首次揭示联邦图神经网络中样本归属泄露风险
Who Owns This Sample: Cross-Client Membership Inference Attack in Federated Graph Neural Networks
- 利用聚合行为、梯度更新和嵌入相似性定位数据来源客户端
- 在多个真实联邦设置下实现高精度成员推理与归属识别
- 适合关注联邦学习隐私安全的研究者与系统设计者
图结构数据广泛应用于社交网络、金融系统和分子生物学等领域。图神经网络(GNN)因其强大的表征能力,已成为从这类数据中学习的标准方法。随着GNN在联邦学习(FL)场景中部署以保护数据本地性和隐私,图结构与去中心化训练的交互带来了新的隐私威胁。本文首次系统研究了针对节点分类任务的跨客户端成员推理攻击(CC-MIA),其中恶意客户端试图推断给定样本归属于哪个客户端。不同于以往集中式研究关注样本是否被用于训练,本工作聚焦于样本到客户端的归属定位,这是联邦设置下更细粒度的隐私风险。我们设计了一种通用攻击框架,利用FedGNN的聚合行为、梯度更新和嵌入相似性,在多个训练轮次中将样本与其源客户端关联。在多种图数据集上进行评估,结果表明该方法在成员推理和归属识别方面均表现优异。研究揭示了联邦图学习中的新型隐私威胁——通过结构与模型级线索导致客户端身份泄露,亟需设计具备归属鲁棒性的图神经网络。
原文摘要 · Abstract (English)
Graph-structured data is prevalent in many real-world applications, including social networks, financial systems, and molecular biology. Graph Neural Networks (GNNs) have become the de facto standard for learning from such data due to their strong representation capabilities. As GNNs are increasingly deployed in federated learning (FL) settings to preserve data locality and privacy, new privacy threats arise from the interaction between graph structures and decentralized training. In this paper, we present the first systematic study of cross-client membership inference attacks (CC-MIA) against node classification tasks of federated GNNs (FedGNNs), where a malicious client aims to infer which client owns the given data. Unlike prior centralized-focused work that focuses on whether a sample was included in training, our attack targets sample-to-client attribution, a finer-grained privacy risk unique to federated settings. We design a general attack framework that exploits FedGNNs' aggregation behaviors, gradient updates, and embedding proximity to link samples to their source clients across training rounds. We evaluate our attack across multiple graph datasets under realistic FL setups. Results show that our method achieves high performance on both membership inference and ownership identification. Our findings highlight a new privacy threat in federated graph learning-client identity leakage through structural and model-level cues, motivating the need for attribution-robust GNN design.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。