Attention-Based Membership Inference Attacks on Graph Neural Network Through Topological Features

Faqian Guan, Tianqing Zhu, Hanjin Tong, Wanlei Zhou · IEEE Transactions on Dependable and Secure Computing · 2025

Graph Neural Networks (GNNs), a type of machine learning model has been widely used in social networks, drug recommendations, and various other domains. While GNNs provide significant benefits, they also raise privacy concerns such as membership inference attack, posing a substantial risk to the private training data of GNNs. Previous studies have demonstrated that GNNs are susceptible to membership inference attacks, revealing private information about the training graph. However, these studies overlook the challenges of training data imbalance and a small number of training datasets in node-level membership inference attacks. Additionally, they under-utilize the topological features of the graph, resulting in sub-optimal performance of the attack models. In this paper, we find that by using attention mechanism, attackers have higher attack accuracy on the node-level membership inference attacks. This is because attention mechanism assigns different weights to neighboring nodes based on their contribution to the membership inference attack. To implement the attack, first, we tackle the training data imbalance issue through a random selection strategy. Second, we propose a data augmentation method exclusively tailored for membership inference attacks to address the problem of small datasets in node-level membership inference attacks. Next, we leverage the topological features of the graph and introduce two different feature padding strategies in feature processing. Finally, we employ the attention mechanism to assign different weights to neighboring nodes, enhancing the accuracy of the attack. We evaluate our proposed method on three datasets and three different GNN models, and the experimental results consistently demonstrate outstanding performance

Read the paper · More papers on PaperTik