Privacy-Enhanced Federated GNN Inference Against Adversarial Example Attack

Guanghui He,Yanli Ren,Jingyuan Jiang,Guorui Feng,Xinpeng Zhang
DOI: https://doi.org/10.1109/tetci.2024.3502434
2024-01-01
IEEE Transactions on Emerging Topics in Computational Intelligence
Abstract:Graph neural networks (GNNs) have become a powerful tool for processing and learning graph data. However, due to the existence of data silos, the privacy of data and the processing result is an important concern. Meanwhile, the malicious example will result in the incorrect output of the model. For the above concerns, this paper proposes privacy-enhanced federated graph network inference against adversarial example attack. Specifically, we adopt secret sharing and homomorphic encryption to ensure the privacy of graph data, where the user can get the final inference, and the server holds nothing except the model parameters. Moreover, in order to prevent malicious users from interfering with the accuracy of the model, an adversarial example detection mechanism on the ciphertext is designed to identify local embedding submitted by malicious users. During the whole process, both local and global embedding are both protected. The experimental results show that the model accuracy is about 69% and 66% with malicious samples on Cora and Citeseer in the domain of ciphertext respectively and they are nearly same as 70% and 69% in the domain of plaintext, which shows the effectiveness of our protocol.
What problem does this paper attempt to address?