无需查询即可从公开图数据中推断多个敏感属性,突破传统攻击假设。
Taipan: A Query-free Transfer-based Multiple Sensitive Attribute Inference Attack Solely from Publicly Released Graphs
- 基于图结构的迁移学习,不依赖模型查询即可实现多属性推理。
- 在真实图数据集上攻破率超90%,跨分布场景仍保持高精度。
- 适合隐私安全研究者、图数据发布方及合规审查人员参考。
图结构数据支撑了众多现代应用,但复杂的拓扑和同质性模式可能使敏感信息通过局部邻居传播,导致属性泄露。现有属性推理攻击(AIAs)通常假设攻击者可通过反复查询模型获取敏感信息,但在实际中受限于数据保护法规、高昂查询成本和检测风险,尤其在多属性推理时更难实现。更重要的是,这种以模型为中心的视角忽略了关键盲点:仅从公开发布的图中就存在内在的多重敏感信息泄露。为此,我们提出全新攻击范式,构建首个无查询的基于迁移的图多敏感属性推理攻击框架——Taipan。Taipan融合层次化攻击知识路由以捕捉复杂属性关联,并采用提示引导的攻击原型精炼机制缓解负迁移与性能下降。我们还设计了专门针对图多敏感属性推理攻击的评估框架。在多种真实世界图数据集上的实验表明,Taipan在同分布、异分布及特征维度不匹配场景下均表现强劲,且在严格的差分隐私保护下仍有效。研究揭示了亟需更强大的多属性隐私保护图发布方法与数据共享实践。
原文摘要 · Abstract (English)
Graph-structured data underpin a wide spectrum of modern applications. However, complex graph topologies and homophilic patterns can facilitate attribute inference attacks (AIAs) by enabling sensitive information leakage to propagate across local neighborhoods. Existing AIAs predominantly assume that adversaries can probe sensitive attributes through repeated model queries. Such assumptions are often impractical in real-world settings due to stringent data protection regulations, prohibitive query budgets, and heightened detection risks, especially when inferring multiple sensitive attributes. More critically, this model-centric perspective obscures a pervasive blind spot: \textbf{intrinsic multiple sensitive information leakage arising solely from publicly released graphs.} To exploit this unexplored vulnerability, we introduce a new attack paradigm and propose \textbf{Taipan, the first query-free transfer-based attack framework for multiple sensitive attribute inference attacks on graphs (G-MSAIAs).} Taipan integrates \emph{Hierarchical Attack Knowledge Routing} to capture intricate inter-attribute correlations, and \emph{Prompt-guided Attack Prototype Refinement} to mitigate negative transfer and performance degradation. We further present a systematic evaluation framework tailored to G-MSAIAs. Extensive experiments on diverse real-world graph datasets demonstrate that Taipan consistently achieves strong attack performance across same-distribution settings and heterogeneous similar- and out-of-distribution settings with mismatched feature dimensionalities, and remains effective even under rigorous differential privacy guarantees. Our findings underscore the urgent need for more robust multi-attribute privacy-preserving graph publishing methods and data-sharing practices.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。