Can Contrastive Learning Always be Trusted? Privacy Leakage Evaluation of Contrastive Learning for Graph Neural Networks

Jinyin Chen, Wenbo Mu, Haonan Ma, Chengyi Wang, Haibin Zheng, Hang Du · IEEE Transactions on Computational Social Systems · 2025

Contrastive learning, as an efficient unsupervised learning, has been extensively studied for improving graph neural network (GNN) in graph-structured data mining. With the wider application of GNN, recent work has revealed that it is vulnerable toward privacy leakage (e.g., property inference). How dose contrastive learning influence privacy leakage of GNN? To address the issue, for the first time we comprehensively evaluate the privacy leakage of contrastive learning for GNN. Specifically, we conduct property inference attack on GNN and evaluate the leakage from the perspective of graph augmentation, encoders, negative sampling and privacy preservation on seven graph contrastive learning (GCL) models with five datasets. Based on extensive experiments, several important insights are gained. 1) Contrastive learning will make GNN more vulnerable to property inference attack than supervised GNNs, e.g., the inference accuracy on GCL models is$\boldsymbol{\times\sim}$1.42 of that of supervised GNNs. 2) The strategy of node augmentation in contrastive learning will make the property of the graph easier to steal among all strategies, e.g., it achieves average inference accuracy (ACC) of 83.89% on the node augmentation. 3) Negative sampling based on rationale-aware will lead to easier leakage of graph properties than other strategies, e.g., the ACC of property inference attack is 100% when using rationale-aware. 4) The better performance results of the graph encoder, the more privacy leakage of the graph property, e.g., the ACC of property inference attack reaches 83.89% on average, and reaches 84.40% when GIN is used as the encoder. 5) The simpler the structure of the graph, the more vulnerable its graph properties are, i.e., the AIDS dataset achieved the highest ACC of 90.96 with the simplest structure. 6) Existing privacy-preserving methods for supervised GNN are deficient for GCL, e.g., the ACC of property inference attack after defence maintains 96% of the nondefensive ones. Furthermore, we make an in-depth analyze of the reasons behind these observations for better understanding of robust contrastive learning for GNN.

Read the paper · More papers on PaperTik