Saved in:
Bibliographic Details
Main Authors: Shen, Bolin, Seraj, Md Shamim, Cheng, Zhan, Chakraborty, Shayok, Dong, Yushun
Format: Preprint
Published: 2026
Subjects:
Online Access:https://arxiv.org/abs/2602.20418
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911464264040448
author Shen, Bolin
Seraj, Md Shamim
Cheng, Zhan
Chakraborty, Shayok
Dong, Yushun
author_facet Shen, Bolin
Seraj, Md Shamim
Cheng, Zhan
Chakraborty, Shayok
Dong, Yushun
contents Graph neural networks (GNNs) have demonstrated superior performance in various applications, such as recommendation systems and financial risk management. However, deploying large-scale GNN models locally is particularly challenging for users, as it requires significant computational resources and extensive property data. Consequently, Machine Learning as a Service (MLaaS) has become increasingly popular, offering a convenient way to deploy and access various models, including GNNs. However, an emerging threat known as Model Extraction Attacks (MEAs) presents significant risks, as adversaries can readily obtain surrogate GNN models exhibiting similar functionality. Specifically, attackers repeatedly query the target model using subgraph inputs to collect corresponding responses. These input-output pairs are subsequently utilized to train their own surrogate models at minimal cost. Many techniques have been proposed to defend against MEAs, but most are limited to specific output levels (e.g., embedding or label) and suffer from inherent technical drawbacks. To address these limitations, we propose a novel ownership verification framework CITED which is a first-of-its-kind method to achieve ownership verification on both embedding and label levels. Moreover, CITED is a novel signature-based method that neither harms downstream performance nor introduces auxiliary models that reduce efficiency, while still outperforming all watermarking and fingerprinting approaches. Extensive experiments demonstrate the effectiveness and robustness of our CITED framework. Code is available at: https://github.com/LabRAI/CITED.
format Preprint
id arxiv_https___arxiv_org_abs_2602_20418
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle CITED: A Decision Boundary-Aware Signature for GNNs Towards Model Extraction Defense
Shen, Bolin
Seraj, Md Shamim
Cheng, Zhan
Chakraborty, Shayok
Dong, Yushun
Machine Learning
Graph neural networks (GNNs) have demonstrated superior performance in various applications, such as recommendation systems and financial risk management. However, deploying large-scale GNN models locally is particularly challenging for users, as it requires significant computational resources and extensive property data. Consequently, Machine Learning as a Service (MLaaS) has become increasingly popular, offering a convenient way to deploy and access various models, including GNNs. However, an emerging threat known as Model Extraction Attacks (MEAs) presents significant risks, as adversaries can readily obtain surrogate GNN models exhibiting similar functionality. Specifically, attackers repeatedly query the target model using subgraph inputs to collect corresponding responses. These input-output pairs are subsequently utilized to train their own surrogate models at minimal cost. Many techniques have been proposed to defend against MEAs, but most are limited to specific output levels (e.g., embedding or label) and suffer from inherent technical drawbacks. To address these limitations, we propose a novel ownership verification framework CITED which is a first-of-its-kind method to achieve ownership verification on both embedding and label levels. Moreover, CITED is a novel signature-based method that neither harms downstream performance nor introduces auxiliary models that reduce efficiency, while still outperforming all watermarking and fingerprinting approaches. Extensive experiments demonstrate the effectiveness and robustness of our CITED framework. Code is available at: https://github.com/LabRAI/CITED.
title CITED: A Decision Boundary-Aware Signature for GNNs Towards Model Extraction Defense
topic Machine Learning
url https://arxiv.org/abs/2602.20418