Stealing Links from Graph Neural Networks

Stealing Links from Graph Neural Networks
复制标题

DOI:
--
复制
发表时间:
2020-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Xinlei He;Jinyuan Jia;M. Backes;N. Gong;Yang Zhang
Xinlei He;Jinyuan Jia;M. Backes;N. Gong;Yang Zhang
中科院分区:
其他
文献类型:
--
作者:
Xinlei He;Jinyuan Jia;M. Backes;N. Gong;Yang Zhang

文献摘要

被引文献

相似文献

图形数据(如社交网络和化学网络)包含丰富的信息,可以帮助构建强大的应用程序。为了充分释放图数据的力量,引入了一系列机器学习模型,即图神经网络(GNN)。实证结果表明,GNN在各种任务中都取得了最先进的性能。图数据是GNN成功的关键。高质量的图的收集成本很高,并且通常包含敏感信息,例如社会关系。各种研究表明,机器学习模型很容易受到对其训练数据的攻击。这些模型中的大多数侧重于来自欧几里得空间的数据,例如图像和文本。与此同时,很少有人关注用于训练GNN的图数据的安全和隐私风险。在本文中,我们的目标是填补差距提出的第一个链接窃取攻击图神经网络。给定对GNN模型的黑盒访问,攻击者的目标是推断用于训练模型的图中的任何一对节点之间是否存在链接。我们提出了一个威胁模型,系统地描述对手的背景知识沿着三个维度。通过组合,我们得到了一个全面的分类8种不同的链接窃取攻击。我们提出了多种新颖的方法来实现这些攻击。在8个真实世界数据集上的广泛实验表明,我们的攻击在推断链接方面是有效的,例如,AUC(ROC曲线下面积)在多个病例中高于0.95。
Graph data, such as social networks and chemical networks, contains a wealth of information that can help to build powerful applications. To fully unleash the power of graph data, a family of machine learning models, namely graph neural networks (GNNs), is introduced. Empirical results show that GNNs have achieved state-of-the-art performance in various tasks. Graph data is the key to the success of GNNs. High-quality graph is expensive to collect and often contains sensitive information, such as social relations. Various research has shown that machine learning models are vulnerable to attacks against their training data. Most of these models focus on data from the Euclidean space, such as images and texts. Meanwhile, little attention has been paid to the security and privacy risks of graph data used to train GNNs. In this paper, we aim at filling the gap by proposing the first link stealing attacks against graph neural networks. Given a black-box access to a GNN model, the goal of an adversary is to infer whether there exists a link between any pair of nodes in the graph used to train the model. We propose a threat model to systematically characterize the adversary's background knowledge along three dimensions. By combination, we obtain a comprehensive taxonomy of 8 different link stealing attacks. We propose multiple novel methods to realize these attacks. Extensive experiments over 8 real-world datasets show that our attacks are effective at inferring links, e.g., AUC (area under the ROC curve) is above 0.95 in multiple cases.