arXiv:2506.09803cs.LGcs.CR2025-06KDD被引 2

首个针对本地隐私图学习的投毒攻击,可破坏隐私保护下的图模型性能。

Devil's Hand: Data Poisoning Attacks to Locally Private Graph Learning Protocols

  • 通过伪造用户建立虚假连接并投送恶意数据
  • 理论与实验均证明攻击能显著降低节点分类准确率
  • 揭示现有防御手段不足,适合关注隐私安全的研究者

图神经网络(GNN)在图表示学习中取得显著进展,并被广泛应用于多个领域。然而,许多现实世界的图包含敏感个人信息(如社交网络中的用户资料),使用GNN进行图学习时引发严重隐私问题。为解决此问题,本地差分隐私(LDP)驱动的图学习协议受到广泛关注。这类协议利用LDP的隐私优势和GNN消息传递机制对噪声数据的校准能力,在严格保障用户本地数据隐私的同时,维持较高的图学习效用(如节点分类准确率)。尽管如此,此类协议可能面临数据投毒攻击,这一威胁此前未被研究。本文首次提出针对本地隐私图学习协议的数据投毒攻击:攻击者注入伪造用户,操纵其与真实用户建立连接,并向服务器发送精心设计的数据,最终破坏私有图学习的效用。攻击的有效性在理论上和实证上均得到验证。同时探索了多种防御策略,但其效果有限,凸显出构建更鲁棒防御的必要性。

原文摘要 · Abstract (English)

Graph neural networks (GNNs) have achieved significant success in graph representation learning and have been applied to various domains. However, many real-world graphs contain sensitive personal information, such as user profiles in social networks, raising serious privacy concerns when graph learning is performed using GNNs. To address this issue, locally private graph learning protocols have gained considerable attention. These protocols leverage the privacy advantages of local differential privacy (LDP) and the effectiveness of GNN's message-passing in calibrating noisy data, offering strict privacy guarantees for users' local data while maintaining high utility (e.g., node classification accuracy) for graph learning. Despite these advantages, such protocols may be vulnerable to data poisoning attacks, a threat that has not been considered in previous research. Identifying and addressing these threats is crucial for ensuring the robustness and security of privacy-preserving graph learning frameworks. This work introduces the first data poisoning attack targeting locally private graph learning protocols. The attacker injects fake users into the protocol, manipulates these fake users to establish links with genuine users, and sends carefully crafted data to the server, ultimately compromising the utility of private graph learning. The effectiveness of the attack is demonstrated both theoretically and empirically. In addition, several defense strategies have also been explored, but their limited effectiveness highlights the need for more robust defenses.

图神经网络隐私保护投毒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。