Link Membership Inference Attacks against Unsupervised Graph Representation Learning

Link Membership Inference Attacks against Unsupervised Graph Representation Learning
复制标题

DOI:
10.1145/3627106.3627115
复制
发表时间:
2023-12
期刊:
Proceedings of the 39th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Xiuling Wang;Wendy Hui Wang
Xiuling Wang;Wendy Hui Wang
中科院分区:
其他
文献类型:
--
作者:
Xiuling Wang;Wendy Hui Wang

文献摘要

相似文献

近年来,在无监督图表示学习(UGRL)方法领域取得了重大进展。UGRL涉及将大型图形表示为低维向量,通常称为嵌入。这些嵌入可以公开发布,也可以与第三方共享以进行下游分析。然而,攻击者可以利用各种类型的隐私推理攻击,通过嵌入目标图来推断目标图中的敏感结构信息。从链接成员关系推理攻击(LMIA)的角度研究了UGRL模型的隐私漏洞。具体地说,LMIA攻击者的目标是从UGRL模型生成的节点嵌入中推断目标图中是否有任何两个节点相连。为了实现这一点,我们提出了两种LMIA攻击,它们利用节点嵌入的特性和各种形式的对手知识进行推理。通过使用五个真实图形数据集在四个最新的UGRL模型上进行实验,我们证明了两种LMIA攻击对这些UGRL模型的有效性。此外,我们还进行了全面的分析,以考察嵌入中不同程度保留的结构信息对LMIA性能的影响。为了提高UGRL模型对抗LMIA的安全性,我们设计了一系列干扰嵌入最低有效维度的防御机制。实验结果表明,我们的防御机制在防御效果和嵌入质量之间取得了良好的平衡。
Significant advancements have been made in recent years in the field of unsupervised graph representation learning (UGRL) approaches. UGRL involves representing large graphs as low-dimensional vectors, commonly referred to as embeddings. These embeddings can be publicly released or shared with third parties for downstream analytics. However, adversaries can deduce sensitive structural information from the target graph through its embedding using various types of privacy inference attacks. This paper investigates the privacy vulnerabilities of UGRL models through the lens of link membership inference attack (LMIA). Specifically, an LMIA adversary aims to infer whether any two nodes are connected in the target graph from the node embeddings generated by a UGRL model. To achieve this, we propose two LMIA attacks that leverage the properties of node embeddings and various forms of adversary knowledge for inference. By conducting experiments on four state-of-the-art UGRL models using five real-world graph datasets, we demonstrate the effectiveness of the two LMIA attacks against these UGRL models. Furthermore, we conduct a comprehensive analysis to examine how varying degrees of preserved structural information in the embeddings impact the performance of LMIA. To enhance the security of UGRL models against LMIA, we design a family of defense mechanisms that perturb the least significant dimensions of embeddings. Our experimental results show that our defense mechanism achieves a favorable balance between defense effectiveness and embedding quality.