arXiv:2511.10936cs.LGcs.AI2025-11

提出首个图数据删除后重建攻击,揭示图去学习的隐私漏洞。

GraphToxin: Reconstructing Full Unlearned Graphs from Graph Unlearning

  • 设计曲率匹配模块,精准引导被删除图结构的恢复。
  • 可重建单节点及多节点删除后的用户信息与关联内容。
  • 适用于白盒黑盒场景,现有防御反而可能加剧风险。

图去学习作为满足“被遗忘权”的潜在方案,可通过请求删除敏感信息。然而该方案存在漏洞:多方参与带来新攻击面,被删数据残留仍存在于去学习后的图神经网络中。本文提出GraphToxin,首个针对图去学习的完整图结构重建攻击。通过引入新颖的曲率匹配模块,实现对去学习图的细粒度恢复指导。实验表明,GraphToxin不仅能复原被删除个体的信息与个人连接,还可恢复其关联方的敏感内容,严重威胁隐私保护效果。我们进一步在白盒与黑盒设定下扩展至多节点删除场景,验证其实际可行性与危害性。提出系统化评估框架,涵盖随机与最坏情况下的节点移除。大量实验显示,GraphToxin具有高效与灵活特性;且现有防御机制普遍无效,甚至在某些情况下放大攻击效果。本工作强调亟需更鲁棒的防御策略。

原文摘要 · Abstract (English)

Graph unlearning has emerged as a promising solution to comply with "the right to be forgotten" regulations by enabling the removal of sensitive information upon request. However, this solution is not foolproof. The involvement of multiple parties creates new attack surfaces, and residual traces of deleted data can still remain in the unlearned graph neural networks (GNNs). These vulnerabilities can be exploited by attackers to recover the supposedly erased samples, thereby undermining the intended functionality of graph unlearning. In this work, we propose GraphToxin, the first full graph reconstruction attack against graph unlearning. Specifically, we introduce a novel curvature matching module to provide fine-grained guidance for unlearned graph recovery. We demonstrate that GraphToxin can successfully subvert the regulatory guarantees expected from graph unlearning, it can recover not only a deleted individual's information and personal links but also sensitive content from their connections, thereby posing substantially more detrimental threats. Furthermore, we extend GraphToxin to multiple-node removal under both white-box and black-box settings, showcasing its practical feasibility and potential to cause considerable harm. We highlight the necessity of worst-case analysis and propose a systematic evaluation framework to assess attack performance under both random and worst-case node removal scenarios. Our extensive experiments demonstrate the effectiveness and flexibility of GraphToxin. Notably, existing defense mechanisms are largely ineffective against this attack or even amplify its performance in some cases. Given the severe privacy risks posed by GraphToxin, our work underscores the urgent need for more effective and robust defenses.

图神经网络隐私安全去学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。