提出贝叶斯隐私框架,精准评估图神经网络中节点的隐私泄露风险。
Bayesian Membership Privacy for Graph Neural Networks

- 基于贝叶斯假设检验,引入节点依赖先验与采样概率建模
- 通过后验概率量化节点级隐私泄露,揭示全局准确率忽略的细粒度风险
- 可实用审计机制,适用于有采样过程的图模型隐私评估
现有图神经网络(GNN)隐私分析大多沿用非图场景假设,忽略了结构相关性和随机训练图采样问题。特别是,节点依赖先验使得仅靠类型Ⅰ和Ⅱ错误无法充分刻画最优成员推断测试。为此,本文提出贝叶斯成员隐私(BMP),一种考虑采样过程的节点级隐私形式,将节点先验和图采样概率纳入攻击者知识范畴。BMP 将成员推断视为贝叶斯假设检验,并以后验成员概率衡量隐私泄露程度。我们研究了 BMP 与文献中已有定义的理论关联,并提出一种实用的、采样感知的审计机制,用于估计 BMP 参数以衡量 GNN 中的节点级隐私泄漏。在基准图数据集上的实验表明,BMP 能提供全局攻击准确率无法揭示的精细隐私洞察。
原文摘要 · Abstract (English)
Existing privacy analyses for Graph Neural Networks (GNNs) largely inherit assumptions from non-graph settings, overlooking structural correlations and stochastic training-graph sampling. In particular, node-dependent priors make type-I and type-II errors alone insufficient to characterize the best membership inference test. To address this, we introduce Bayesian Membership Privacy (BMP), a sampling-aware formulation of node-level membership privacy that incorporates node-dependent priors and treats graph sampling probabilities as part of the adversary's knowledge. BMP casts membership inference as a Bayesian hypothesis test and accordingly quantifies membership privacy in terms of posterior membership probability. We explore theoretical properties of BMP in relation to the existing definitions in the literature. We further propose a practical, sampling-aware auditing mechanism to estimate the parameters of BMP as a measure of node-level privacy leakage in GNNs. We conduct experiments on benchmark graph datasets and show that BMP yields fine-grained privacy insights that are not visible through global attack accuracy alone.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。