Group Property Inference Attacks Against Graph Neural Networks

Group Property Inference Attacks Against Graph Neural Networks
复制标题

DOI:
10.1145/3548606.3560662
复制
发表时间:
2022-09
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Xiuling Wang;Wendy Hui Wang
Xiuling Wang;Wendy Hui Wang
中科院分区:
其他
文献类型:
--
作者:
Xiuling Wang;Wendy Hui Wang

文献摘要

被引文献

相似文献

最近的研究表明,机器学习(ML)模型容易受到隐私攻击,这些攻击会泄露有关训练数据的信息。在这项工作中,我们以图神经网络(GNN)为目标模型,重点研究了一种特殊类型的隐私攻击--属性推理攻击(PIA),它通过访问图神经网络来推断训练图的敏感属性。虽然现有的工作已经针对图级属性(例如节点度和图密度)来研究PIA,但我们是第一个对群属性推理攻击(GPIA)进行系统研究的,所述群属性推断攻击(GPIA)推断特定的节点组和链接在训练图中的分布(例如,男性节点之间的链接比女性节点之间的链接更多)。首先,我们考虑了具有不同类型对手知识的威胁模型的分类,并针对这些设置设计了六种不同的攻击。其次,我们通过在三个具有代表性的GNN模型和三个真实世界图上的大量实验证明了这些攻击的有效性。第三,我们分析了导致GPIA成功的潜在因素,并证明了在有或没有目标属性的图上训练的GNN模型在模型参数和/或模型输出上表现出一些不同,这使得对手能够推断该属性的存在。在此基础上,设计了一套针对GPIA攻击的防御机制,并通过实验证明,这些机制能够在较小损失GNN模型精度的情况下有效降低攻击准确率。
Recent research has shown that machine learning (ML) models are vulnerable to privacy attacks that leak information about the training data. In this work, we consider Graph Neural Networks (GNNs) as the target model, and focus on a particular type of privacy attack named property inference attack (PIA) which infers the sensitive properties of the training graph through the access to GNNs. While the existing work has investigated PIAs against graph-level properties (e.g., node degree and graph density), we are the first to perform a systematic study of the group property inference attacks (GPIAs) that infer the distribution of particular groups of nodes and links (e.g., there are more links between male nodes than those between female nodes) in the training graph. First, we consider a taxonomy of threat models with various types of adversary knowledge, and design six different attacks for these settings. Second, we demonstrate the effectiveness of these attacks through extensive experiments on three representative GNN models and three real-world graphs. Third, we analyze the underlying factors that contribute to GPIA's success, and show that the GNN model trained on the graphs with or without the target property represents some dissimilarity in model parameters and/or model outputs, which enables the adversary to infer the existence of the property. Further, we design a set of defense mechanisms against the GPIA attacks, and demonstrate empirically that these mechanisms can reduce attack accuracy effectively with small loss on GNN model accuracy.