph setting. We introduce BASE and G-BASE, tractable approximations of the Bayes-optimal membership inference. G-BASE achieves superior performance compared to previously proposed classifier-based node-level MIA attacks. BASE, which is also applicable to non-graph data, matches or exceeds the performance of prior state-of-the-art MIAs, such as LiRA and RMIA, at a significantly lower computational cost. Finally, we show that BASE and RMIA are equivalent under a specific hyperparameter setting, providing a principled, Bayes-optimal justification for the RMIA attack.

成员推断图神经网络贝叶斯优化隐私攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。