提出两种新攻击方法,可黑盒重建GNN训练的敏感图数据。
Rethinking Generative Reconstruction Attacks against Graph Neural Network Models

- 基于标签条件生成图结构与嵌入表示,实现高精度重构。
- 在三个数据集上成功重建高质量图,攻击性能优于现有方法。
- 适用于研究GNN隐私安全的学者,尤其关注对抗样本与数据泄露。
图数据在多个领域广泛应用,带来海量数据的收集与分析需求,其中部分数据具有隐私性。由于图数据的非欧几里得特性,计算分析复杂,因此在人工智能时代广泛采用图神经网络(GNNs)。然而,GNN可能无意中泄露训练数据,引发严重数据安全问题,如模型逆向攻击。本文引入两种新型图逆向(即重构)攻击:图-标签条件(GLC)攻击和嵌入-标签条件(ELC)攻击,分别利用目标模型预测结果及其中间表示。我们在三个基准图数据集(NCI1、PROTEINS、AIDS)上,通过四种图分布/结构度量(FGD、EGD、MMD、GKS)对所提攻击进行了全面分析,并与现有基线比较。结果表明,攻击者可借助生成器-判别器技术,在真实黑盒场景下重建高质量图。此外,我们提出的改进版本(Ours--)将查询次数减少50%,仍保持良好或相当的重构性能。同时,实验显示GNN对隐私攻击高度脆弱,其脆弱性随拉普拉斯噪声尺度变化而显著波动。
原文摘要 · Abstract (English)
The application of graph data in numerous disciplines raises the need for gathering and analyzing huge volumes of data, some of which is private and sensitive. The non-Euclidean nature of the graph data makes the analysis computationally challenging, leading to the use of Graph Neural Networks (GNNs) in the age of AI. GNNs may inadvertently leak sensitive data they are trained on, which raises serious data security issues, including the model inversion attack. In this study, we analyze GNNs' vulnerabilities by introducing two novel graph inversion (i.e., reconstruction) attacks: graph-label conditioned (GLC) attack and embedding-label conditioned (ELC) attack, utilizing targetmodel predictions and their intermediate representations, respectively. We perform a comprehensive analysis of our introduced privacy attacks and compare them with existing baselines across three benchmark graph datasets (i.e., NCI1, PROTEINS, and AIDS) and four graph distributional/structural metrics (i.e., FGD, EGD, MMD, and GKS). Our work demonstrates that an adversary can use the generator-discriminator technique to reconstruct high-quality graphs in real-world black-box attack scenarios against GNNs. Additionally, we present a variant of our attacks (Ours--) with 50% reduced queries, achieving good or comparable reconstruction attack performance. In addition, we show that GNNs are highly vulnerable to privacy attacks, varying Laplacian noise-scales.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。