Finding MNEMON: Reviving Memories of Node Embeddings

Finding MNEMON: Reviving Memories of Node Embeddings
复制标题

DOI:
10.1145/3548606.3559358
复制
发表时间:
2022-04
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Yun Shen;Yufei Han;Zhikun Zhang;Min Chen;Tingyue Yu;Michael Backes;Yang Zhang;G. Stringhini
Yun Shen;Yufei Han;Zhikun Zhang;Min Chen;Tingyue Yu;Michael Backes;Yang Zhang;G. Stringhini
中科院分区:
其他
文献类型:
--
作者:
Yun Shen;Yufei Han;Zhikun Zhang;Min Chen;Tingyue Yu;Michael Backes;Yang Zhang;G. Stringhini

文献摘要

相似文献

以前围绕图的安全研究工作一直专注于图的(去)匿名化或理解图神经网络的安全和隐私问题。很少有人注意到集成图嵌入模型的输出的隐私风险(例如,节点嵌入)与复杂的下游机器学习管道。在本文中,我们填补了这一空白,并提出了一种新的模型无关的图恢复攻击,利用隐式图结构信息保留在嵌入的图形节点。我们表明,对手可以恢复边缘与体面的准确性,只获得访问原始图的节点嵌入矩阵,而不与节点嵌入模型的相互作用。我们通过大量的实验证明了我们的图恢复攻击的有效性和适用性。
Previous security research efforts orbiting around graphs have been exclusively focusing on either (de-)anonymizing the graphs or understanding the security and privacy issues of graph neural networks. Little attention has been paid to understand the privacy risks of integrating the output from graph embedding models (e.g., node embeddings) with complex downstream machine learning pipelines. In this paper, we fill this gap and propose a novel model-agnostic graph recovery attack that exploits the implicit graph structural information preserved in the embeddings of graph nodes. We show that an adversary can recover edges with decent accuracy by only gaining access to the node embedding matrix of the original graph without interactions with the node embedding models. We demonstrate the effectiveness and applicability of our graph recovery attack through extensive experiments.