EC-LDA : Label Distribution Inference Attack against Federated Graph Learning with Embedding Compression

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cheng, Tong, Fu, Jie, Ling, Xinpeng, Li, Huifa, Chen, Zhili, Qian, Haifeng, Gong, Junqing
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915510282616832
author Cheng, Tong
Fu, Jie
Ling, Xinpeng
Li, Huifa
Chen, Zhili
Qian, Haifeng
Gong, Junqing
author_facet Cheng, Tong
Fu, Jie
Ling, Xinpeng
Li, Huifa
Chen, Zhili
Qian, Haifeng
Gong, Junqing
contents Graph Neural Networks (GNNs) have been widely used for graph analysis. Federated Graph Learning (FGL) is an emerging learning framework to collaboratively train graph data from various clients. Although FGL allows client data to remain localized, a malicious server can still steal client private data information through uploaded gradient. In this paper, we for the first time propose label distribution attacks (LDAs) on FGL that aim to infer the label distributions of the client-side data. Firstly, we observe that the effectiveness of LDA is closely related to the variance of node embeddings in GNNs. Next, we analyze the relation between them and propose a new attack named EC-LDA, which significantly improves the attack effectiveness by compressing node embeddings. Then, extensive experiments on node classification and link prediction tasks across six widely used graph datasets show that EC-LDA outperforms the SOTA LDAs. Specifically, EC-LDA can achieve the Cos-sim as high as 1.0 under almost all cases. Finally, we explore the robustness of EC-LDA under differential privacy protection and discuss the potential effective defense methods to EC-LDA. Our code is available at https://github.com/cheng-t/EC-LDA.
format Preprint
id arxiv_https___arxiv_org_abs_2505_15140
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle EC-LDA : Label Distribution Inference Attack against Federated Graph Learning with Embedding Compression
Cheng, Tong
Fu, Jie
Ling, Xinpeng
Li, Huifa
Chen, Zhili
Qian, Haifeng
Gong, Junqing
Machine Learning
Cryptography and Security
Graph Neural Networks (GNNs) have been widely used for graph analysis. Federated Graph Learning (FGL) is an emerging learning framework to collaboratively train graph data from various clients. Although FGL allows client data to remain localized, a malicious server can still steal client private data information through uploaded gradient. In this paper, we for the first time propose label distribution attacks (LDAs) on FGL that aim to infer the label distributions of the client-side data. Firstly, we observe that the effectiveness of LDA is closely related to the variance of node embeddings in GNNs. Next, we analyze the relation between them and propose a new attack named EC-LDA, which significantly improves the attack effectiveness by compressing node embeddings. Then, extensive experiments on node classification and link prediction tasks across six widely used graph datasets show that EC-LDA outperforms the SOTA LDAs. Specifically, EC-LDA can achieve the Cos-sim as high as 1.0 under almost all cases. Finally, we explore the robustness of EC-LDA under differential privacy protection and discuss the potential effective defense methods to EC-LDA. Our code is available at https://github.com/cheng-t/EC-LDA.
title EC-LDA : Label Distribution Inference Attack against Federated Graph Learning with Embedding Compression
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2505.15140