GraphTheft: Quantifying Privacy Risks in Graph Prompt Learning
Jiani Zhu, Xi Lin, Yuxin Qi, Qinghua Mao, Jun Wu · IEEE Transactions on Dependable and Secure Computing · 2026
Graph Prompt Learning (GPL) represents an innovative approach in graph representation learning, enabling task-specific adaptations by fine-tuning prompts without altering the underlying pre-trained model. Despite its growing prominence, the privacy risks inherent in GPL remain unexplored. In this study, we provide the first evaluation of privacy leakage in GPL across three attacker capabilities: black-box attacks when GPL as a service, and scenarios where node embeddings and prompt representations are accessible to third parties. We assess GPL's privacy vulnerabilities through Attribute Inference Attacks (AIAs) and Link Inference Attacks (LIAs), finding that under any capability, attackers can effectively infer the properties and relationships of sensitive nodes, and the success rate of inference on some data sets is as high as 98%. Importantly, while targeted inference attacks on specific prompts (e.g., GPF-plus) maintain high success rates, our analysis suggests that the prompt-tuning in GPL does not significantly elevate privacy risks compared to traditional GNNs. To mitigate these risks, we explored several typical differential privacy techniques, including DP-Aggregation, DP-SGD on prompt gradients, and Gaussian embedding noise, offering guidance for the privacy-utility trade-off in DP-GPL. This work highlights key privacy vulnerabilities in GPL and provides novel insights and foundational directions for future privacy-preserving strategies in graph learning.