Stealing Training Graphs from Graph Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lin, Minhua, Dai, Enyan, Xu, Junjie, Jia, Jinyuan, Zhang, Xiang, Wang, Suhang
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916755994050560
author Lin, Minhua
Dai, Enyan
Xu, Junjie
Jia, Jinyuan
Zhang, Xiang
Wang, Suhang
author_facet Lin, Minhua
Dai, Enyan
Xu, Junjie
Jia, Jinyuan
Zhang, Xiang
Wang, Suhang
contents Graph Neural Networks (GNNs) have shown promising results in modeling graphs in various tasks. The training of GNNs, especially on specialized tasks such as bioinformatics, demands extensive expert annotations, which are expensive and usually contain sensitive information of data providers. The trained GNN models are often shared for deployment in the real world. As neural networks can memorize the training samples, the model parameters of GNNs have a high risk of leaking private training data. Our theoretical analysis shows the strong connections between trained GNN parameters and the training graphs used, confirming the training graph leakage issue. However, explorations into training data leakage from trained GNNs are rather limited. Therefore, we investigate a novel problem of stealing graphs from trained GNNs. To obtain high-quality graphs that resemble the target training set, a graph diffusion model with diffusion noise optimization is deployed as a graph generator. Furthermore, we propose a selection method that effectively leverages GNN model parameters to identify training graphs from samples generated by the graph diffusion model. Extensive experiments on real-world datasets demonstrate the effectiveness of the proposed framework in stealing training graphs from the trained GNN.
format Preprint
id arxiv_https___arxiv_org_abs_2411_11197
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Stealing Training Graphs from Graph Neural Networks
Lin, Minhua
Dai, Enyan
Xu, Junjie
Jia, Jinyuan
Zhang, Xiang
Wang, Suhang
Machine Learning
Cryptography and Security
Graph Neural Networks (GNNs) have shown promising results in modeling graphs in various tasks. The training of GNNs, especially on specialized tasks such as bioinformatics, demands extensive expert annotations, which are expensive and usually contain sensitive information of data providers. The trained GNN models are often shared for deployment in the real world. As neural networks can memorize the training samples, the model parameters of GNNs have a high risk of leaking private training data. Our theoretical analysis shows the strong connections between trained GNN parameters and the training graphs used, confirming the training graph leakage issue. However, explorations into training data leakage from trained GNNs are rather limited. Therefore, we investigate a novel problem of stealing graphs from trained GNNs. To obtain high-quality graphs that resemble the target training set, a graph diffusion model with diffusion noise optimization is deployed as a graph generator. Furthermore, we propose a selection method that effectively leverages GNN model parameters to identify training graphs from samples generated by the graph diffusion model. Extensive experiments on real-world datasets demonstrate the effectiveness of the proposed framework in stealing training graphs from the trained GNN.
title Stealing Training Graphs from Graph Neural Networks
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2411.11197