MPGStack: Membership Privacy Protection on Graph Data via Model Stacking

Chenyang Chen, Xiaoyu Zhang, Shen Lin, Xiaofeng Chen · IEEE Transactions on Dependable and Secure Computing · 2025

Graph neural networks (GNNs) can retain the structural information of graph data when processing graph data via message passing mechanism. Recently, GNNs have been widely used in recommendation systems, social networks, finance, etc. However, GNNs are also vulnerable when encountering severe security and data privacy challenges. Membership inference attacks (MIA) on graph data can make the trained GNN model leak the training data, which causes serious privacy problems. However, all the studies reviewed so far suffer from the fact that there are few types of research on GNNs to defend against MIA. In this paper, we proposeMPGStack: a framework that utilizes ensemble learning of GNNs to safeguard against MIA. More concretely, we propose three ensemble strategies inMPGStack: KFold, GP-KFold, and LPA-KFold, which partition the graph at different degrees of granularity based on random uniform partition, class information, and label propagation, respectively.MPGStackcan enhance the target model's generalization performance, mitigate MIA, and boost classification accuracy. The experimental results conducted on seven benchmark datasets demonstrate thatMPGStackcan effectively defend against MIA and significantly reduce the attack model's success rate to the level of random guessing.MPGStackalso improves the classification accuracy of the target model up to 99% or more. Extensive experimental results demonstrate thatMPGStackis more effective, stable, and applicable to different datasets and scenarios than other methods, achieving random guessing attack models while improving the model's classification accuracy on different datasets.

Read the paper · More papers on PaperTik