Information Bottleneck-Based Subgraphs Defending Against Inference Attacks in Federated Graph Learning Systems
Chenhan Zhang, Weiqi Wang, Zhiyi Tian, Shui Yu · IEEE Transactions on Cognitive Communications and Networking · 2025
Federated Graph learning (FGL) for networked system data enables collaborative model training without sharing raw data, but it also introduces severe privacy risks. Model inversion attacks (MIA), as a type of inference attacks, can extract private graph structure information utilizing the information leakage such as model gradients and nodal attributes. MIA pose significant threats to FGL systems since attackers at the central server can easily access local GNNs’ gradients and potentially infer the private graph structure information of clients. In this paper, we propose a novel scheme to defend against MIA on graph structures in FGL systems while simultaneously preserving their learning performance. Specifically, we utilize the principle of information bottleneck (IB) to extract subgraphs, referred to as IB-subgraphs, that balance the privacy-utility trade-off from the clients’ original subgraphs for local GNN training. IB-subgraphs contain less information regarding the original structure of subgraphs. However, the task-relevant information is retained to a great extent. In particular, we develop a neural network-based approach to address the intractability of estimating the mutual information of graph data during IB optimization. Additionally, we design a subgraph generation algorithm to produce meaningful IB-subgraphs based on the optimization results. Extensive experiments demonstrate that our scheme effectively enhances MIA resilience in FGL while maintaining strong predictive accuracy, making it suitable for secure and intelligent communications and networking applications.