Disparate Vulnerability in Link Inference Attacks against Graph Neural Networks

Disparate Vulnerability in Link Inference Attacks against Graph Neural Networks
复制标题

DOI:
10.56553/popets-2023-0103
复制
发表时间:
2023-10
期刊:
Proc. Priv. Enhancing Technol.
影响因子:
--
通讯作者:
Da Zhong;Ruotong Yu;Kun Wu;Xiuling Wang;Jun Xu;Wendy Hui Wang
Da Zhong;Ruotong Yu;Kun Wu;Xiuling Wang;Jun Xu;Wendy Hui Wang
中科院分区:
其他
文献类型:
--
作者:
Da Zhong;Ruotong Yu;Kun Wu;Xiuling Wang;Jun Xu;Wendy Hui Wang

文献摘要

相似文献

图神经网络(GNN)已广泛用于各种基于图的应用。最近的研究表明,GNN很容易受到链接级成员推断攻击(LMIA)的攻击,该攻击可以推断给定链接是否包含在GNN模型的训练图中。虽然大多数研究都集中在整个图中链接的隐私脆弱性上,但没有一项研究检查过特定链接子组的隐私风险(例如,LGBT用户之间的链接)。在本文中,我们提出了第一个研究的差距子群脆弱性(DSV)的GNNs对LMIA。首先,通过广泛的实证评估,我们证明了在GNN模型和输入图的各种设置下存在不可忽略的DSV。其次,通过统计和因果分析,我们确定了三个特定的图结构属性的亚组之间的差异作为DSV的根本原因之一。在这三个性质中,子群密度的差异对DSV的影响最大。第三,受因果分析的启发,我们设计了一个新的防御机制FairDefense,以减轻DSV,同时提供对LMIA的保护。在高层次上,在目标模型训练的每次迭代中,FairDefense以给定的概率随机化训练图中边缘的成员资格,旨在减少不同子组密度之间的差距,以减轻DSV。我们的实证结果表明,FairDefense优于现有的防御方法之间的权衡防御和目标模型的准确性。更重要的是,它提供了更好的DSV缓解。
Graph Neural Networks (GNNs) have been widely used in various graph-based applications. Recent studies have shown that GNNs are vulnerable to link-level membership inference attacks (LMIA) which can infer whether a given link was included in the training graph of a GNN model. While most of the studies focus on the privacy vulnerability of the links in the entire graph, none have inspected the privacy risk of specific subgroups of links (e.g., links between LGBT users). In this paper, we present the first study of disparity in subgroup vulnerability (DSV) of GNNs against LMIA. First, with extensive empirical evaluation, we demonstrate the existence of non-negligible DSV under various settings of GNN models and input graphs. Second, by both statistical and causal analysis, we identify the difference between three specific graph structural properties of subgroups as one of the underlying reasons for DSV. Among the three properties, the difference between subgroup density has the largest causal effect on DSV. Third, inspired by the causal analysis, we design a new defense mechanism named FairDefense to mitigate DSV while providing protection against LMIA. At a high level, at each iteration of target model training, FairDefense randomizes the membership of edges in the training graph with a given probability, aiming to reduce the gap between the density of different subgroups for DSV mitigation. Our empirical results demonstrate that FairDefense outperforms the existing defense methods in the trade-off between defense and target model accuracy. More importantly, it offers better DSV mitigation.