Membership Inference Attacks Against the Graph Classification

Junze Yang,Hongwei Li,Wenshu Fan,Xilin Zhang,Meng Hao
DOI: https://doi.org/10.1109/globecom54140.2023.10437279
2023-01-01
Abstract:Recently, there has been increasing interest in extending deep learning approaches to graph data. Graph representation learning has become an important way to fully utilize the information contained in graph data. Graph Neural Networks (GNNs) have demonstrated significant efficacy in various fields. Previous studies have shown that traditional machine learning models may lead to disclosure of private data, but the privacy risks of GNNs have not received enough attention. In this paper, we propose two attack methods based on the ground-truth label. Our attack approach covers two mainstream attack patterns, including training attack models based on neural networks and setting thresholds. To improve the effectiveness of attacks, we consider incorporating label information of the samples. Since the samples' distributions of different classes are different, the possibility of privacy leakage cannot be treated equally. In neural network-based attacks, we concatenate the label information into the input vector of the attack model. In threshold-based attacks, we set separate thresholds for each label category. We systematically evaluate the performance of membership inference attacks against graph-level classification. Our evaluation on three GNN structures and four benchmark datasets shows that GNNs for graph classification are more vulnerable to the improved attacks. On the DD dataset, our attack achieved an accuracy of 79%. Furthermore, we proposed two defense mechanisms to mitigate the privacy leakage caused by membership inference attacks.
What problem does this paper attempt to address?