arXiv:2506.02134cs.LG2025-06

公开特征解释+差分隐私数据仍可被重构图结构

ReconXF: Graph Reconstruction Attack via Public Feature Explanations on Privatized Node Features and Labels

  • 利用公开解释与去噪机制,从加噪数据中重建图结构
  • 在多个数据集上AUC和平均精度均超越现有方法
  • 揭示了解释透明性带来的隐私泄露风险,适合安全研究者

图神经网络在众多应用中表现优异,但其黑箱特性限制了在医疗、司法等关键领域的使用。可解释性方法通过提供特征级解释来识别预测重要节点属性,却带来隐私风险。结合辅助信息,特征解释可能被攻击者用于重建图结构,暴露敏感关系。现有重构攻击假设可访问原始辅助数据,但在实际系统中,节点特征与标签常通过差分隐私保护,并提供解释以实现透明。我们研究一种威胁模型:攻击者仅能获取公开的特征解释及经差分隐私处理的节点特征与标签。实验表明,现有基于解释的攻击(如GSEF)在加噪数据下表现不佳。本文提出ReconXF,一种适用于公开解释与隐私化辅助数据场景的图重构攻击方法。该方法通过引入去噪机制,在保留解释中结构信号的同时处理差分隐私噪声。跨多个数据集的实验显示,ReconXF在隐私设置下显著优于现有最先进方法,提升AUC与平均精度。结果表明,即使在辅助数据受隐私保护的情况下,公开解释结合去噪仍可实现图结构恢复。代码将在论文录用后公开。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) achieve high performance across many applications but function as black-box models, limiting their use in critical domains like healthcare and criminal justice. Explainability methods address this by providing feature-level explanations that identify important node attributes for predictions. These explanations create privacy risks. Combined with auxiliary information, feature explanations can enable adversaries to reconstruct graph structure, exposing sensitive relationships. Existing graph reconstruction attacks assume access to original auxiliary data, but practical systems use differential privacy to protect node features and labels while providing explanations for transparency. We study a threat model where adversaries access public feature explanations along with privatized node features and labels. We show that existing explanation-based attacks like GSEF perform poorly with privatized data due to noise from differential privacy mechanisms. We propose ReconXF, a graph reconstruction attack for scenarios with public explanations and privatized auxiliary data. Our method adapts explanation-based frameworks by incorporating denoising mechanisms that handle differential privacy noise while exploiting structural signals in explanations. Experiments across multiple datasets show ReconXF outperforms SoTA methods in privatized settings, with improvements in AUC and average precision. Results indicate that public explanations combined with denoising enable graph structure recovery even under the privacy protection of auxiliary data. Code is available at (link to be made public after acceptance).

图神经网络隐私攻击差分隐私可解释性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。