arXiv:2603.20746cs.LGcs.CR2026-03

研究隐私保护图神经网络的对抗攻击,揭示隐私与安全的权衡关系。

Adversarial Attacks on Locally Private Graph Neural Networks

  • 分析本地差分隐私下图神经网络的对抗攻击方法
  • 发现隐私保护会削弱部分攻击效果但引入新挑战
  • 为隐私安全的图学习架构设计提供方向

图神经网络(GNN)是分析图结构数据的强大工具,但其对对抗攻击的脆弱性引发担忧,尤其在处理敏感信息时。本地差分隐私(LDP)为训练GNN提供了隐私保护框架,但其对对抗鲁棒性的影响尚不明确。本文研究了受LDP保护的GNN面临的对抗攻击问题,探讨了LDP的隐私保障如何被对抗扰动利用或削弱。分析了现有攻击方法在LDP保护下的有效性,并讨论了在LDP约束下生成对抗样本的潜在挑战。此外,提出了防御受LDP保护的GNN免受对抗攻击的方向。该工作揭示了图学习中隐私与安全的相互作用,强调了构建兼具鲁棒性与隐私保护的GNN架构的必要性。

原文摘要 · Abstract (English)

Graph neural network (GNN) is a powerful tool for analyzing graph-structured data. However, their vulnerability to adversarial attacks raises serious concerns, especially when dealing with sensitive information. Local Differential Privacy (LDP) offers a privacy-preserving framework for training GNNs, but its impact on adversarial robustness remains underexplored. This paper investigates adversarial attacks on LDP-protected GNNs. We explore how the privacy guarantees of LDP can be leveraged or hindered by adversarial perturbations. The effectiveness of existing attack methods on LDP-protected GNNs are analyzed and potential challenges in crafting adversarial examples under LDP constraints are discussed. Additionally, we suggest directions for defending LDP-protected GNNs against adversarial attacks. This work investigates the interplay between privacy and security in graph learning, highlighting the need for robust and privacy-preserving GNN architectures.

图神经网络对抗攻击隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。