{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/can-graph-neural-networks-expose-training","title":"Can Graph Neural Networks Expose Training Data Properties? An Efficient Risk Assessment Approach","arxiv_id":"2411.03663","date":"2024-11-06","proceeding":null,"authors":["Hanyang Yuan","Jiarong Xu","Renhong Huang","Mingli Song","Chunping Wang","Yang Yang"],"abstract":"Graph neural networks (GNNs) have attracted considerable attention due to their diverse applications. However, the scarcity and quality limitations of graph data present challenges to their training process in practical settings. To facilitate the development of effective GNNs, companies and researchers often seek external collaboration. Yet, directly sharing data raises privacy concerns, motivating data owners to train GNNs on their private graphs and share the trained models. Unfortunately, these models may still inadvertently disclose sensitive properties of their training graphs (e.g., average default rate in a transaction network), leading to severe consequences for data owners. In this work, we study graph property inference attack to identify the risk of sensitive property information leakage from shared models. Existing approaches typically train numerous shadow models for developing such attack, which is computationally intensive and impractical. To address this issue, we propose an efficient graph property inference attack by leveraging model approximation techniques. Our method only requires training a small set of models on graphs, while generating a sufficient number of approximated shadow models for attacks. To enhance diversity while reducing errors in the approximated models, we apply edit distance to quantify the diversity within a group of approximated models and introduce a theoretically guaranteed criterion to evaluate each model's error. Subsequently, we propose a novel selection mechanism to ensure that the retained approximated models achieve high diversity and low error. Extensive experiments across six real-world scenarios demonstrate our method's substantial improvement, with average increases of 2.7% in attack accuracy and 4.1% in ROC-AUC, while being 6.5$\\times$ faster compared to the best baseline.","url_abs":"https://arxiv.org/abs/2411.03663v1","url_pdf":"https://arxiv.org/pdf/2411.03663v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"can-graph-neural-networks-expose-training","repo_url":"https://github.com/zjunet/GPIA_NIPS","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"diversity","task_name":"Diversity"},{"task_slug":"inference-attack","task_name":"Inference Attack"}],"methods":[{"method_slug":"attention","method_name":"Attention"},{"method_slug":"set","method_name":"SET"},{"method_slug":"softmax","method_name":"Softmax"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2411.03663","atlas_url":"https://app.syntology.ai/?focus=2411.03663","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2411.03663"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/zjunet/GPIA_NIPS","reach":null}],"summary":{"ran_draft_wrong":3,"ran_fixture":1},"by_repo_kind":{"official":{"samples":4,"ran":4,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":4,"samples":[{"code_sha256_prefix":"3f3cfab762d4e200","entry":"_autograd_grad","repo":"zjunet/GPIA_NIPS","repo_kind":"official","path":"utils/cg.py","file_url":"https://github.com/zjunet/GPIA_NIPS/blob/HEAD/utils/cg.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"3f3cfab762d4e200"}},{"code_sha256_prefix":"c08b2333b2512f6c","entry":"_fill_in_zeros","repo":"zjunet/GPIA_NIPS","repo_kind":"official","path":"utils/cg.py","file_url":"https://github.com/zjunet/GPIA_NIPS/blob/HEAD/utils/cg.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"c08b2333b2512f6c"}},{"code_sha256_prefix":"44fb24478c2316e8","entry":"_grad_postprocess","repo":"zjunet/GPIA_NIPS","repo_kind":"official","path":"utils/cg.py","file_url":"https://github.com/zjunet/GPIA_NIPS/blob/HEAD/utils/cg.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"44fb24478c2316e8"}},{"code_sha256_prefix":"768462724bfa006f","entry":"hessian_vector_product","repo":"zjunet/GPIA_NIPS","repo_kind":"official","path":"utils/cg.py","file_url":"https://github.com/zjunet/GPIA_NIPS/blob/HEAD/utils/cg.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"768462724bfa006f"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}