Jun 2026· arXiv.org· Vol abs/2606.29748· 0 citations· 40 references
Computer Science
TL;DR
This work demonstrates that an adversary can use the generator-discriminator technique to reconstruct high-quality graphs in real-world black-box attack scenarios against GNNs, and shows that GNNs are highly vulnerable to privacy attacks, varying Laplacian noise-scales.
Abstract
The application of graph data in numerous disciplines raises the need for gathering and analyzing huge volumes of data, some of which is private and sensitive. The non-Euclidean nature of the graph data makes the analysis computationally challenging, leading to the use of Graph Neural Networks (GNNs) in the age of AI. GNNs may inadvertently leak sensitive data they are trained on, which raises serious data security issues, including the model inversion attack. In this study, we analyze GNNs'vulnerabilities by introducing two novel graph inversion (i.e., reconstruction) attacks: graph-label conditioned (GLC) attack and embedding-label conditioned (ELC) attack, utilizing targetmodel predictions and their intermediate representations, respectively. We perform a comprehensive analysis of our introduced privacy attacks and compare them with existing baselines across three benchmark graph datasets (i.e., NCI1, PROTEINS, and AIDS) and four graph distributional/structural metrics (i.e., FGD, EGD, MMD, and GKS). Our work demonstrates that an adversary can use the generator-discriminator technique to reconstruct high-quality graphs in real-world black-box attack scenarios against GNNs. Additionally, we present a variant of our attacks (Ours--) with 50% reduced queries, achieving good or comparable reconstruction attack performance. In addition, we show that GNNs are highly vulnerable to privacy attacks, varying Laplacian noise-scales.
This research introduces a new graph adversarial attack protection approach termed evolutionary algorithm integration of neighbor importance estimate to tackle this issue and attains notably superior performance in comparison to alternative defense methodologies.
Hong Pan, Jingwei Guo, Liang Cheng et al.· International Journal of Mac...· 0 citations
An active paradigm that repurposes the offensive tactic of node injection into a structural defense, ANIE significantly enhances GNN robustness, outperforming state-of-the-art defenses by up to 2× in classification accuracy under poisoning and evasion attacks.
Xiangchao Wen, Zhen Liu, Yunfei Liu· Proceedings of the 32nd ACM...· 0 citations
This work proposes GraphRP (Graph Reprogramming Protection), a proactive defense framework that repurposes Model Reprogramming for security, and proves a lower bound on the attacker's estimation error that increases with the structural sensitivity of the reprogramming noise.
Yan Wen, Zhenyi Wang, Heng Huang· Proceedings of the 32nd ACM...· 0 citations
By integrating temporal graph construction, adversarial augmentation, and GCN classification, GraphGAN effectively models coordinated attack behaviors and mitigates class imbalance, providing a robust and topology-aware solution for intrusion detection in data-constrained environments.
Mohammad Arif Hossain, Yeahia Sarker, Md Jafrin Hossain et al.· 0 citations
A novel framework, Generate and Filter graph learning for Graph Anomaly Detection (GFGAD), which generates a diverse set of synthetic anomalies with enriched feature and structural information to balance the data distribution and significantly outperforms state-of-the-art baselines.
Mengyu Li, Yonghao Liu, Ximing Li et al.· IEEE Transactions on Pattern...· 0 citations
A novel transferable graph prompt attack, called TGPA, is proposed, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism, which reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.
Ju Jia, Haonan Wang, Tian Wu et al.· Neural Networks· 0 citations