Watermarking Graph Neural Networks via Explanations for Ownership Protection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Downer, Jane, Shi, Yingdan, Liu, Ziyan, Wang, Ren, Wang, Binghui
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913108449034240
author Downer, Jane
Shi, Yingdan
Liu, Ziyan
Wang, Ren
Wang, Binghui
author_facet Downer, Jane
Shi, Yingdan
Liu, Ziyan
Wang, Ren
Wang, Binghui
contents Graph Neural Networks (GNNs) are widely deployed in industry, making their intellectual property valuable. However, protecting GNNs from unauthorized use remains a challenge. Watermarking offers a solution by embedding ownership information into models. Existing watermarking methods have two limitations: First, they rarely focus on graph data or GNNs. Second, the de facto backdoor-based method relies on manipulating training data, which can introduce ownership ambiguity through misclassification and vulnerability to data poisoning attacks that can interrupt the backdoor mechanism. Our explanation-based watermarking inherits the strengths of backdoor-based methods (e.g., black-box verification) without data manipulation, eliminating ownership ambiguity and data dependencies. In particular, we watermark GNN explanations such that these explanations are statistically distinct from others, so ownership claims must be verified through statistical significance. We theoretically prove that, even with full knowledge of our method, locating the watermark is NP-hard. Empirically, our method demonstrates robustness to fine-tuning and pruning attacks. By addressing these challenges, our approach significantly advances GNN intellectual property protection.
format Preprint
id arxiv_https___arxiv_org_abs_2501_05614
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Watermarking Graph Neural Networks via Explanations for Ownership Protection
Downer, Jane
Shi, Yingdan
Liu, Ziyan
Wang, Ren
Wang, Binghui
Cryptography and Security
Artificial Intelligence
Graph Neural Networks (GNNs) are widely deployed in industry, making their intellectual property valuable. However, protecting GNNs from unauthorized use remains a challenge. Watermarking offers a solution by embedding ownership information into models. Existing watermarking methods have two limitations: First, they rarely focus on graph data or GNNs. Second, the de facto backdoor-based method relies on manipulating training data, which can introduce ownership ambiguity through misclassification and vulnerability to data poisoning attacks that can interrupt the backdoor mechanism. Our explanation-based watermarking inherits the strengths of backdoor-based methods (e.g., black-box verification) without data manipulation, eliminating ownership ambiguity and data dependencies. In particular, we watermark GNN explanations such that these explanations are statistically distinct from others, so ownership claims must be verified through statistical significance. We theoretically prove that, even with full knowledge of our method, locating the watermark is NP-hard. Empirically, our method demonstrates robustness to fine-tuning and pruning attacks. By addressing these challenges, our approach significantly advances GNN intellectual property protection.
title Watermarking Graph Neural Networks via Explanations for Ownership Protection
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2501.05614