CISPA
Browse

File(s) not publicly available

Stealing Links from Graph Neural Networks

conference contribution
posted on 2023-11-29, 18:17 authored by xinlei.he, Jinyuan Jia, Neil Zhenqiang Gong, Michael BackesMichael Backes, Yang ZhangYang Zhang
Graph data, such as chemical networks and social networks, may be deemed confidential/private because the data owner often spends lots of resources collecting the data or the data contains sensitive information, e.g., social relationships. Recently, neural networks were extended to graph data, which are known as graph neural networks (GNNs). Due to their superior performance, GNNs have many applications, such as healthcare analytics, recommender systems, and fraud detection. In this work, we propose the first attacks to steal a graph from the outputs of a GNN model that is trained on the graph. Specifically, given a black-box access to a GNN model, our attacks can infer whether there exists a link between any pair of nodes in the graph used to train the model. We call our attacks link stealing attacks. We propose a threat model to systematically characterize an adversary's background knowledge along three dimensions which in total leads to a comprehensive taxonomy of 8 different link stealing attacks. We propose multiple novel methods to realize these 8 attacks. Extensive experiments on 8 real-world datasets show that our attacks are effective at stealing links, e.g., AUC (area under the ROC curve) is above 0.95 in multiple cases. Our results indicate that the outputs of a GNN model reveal rich information about the structure of the graph used to train the model.

History

Preferred Citation

Xinlei He, Jinyuan Jia, Neil Gong, Michael Backes and Yang Zhang. Stealing Links from Graph Neural Networks. In: Usenix Security Symposium (USENIX-Security). 2021.

Primary Research Area

  • Trustworthy Information Processing

Name of Conference

Usenix Security Symposium (USENIX-Security)

Legacy Posted Date

2021-08-10

Open Access Type

  • Gold

BibTeX

@inproceedings{cispa_all_3461, title = "Stealing Links from Graph Neural Networks", author = "He, Xinlei and Jia, Jinyuan and Gong, Neil Zhenqiang and Backes, Michael and Zhang, Yang", booktitle="{Usenix Security Symposium (USENIX-Security)}", year="2021", }

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC