Model Inversion Attacks on Homogeneous and Heterogeneous Graph Neural Networks

被引:0
|
作者
Liu, Renyang [1 ]
Zhou, Wei [1 ]
Zhang, Jinhong [1 ]
Liu, Xiaoyuan [2 ]
Si, Peiyuan [3 ]
Li, Haoran [1 ]
机构
[1] Yunnan Univ, Kunming, Yunnan, Peoples R China
[2] Univ Elect Sci & Technol China, Chengdu, Sichuan, Peoples R China
[3] Nanyang Technol Univ, Singapore, Singapore
来源
SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, PT I, SECURECOMM 2023 | 2025年 / 567卷
基金
中国国家自然科学基金;
关键词
Model Inversion Attack; Adversarial Attack; Graph Neural Network; Graph Representation Learning; Network Communication;
D O I
10.1007/978-3-031-64948-6_7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, Graph Neural Networks (GNNs), including Homogeneous Graph Neural Networks (HomoGNNs) and Heterogeneous Graph Neural Networks (HeteGNNs), have made remarkable progress in many physical scenarios, especially in communication applications. Despite achieving great success, the privacy issue of such models has also received considerable attention. Previous studies have shown that given a well-fitted target GNN, the attacker can reconstruct the sensitive training graph of this model via model inversion attacks, leading to significant privacy worries for the AI service provider. We advocate that the vulnerability comes from the target GNN itself and the prior knowledge about the shared properties in real-world graphs. Inspired by this, we propose a novel model inversion attack method on HomoGNNs and HeteGNNs, namely HomoGMI and HeteGMI. Specifically, HomoGMI and HeteGMI are gradient-descent-based optimization methods that aim to maximize the cross-entropy loss on the target GNN and the 1(st) and 2(nd)-order proximities on the reconstructed graph. Notably, to the best of our knowledge, HeteGMI is the first attempt to perform model inversion attacks on HeteGNNs. Extensive experiments on multiple benchmarks demonstrate that the proposed method can achieve better performance than the competitors.
引用
收藏
页码:125 / 144
页数:20
相关论文
共 50 条
  • [21] Heterogeneous Graph Neural Networks for Keyphrase Generation
    Ye, Jiacheng
    Cai, Ruijian
    Gui, Tao
    Zhang, Qi
    2021 CONFERENCE ON EMPIRICAL METHODS IN NATURAL LANGUAGE PROCESSING (EMNLP 2021), 2021, : 2705 - 2715
  • [22] Adversarial Attacks on Graph Neural Networks: Perturbations and their Patterns
    Zuegner, Daniel
    Borchert, Oliver
    Akbarnejad, Amir
    Guennemann, Stephan
    ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2020, 14 (05)
  • [23] TDGIA: Effective Injection Attacks on Graph Neural Networks
    Zou, Xu
    Zheng, Qinkai
    Dong, Yuxiao
    Guan, Xinyu
    Kharlamov, Evgeny
    Lu, Jialiang
    Tang, Jie
    KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 2461 - 2471
  • [24] Watermarking Graph Neural Networks based on Backdoor Attacks
    Xu, Jing
    Koffas, Stefanos
    Ersoy, Oguzhan
    Picek, Stjepan
    2023 IEEE 8TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, EUROS&P, 2023, : 1179 - 1197
  • [25] Explanatory subgraph attacks against Graph Neural Networks
    Wang, Huiwei
    Liu, Tianhua
    Sheng, Ziyu
    Li, Huaqing
    NEURAL NETWORKS, 2024, 172
  • [26] A Survey on Privacy Attacks and Defenses in Graph Neural Networks
    Luo, Lanhua
    Ren, Wang
    Huang, Huasheng
    Wang, Fengling
    INFORMATION TECHNOLOGY AND CONTROL, 2024, 53 (04):
  • [27] DiffMG: Differentiable Meta Graph Search for Heterogeneous Graph Neural Networks
    Ding, Yuhui
    Yao, Quanming
    Zhao, Huan
    Zhang, Tong
    KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 279 - 288
  • [28] Aspect sentiment analysis with heterogeneous graph neural networks
    Lu, Guangquan
    Li, Jiecheng
    Wei, Jian
    INFORMATION PROCESSING & MANAGEMENT, 2022, 59 (04)
  • [29] Poincare Heterogeneous Graph Neural Networks for Sequential Recommendation
    Guo, Naicheng
    Liu, Xiaolei
    Li, Shaoshuai
    Ma, Qiongxu
    Gao, Kaixin
    Han, Bing
    Zheng, Lin
    Guo, Sheng
    Guo, Xiaobo
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2023, 41 (03)
  • [30] Distance Information Improves Heterogeneous Graph Neural Networks
    Shi, Chuan
    Ji, Houye
    Lu, Zhiyuan
    Tang, Ye
    Li, Pan
    Yang, Cheng
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (03) : 1030 - 1043