Defense against membership inference attack in graph neural networks through graph perturbation

被引:6
|
作者
Wang, Kai [1 ]
Wu, Jinxia [1 ]
Zhu, Tianqing [1 ]
Ren, Wei [1 ]
Hong, Ying [2 ]
机构
[1] China Univ Geosci, Sch Comp Sci, 388 Lumo Rd, Wuhan 430074, Peoples R China
[2] Wuhan Text Univ, Sch Comp Sci & Artificial Intelligence, 1 Sunshine Ave, Wuhan 430200, Peoples R China
关键词
Graph neural network; Graph privacy-preserving; Membership inference attack; Perturbation injection; DEEP LEARNING ARCHITECTURE; PRIVACY;
D O I
10.1007/s10207-022-00646-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Graph neural networks have demonstrated remarkable performance in learning node or graph representations for various graph-related tasks. However, learning with graph data or its embedded representations may induce privacy issues when the node representations contain sensitive or private user information. Although many machine learning models or techniques have been proposed for privacy preservation of traditional non-graph structured data, there is limited work to address graph privacy concerns. In this paper, we investigate the privacy problem of embedding representations of nodes, in which an adversary can infer the user's privacy by designing an inference attack algorithm. To address this problem, we develop a defense algorithm against white-box membership inference attacks, based on perturbation injection on the graph. In particular, we employ a graph reconstruction model and inject a certain size of noise into the intermediate output of the model, i.e., the latent representations of the nodes. The experimental results obtained on real-world datasets, along with reasonable usability and privacy metrics, demonstrate that our proposed approach can effectively resist membership inference attacks. Meanwhile, based on our method, the trade-off between usability and privacy brought by defense measures can be observed intuitively, which provides a reference for subsequent research in the field of graph privacy protection.
引用
收藏
页码:497 / 509
页数:13
相关论文
共 50 条
  • [21] Towards Defense Against Adversarial Attacks on Graph Neural Networks via Calibrated Co-Training
    Xu-Gang Wu
    Hui-Jun Wu
    Xu Zhou
    Xiang Zhao
    Kai Lu
    Journal of Computer Science and Technology, 2022, 37 : 1161 - 1175
  • [22] Practical Membership Inference Attack Against Collaborative Inference in Industrial IoT
    Chen, Hanxiao
    Li, Hongwei
    Dong, Guishan
    Hao, Meng
    Xu, Guowen
    Huang, Xiaoming
    Liu, Zhe
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (01) : 477 - 487
  • [23] Membership Inference Attack Against Principal Component Analysis
    Zari, Oualid
    Parra-Arnau, Javier
    Unsal, Ayse
    Strufe, Thorsten
    Onen, Melek
    PRIVACY IN STATISTICAL DATABASES, PSD 2022, 2022, 13463 : 269 - 282
  • [24] Imbalanced Graph Classification via Graph-of-Graph Neural Networks
    Wang, Yu
    Zhao, Yuying
    Shah, Neil
    Derr, Tyler
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2022, 2022, : 2068 - 2077
  • [25] Leveraging Multiple Adversarial Perturbation Distances for Enhanced Membership Inference Attack in Federated Learning
    Xia, Fan
    Liu, Yuhao
    Jin, Bo
    Yu, Zheng
    Cai, Xingwei
    Li, Hao
    Zha, Zhiyong
    Hou, Dai
    Peng, Kai
    SYMMETRY-BASEL, 2024, 16 (12):
  • [26] GRD-GNN: Graph Reconstruction Defense for Graph Neural Network
    Chen J.
    Huang G.
    Zhang D.
    Zhang X.
    Ji S.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2021, 58 (05): : 1075 - 1091
  • [27] DeGNN: Improving Graph Neural Networks with Graph Decomposition
    Miao, Xupeng
    Gurel, Nezihe Merve
    Zhang, Wentao
    Han, Zhichao
    Li, Bo
    Min, Wei
    Rao, Susie Xi
    Ren, Hansheng
    Shan, Yinan
    Shao, Yingxia
    Wang, Yujie
    Wu, Fan
    Xue, Hui
    Yang, Yaming
    Zhang, Zitao
    Zhao, Yang
    Zhang, Shuai
    Wang, Yujing
    Cui, Bin
    Zhang, Ce
    KDD '21: PROCEEDINGS OF THE 27TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2021, : 1223 - 1233
  • [28] An effective targeted label adversarial attack on graph neural networks by strategically allocating the attack budget
    Cao, Feilong
    Chen, Qiyang
    Ye, Hailiang
    KNOWLEDGE-BASED SYSTEMS, 2024, 293
  • [29] Membership inference attack and defense method in federated learning based on GAN
    Zhang J.
    Zhu C.
    Sun X.
    Chen B.
    Tongxin Xuebao/Journal on Communications, 2023, 44 (05): : 193 - 205
  • [30] Dual-Targeted adversarial example in evasion attack on graph neural networks
    Kwon, Hyun
    Kim, Dae-Jin
    SCIENTIFIC REPORTS, 2025, 15 (01):