通过调整节点特征与结构,有效隐藏图神经网络中的敏感社区
Community Concealment from Graph Neural Networks
- 结合结构与特征信息,重构关键边并优化节点属性
- 在真实社交与比特币网络中显著降低社区可识别性
- 适合保护隐私的图数据发布与安全建模场景
图神经网络(GNN)能高效无监督地发现社区结构,但可能无意暴露敏感群体关系、聚集模式或集体行为,引发群组级隐私风险。在社交网络与关键基础设施中,未授权的社区推断可能揭示协同资产组合、运营层级和系统依赖,易被用于侦察或画像。本文研究防御场景:网络运营商希望隐藏特定社区,同时仅做小幅度、保用的修改。分析表明,社区隐蔽性取决于两个可测量因素:社区边界连接度及目标社区与其邻居的特征相似性。基于此,提出特征-社区引导的DICE(FCom-DICE),在原有DICE(Disconnect Internally Connect Externally)基础上,重连一组结构性关键边,并调整节点特征以削弱GNN消息传递所利用的区分性。在合成基准及真实网络(如Facebook、Wikipedia、比特币交易图)上,FCom-DICE在相同扰动预算下持续优于仅改结构的DICE。对与外部弱连接且特征空间分离明显的社区,改进最为显著。该方法在保持原始网络结构与特征核心特性的前提下,有效降低了目标社区被GNN推断出的可能性。
原文摘要 · Abstract (English)
Graph neural networks (GNNs) enable powerful unsupervised learning of communities. However, such inference may inadvertently expose sensitive group structures, critical clustered patterns, or collective behaviors, raising concerns about sensitive group-level privacy. In social and critical infrastructure networks, unauthorized community inference can reveal coordinated asset groups, operational hierarchies, and system dependencies that may be exploited for reconnaissance or profiling. We study a defensive setting in which a network (or defender) operator seeks to conceal a community of interest while making only small, utility-preserving modifications to the network. Our analysis shows that community concealment depends on two measurable factors: the connectivity at the community boundary and the feature similarity between the protected community and its neighbors. Guided by these observations, we introduce Feature-Community-guided DICE (FCom-DICE), a perturbation strategy built on DICE (Disconnect Internally Connect Externally) that rewires a set of structurally influential edges and adjusts node features to reduce the distinctiveness exploited by GNN message passing. Across synthetic benchmarks and real network graphs such as Facebook, Wikipedia, and Bitcoin Transactions, FCom-DICE consistently outperforms structure-only DICE under the same perturbation budgets. The largest improvements are observed for communities that are weakly connected to the rest of the network and well separated in feature space. These gains are achieved while preserving key structural and feature characteristics of the original network. These results demonstrate the effectiveness of feature-aware perturbations for reducing the recoverability of targeted communities under GNN-based community inference.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。