How Powerful are Membership Inference Attacks on Graph Neural Networks?

Abdellah Jnaini, Afafe Bettar, Mohammed Amine Koulali · 2022

Graph Neural Networks (GNNs) are Machine Learning models that operate on structured graph data. By leveraging their node/graphs classification and link prediction capabilities, they have been successfully applied in several domains such as community detection, drug discovery, and location sharing services. These successful applications and the immense availability of graphs in various fields have encouraged the adoption of GNNs in Privacy sensitive contexts (e.g., Healthcare and banking systems). Unfortunately, GNNs are prone to sensitive information leakage through principled attacks. Our focus is on Membership Inference Attacks(MIAs) that allow an adversary to infer the membership of a given sample to the training dataset. Our work focuses first on performing the MIAs on Graph Neural Networks and devises the impact of the used attack classifier on its success. Then, we propose new defense methods that decrease the accuracy of MIAs to 50% (i.e., random guess). Finally, we support our findings through extensive experiments on four largely used GNN models.

Read the paper · More papers on PaperTik