Pith. sign in

REVIEW 3 major objections 6 minor 1 cited by

Stealing Training Graphs from Graph Neural Networks

T0 review · 3 major / 6 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read This paper claims that a white-box attacker can recover private training molecules from a released Graph Neural Network by generating candidate graphs with a diffusion model and selecting those whose gradients reconstruct the model's…

desk verdict GraphSteal is a genuinely new and empirically strong graph-stealing attack, but its theoretical justification is mostly borrowed and the key selection step has no proven selectivity guarantee. read the letter →

arxiv 2411.11197 v2 pith:OCH4OQWF submitted 2024-11-17 cs.LG cs.CR

classification cs.LGcs.CR
keywords GraphneuralnetworksstealingattackPrivacyModelinversiondiffusionTrainingdataleakageHomogeneous
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper tries to show that a released Graph Neural Network leaks its private training graphs: a white-box attacker who knows the model architecture and parameters, and holds a public auxiliary dataset from the same domain, can reconstruct exact molecules from the target training set. To make this concrete, the authors propose GraphSteal, which trains a discrete graph diffusion model on the auxiliary data, nudges high-confidence auxiliary molecules toward the target via a classification-loss optimization, and then runs the diffusion denoiser (SDEdit) to produce realistic candidate graphs. The key claim is that the trained parameters of a homogeneous GNN are a nonnegative linear combination of the gradients of the true training graphs, so the attacker can select candidates by fitting the released parameters with a nonnegative combination of candidate-graph gradients. On molecular benchmarks, the method recovers a non-trivial fraction of the exact training molecules with high validity, outperforming model-inversion and explanation baselines; the paper further argues that differential privacy does not reliably stop this leakage.

What carries the argument

The load-bearing object is the parameter–gradient identity of Theorem 4.1, inherited from homogeneous neural network theory: for a homogeneous ReLU GNN trained by gradient flow to a KKT point of the max-margin problem, the final weights are a nonnegative linear combination of logit-margin gradients evaluated at the training graphs, with coefficients positive only on margin-saturating examples. The paper couples this with a discrete graph diffusion generator (DiGress) trained on the auxiliary set, a diffusion-noise optimization that adjusts adjacency matrices and node features of selected auxiliary graphs by minimizing the target classifier's loss, and SDEdit-style partial denoising to turn those optimized graphs into realistic candidates. The selection stage then treats each candidate's gradient as a dictionary atom and solves the nonnegatively constrained least-squares fit of Eq. (15) to the released parameters; the fitted coefficients λ_i are the selection scores, and the top-k candidates form the reconstructed set.

What would settle it

Train two homogeneous GNNs on disjoint but same-domain molecule sets that share the same auxiliary pool, then run GraphSteal's selection on the same candidate graph pool for both models; if the top-k selected graphs are largely identical or the fit quality is equal for both, the selection mask is not tracking the specific training set, and the reconstruction rates reported for a single dataset would be evidence of distribution overlap rather than membership recovery.

Watch

Extended reading notes

Core claim

For homogeneous GNNs (ReLU activations, no bias or skip connections) trained with gradient flow on cross-entropy, the converged parameter vector θ̃ equals Σ λ_i (∇_θ f_{θ̃}(G_i)_{y_i} − ∇_θ max_{j≠y_i} f_{θ̃}(G_i)_j) over the training graphs, with λ_i ≥ 0 and λ_i = 0 unless the margin β_i(θ̃) equals 1 (Theorem 4.1). Consequently the model parameters encode the training graphs through their gradients, and GraphSteal exploits this by generating candidate graphs with a diffusion model and solving a nonnegative least-squares problem to find a set of candidates whose gradients reconstruct θ; the top-k by λ are reported as stolen training graphs. The paper reports exact reconstruction rates of 50.4% on FreeSolv, 8.6% on ESOL, and 29.2% on QM9 with high validity (about 98%) for the top-100 selections against GCN, with similar trends for GIN and a graph transformer, and shows in ablations that both the diffusion generator and the parameter-guided selection contribute to the result.

Load-bearing premise

The load-bearing premise is that fitting the released weights with a nonnegative combination of gradients of generated candidate graphs singles out the true training graphs; the theorem only guarantees such a representation exists for the actual training set, not that it is unique, sparse, or selective for training members among an overcomplete pool of generated graphs.

Editorial extensions

If this is right

  • A model provider who releases a homogeneous GNN's parameters alongside its architecture is effectively sharing a fingerprint of the training set, at least when an adversary has in-domain auxiliary data.
  • The attack transfers across GNN architectures: the paper demonstrates reconstruction against GCN, GIN, and a 9-layer graph transformer.
  • Differential privacy added during training, at the noise scales tested, reduces but does not eliminate the exact reconstruction rate, so standard DP is not a sufficient defense by itself.
  • The number of exactly recoverable graphs is bounded by the effective number of margin-saturating training examples, so requesting more reconstructed graphs raises recall but lowers precision.
  • The scheme does not require any partial information about the target dataset beyond the auxiliary manifold assumption.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The sparsity of λ is not guaranteed: Theorem 4.1 gives existence of a nonnegative representation over the true training set, but over an overcomplete dictionary of generated candidates the least-squares fit may assign high weight to graphs that are not training members, so the reported reconstruction rates likely mix exact recovery with near-distribution artifacts.
  • The same parameter-gradient identity could be turned into a defense: adding noise or regularization that breaks the nonnegative representability of θ (for example, clipping gradients, adding bias or skip connections, or training with weight decay that changes the KKT characterization) may reduce the attack's precision, a testable design direction the paper does not pursue.
  • The method's dependence on exact SMILES matching means the reconstruction rate is a lower bound on effective leakage; molecules that are chemically equivalent but canonically different, or near-identical scaffolds, are counted as misses, so the true privacy exposure may be larger than the reported numbers.
  • For non-molecular graph domains where exact graph isomorphism is the matching criterion, the same pipeline should be testable, with the auxiliary-manifold assumption being the main transfer risk.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. The paper introduces GraphSteal, a white-box attack that aims to recover private training graphs from a released GNN classifier. The method first trains a DiGress graph diffusion model on an auxiliary dataset, selects high-confidence auxiliary graphs, optimizes their adjacency matrices and node features against the target model (Eq. 6), and then uses SDEdit to generate candidate graphs. A parameter-guided selection step (Eq. 15) fits the target parameters as a nonnegative linear combination of gradients of the candidates and keeps the top-k coefficients. The theoretical foundation is Theorem 4.1, which states that at a KKT point of the max-margin problem, the parameters of a homogeneous GNN are a nonnegative combination of gradients at the true training graphs. Experiments on FreeSolv, ESOL, and QM9 against GCN, GIN, and GTN report exact-match reconstruction rates up to 50.4% and better FCD and validity than baselines. Ablations and robustness checks under differential privacy, distribution shift, and split ratios are included. The paper claims that the theoretical analysis confirms a strong connection between GNN parameters and training graphs and that GraphSteal effectively recreates training graphs by leveraging these parameters.

Significance. If the empirical results are reproducible, the paper identifies a new privacy threat and provides a useful benchmark for graph-level model inversion. Strengths include public code, multiple datasets and architectures, exact graph matching as an evaluation metric, and ablations that separate the generation, noise-optimization, and selection components. The main weakness is that the theoretical bridge from Theorem 4.1 to the selection step is not established; the selection is an empirically motivated heuristic, and the abstract and Sec. 1 overstate the theoretical support. Nevertheless, the attack itself may be effective, and the empirical findings are valuable regardless of the theory's precise scope.

major comments (3)
  1. [Sec. 4.2.2, Eq. (15)] The selection step is the load-bearing bridge from theory to attack, but Theorem 4.1 does not imply that the nonnegative least-squares fit in Eq. (15) is selective. The theorem states only that, at a KKT point, the target parameters equal a nonnegative combination of gradients at the true training graphs with complementary-slackness coefficients; it gives no sparsity, uniqueness, or discriminativity condition for an overcomplete dictionary of generated graphs. In the high-dimensional gradient space, many subsets of the candidate set can approximate the target parameters to small residual, so the top-k lambda values need not correspond to training graphs. The GraphSteal/S ablation shows that the selection component helps empirically, but it does not identify the mechanism as the margin/KKT structure rather than a general similarity between candidate gradients and target gradients. Please either add an explicit selectivity condition with proof, or revise the abstract and Sec. 1 so that the theory is presented as motivation rather than as a guarantee that selected graphs are training graphs.
  2. [Theorem 4.1 and Sec. 5.2.2] Theorem 4.1 applies only to homogeneous GNNs without bias terms or skip connections, and its proof relies on Lyu and Li's gradient-flow directional-convergence result. The evaluated architectures (standard 2-layer GCN, 2-layer GIN, and 9-layer GTN) are not shown to satisfy the homogeneity premise; typical implementations of these models include bias terms, and GTN includes normalization, skip, and attention components. Moreover, the theorem assumes convergence in direction to a KKT point under gradient flow, while the experiments use a standard optimizer on finite training runs. The paper should either verify the premise by configuring bias-free and skip-free target models and reporting these settings, or explicitly state that Eq. (11) holds only under idealized conditions and is used as motivation for the experiments rather than as a description of the evaluated models.
  3. [Sec. 5.3, Fig. 4] The explanation of the decreasing reconstruction rate invokes Theorem 4.1, saying that there is 'a theoretical upper bound to the number of graphs that can be reconstructed based on θ'. Theorem 4.1 bounds the number of nonzero lambda_i in the KKT representation for the true training set; it does not bound the number of exact graph matches an attacker can recover from an overcomplete candidate set, and it says nothing about the generated set D_g. This inference is unsupported and should be removed or replaced with an empirical explanation of the observed saturation.
minor comments (6)
  1. [Sec. 4.3, Algorithm 1] The text refers to 'Algorithm 10' when discussing the reconstruction algorithm; it should refer to Algorithm 1.
  2. [Algorithm 1, line 8] Line 8 contains a typo: 'gradient decent' should be 'gradient descent'.
  3. [Appendix A.2.2, Eq. (31)] Equation (31) has a typo: the right-hand side should be sigma times f^{(i)}(H^{(i-1)}; theta^{(i)}), not sigma times f^{(i)}(H^{(i-1)}; sigma theta^{(i)}).
  4. [Sec. 5.3 and Table 3] The absolute exact-match counts for QM9 in Table 3 (100 matches at k=200 and 121.5 matches at k=500) are inconsistent with the monotone decrease of reconstruction rate described in the text and shown in Fig. 4; please reconcile the numbers or the description.
  5. [Table 4] The FCD values in Table 4 are labeled with '%', but FCD is not a percentage; the unit should be removed.
  6. [Sec. 1] There is an empty citation placeholder in the sentence 'such as node classification [] and graph classifications [18]'; the missing citation should be added.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the central theoretical input is an external cited result and the reconstruction-rate evaluation is against the true target set, not the fitted objective.

full rationale

The paper's claimed derivation chain is not circular in a load-bearing way. Theorem 4.1 is an instantiation of the KKT characterization of gradient descent for homogeneous networks from Lyu and Li [49]; the paper cites that external result as Lemma 4.1 and then provides its own proof of the GNN specialization. This is independent mathematical support, not a self-citation chain. The selection step in Sec. 4.2.2 solves the nonnegative least-squares problem in Eq. (15) to fit the target parameters theta using gradient differences of generated candidate graphs. This fit is a heuristic: Theorem 4.1 guarantees that the true training graphs admit such a representation, but it does not by itself guarantee that decoy graphs cannot also fit theta, so the selectivity of the top-lambda rule is not theoretically forced. However, that is a validity gap about an unproven heuristic, not circularity. The reconstruction-rate and FCD evaluations are performed against the actual held-out target training set, i.e., external ground truth not used in the fitting objective, so the empirical claims are falsifiable outside the fitted values. The paper contains multiple self-citations, but they appear in related work and background and do not carry the central derivation. No uniqueness theorem is imported from the authors' own prior work, and no known result is merely renamed. An empty citation appears in Sec. 2, but that is an editorial defect and does not affect circularity. Overall, the central claim has independent empirical content and the score reflects only minor, non-load-bearing self-citations.

Assumptions & free parameters 5 free parameters · 5 assumptions · 0 invented entities

The central claim rests on a KKT stationarity theorem borrowed from prior work, plus the unproven assumption that fitting the model parameters with gradients of generated graphs selects true training graphs. The paper also assumes a homogeneous network and a close auxiliary manifold, both of which are only partially checked.

free parameters (5)
  • k (number of final selected graphs) = 100 (main results); varied 10-500
    Chosen by hand; reconstruction rate is reported as a function of k in Sec. 5.3, so the headline numbers depend on this choice.
  • m (top-confidence auxiliary graphs per class) = not reported
    Defines M = C*m candidate seeds; controls the candidate pool size and is not listed in the experimental setup.
  • alpha (balance weight in Eq. 17) = not reported
    Balances the reconstruction loss and the non-negativity penalty for lambda; no sensitivity analysis is provided.
  • K (SDEdit diffusion steps) = not reported
    Controls how much noise is added before denoising in Eq. (7); a key hyperparameter for the realism and resemblance trade-off, not specified.
  • lambda_i selection masks = optimized via Eq. (15)
    Fitted to the target model parameters theta; these scores drive the final selection and are the output of a linear reconstruction fit rather than an independent training-membership measurement.
assumptions (5)
  • domain assumption Homogeneous ReLU GNN with no bias or skip connections, except possibly in the first layer
    Theorem 4.1 relies on homogeneity in Def. 4.1. Appendix A.2 asserts GCN and SGC satisfy it, but the experimental GIN, graph transformer, and GCN models with bias or normalization are not shown to satisfy it.
  • standard math Gradient flow directional convergence to a KKT point of the max-margin problem (Lemma 4.1 from Lyu and Li)
    Imported from the cited literature and not reproven; it is the foundation of Theorem 4.1 and is used without modification.
  • domain assumption Auxiliary dataset D_a shares a similar low-dimensional manifold with target dataset D_t, and D_a and D_t are disjoint
    Stated in Sec. 3.2.2 and Problem 1; needed for training the diffusion generator and for selecting high-confidence noise seeds.
  • standard math Mangasarian-Fromovitz Constraint Qualification holds for the max-margin problem
    Used in Appendix A.3 to justify that KKT conditions are necessary for the global optimum; the argument follows Lyu and Li.
  • domain assumption The graph diffusion model trained on D_a, after SDEdit, generates graphs that follow the target distribution D_t
    Core to the reconstruction generation stage; the paper only provides empirical evidence, no formal guarantee.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Stealing Training Graphs from Graph Neural Networks." pith.science (2026). https://pith.science/paper/OCH4OQWF

@misc{pith2026241111197,
  author       = {Pith},
  title        = {Pith review of: Stealing Training Graphs from Graph Neural Networks},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/OCH4OQWF}},
  note         = {Machine review of arXiv:2411.11197}
}
read the original abstract

Graph Neural Networks (GNNs) have shown promising results in modeling graphs in various tasks. The training of GNNs, especially on specialized tasks such as bioinformatics, demands extensive expert annotations, which are expensive and usually contain sensitive information of data providers. The trained GNN models are often shared for deployment in the real world. As neural networks can memorize the training samples, the model parameters of GNNs have a high risk of leaking private training data. Our theoretical analysis shows the strong connections between trained GNN parameters and the training graphs used, confirming the training graph leakage issue. However, explorations into training data leakage from trained GNNs are rather limited. Therefore, we investigate a novel problem of stealing graphs from trained GNNs. To obtain high-quality graphs that resemble the target training set, a graph diffusion model with diffusion noise optimization is deployed as a graph generator. Furthermore, we propose a selection method that effectively leverages GNN model parameters to identify training graphs from samples generated by the graph diffusion model. Extensive experiments on real-world datasets demonstrate the effectiveness of the proposed framework in stealing training graphs from the trained GNN.

Figures

Figures reproduced from arXiv: 2411.11197 by the authors.

Figure 1
Figure 1. Illustration of GNNs training and releasing. [PITH_FULL_IMAGE:figures/full_fig_p001_1.png] view at source ↗
Figure 2
Figure 2. An overview of proposed GraphSteal. composed of a graph generator ℎG, a noise generator ℎ𝑞, a recon￾structed graph selector ℎ𝑠 and the target GNN model 𝑓𝜽 . Specifically, a graph diffusion model is adopted as the graph generator ℎG to generate realistic and high-quality graphs. The noise generator ℎ𝑞 takes graphs from the auxiliary dataset D𝑎 as inputs to learn input noises for the graph generator ℎG, aiming to ensu… view at source ↗
Figure 3
Figure 3. Reconstruction results on QM9 for various GNNs. [PITH_FULL_IMAGE:figures/full_fig_p007_3.png] view at source ↗
Figures from the paper (3 more)
Figure 4
Figure 4. Figure 4: Impact of the numbers of selected graphs on QM9 [PITH_FULL_IMAGE:figures/full_fig_p008_4.png]
Figure 6
Figure 6. Figure 6: Reconstructed training graphs of QM9. reconstruction rate, while they still outperform BL-Diff. It shows the effectiveness of our proposed diffusion noise optimization and graph selection mask optimization, respectively; (ii) GraphSteal outperforms GraphSteal/D and Gra…
Figure 7
Figure 7. Figure 7: Impact of the numbers of selected graphs on Free [PITH_FULL_IMAGE:figures/full_fig_p012_7.png]

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses

    cs.CR 2025-08 conditional novelty 4.0 of 10

    A systematic review that organizes graph-ML IP protection into model-level and data-level attacks and defenses, and ships a benchmark library, PyGIP.

Reference graph

Works this paper leans on

88 extracted references · 42 canonical work pages · cited by 1 Pith paper

  1. [1]

    Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. 308–318

  2. [2]

    Yogesh Balaji, Seungjun Nah, Xun Huang, Arash Vahdat, Jiaming Song, Karsten Kreis, Miika Aittala, Timo Aila, Samuli Laine, Bryan Catanzaro, et al. 2022. ediffi: Text-to-image diffusion models with an ensemble of expert denoisers. arXiv preprint arXiv:2211.01324 (2022)

  3. [3]

    Ting Chen. 2023. On the importance of noise scheduling for diffusion models. arXiv preprint arXiv:2301.10972 (2023)

  4. [4]

    Enyan Dai and Jie Chen. 2022. Graph-augmented normalizing flows for anomaly detection of multiple time series. arXiv preprint arXiv:2202.07857 (2022)

  5. [5]

    Enyan Dai, Limeng Cui, Zhengyang Wang, Xianfeng Tang, Yinghan Wang, Mon- ica Cheng, Bing Yin, and Suhang Wang. 2023. A unified framework of graph information bottleneck for robustness and membership privacy. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 368–379

  6. [6]

    Enyan Dai, Minhua Lin, and Suhang Wang. 2024. PreGIP: Watermarking the Pretraining of Graph Neural Networks for Deep Intellectual Property Protection. arXiv preprint arXiv:2402.04435 (2024)

  7. [7]

    Enyan Dai, Minhua Lin, Xiang Zhang, and Suhang Wang. 2023. Unnoticeable backdoor attacks on graph neural networks. In Proceedings of the ACM Web Conference 2023. 2263–2273

  8. [8]

    Enyan Dai and Suhang Wang. 2021. Say no to the discrimination: Learning fair graph neural networks with limited sensitive attribute information. InProceedings of the 14th ACM International Conference on Web Search and Data Mining . 680– 688

Show all 88 references
  1. [9]

    Enyan Dai and Suhang Wang. 2021. Towards self-explainable graph neural network. In Proceedings of the 30th ACM International Conference on Information & Knowledge Management. 302–311

  2. [10]

    Enyan Dai and Suhang Wang. 2022. Learning fair graph neural networks with lim- ited and private sensitive attribute information. IEEE Transactions on Knowledge and Data Engineering 35, 7 (2022), 7103–7117

  3. [11]

    Enyan Dai and Suhang Wang. 2022. Towards prototype-based self-explainable graph neural network. ACM Transactions on Knowledge Discovery from Data (2022)

  4. [12]

    Enyan Dai, Tianxiang Zhao, Huaisheng Zhu, Junjie Xu, Zhimeng Guo, Hui Liu, Jiliang Tang, and Suhang Wang. 2022. A comprehensive survey on trustworthy graph neural networks: Privacy, robustness, fairness, and explainability. arXiv preprint arXiv:2204.08570 (2022)

  5. [13]

    Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding.arXiv preprint arXiv:1810.04805 (2018)

  6. [14]

    Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xi- aohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et al. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv prepri...

  7. [15]

    Simon Shaolei Du, Wei Hu, Sham M Kakade, Jason D Lee, and Qi Lei. 2020. Few-Shot Learning via Learning the Representation, Provably. In ICLR

  8. [16]

    Vasisht Duddu, Antoine Boutet, and Virat Shejwalkar. 2020. Quantifying privacy leakage in graph embedding. In MobiQuitous 2020-17th EAI International Con- ference on Mobile and Ubiquitous Systems: Computing, Networking and Services . 76–85

  9. [17]

    Vijay Prakash Dwivedi and Xavier Bresson. 2021. A Generalization of Trans- former Networks to Graphs.AAAI Workshop on Deep Learning on Graphs: Methods and Applications (2021)

  10. [18]

    Federico Errica, Marco Podda, Davide Bacciu, and Alessio Micheli. 2019. A Fair Comparison of Graph Neural Networks for Graph Classification. In ICLR

  11. [19]

    Wenqi Fan, Yao Ma, Qing Li, Yuan He, Eric Zhao, Jiliang Tang, and Dawei Yin

  12. [20]

    Xiang Fang, Arvind Easwaran, Blaise Genest, and Ponnuthurai Nagaratnam Sug- anthan. 2025. Your data is not perfect: Towards cross-domain out-of-distribution detection in class-imbalanced data. Expert Systems with Applications 267 (2025), 126031

  13. [21]

    Xiang Fang, Wanlong Fang, Daizong Liu, Xiaoye Qu, Jianfeng Dong, Pan Zhou, Renfu Li, Zichuan Xu, Lixing Chen, Panpan Zheng, et al. 2024. Not all inputs are valid: Towards open-set video moment retrieval using language. In ACM MM

  14. [22]

    Xiang Fang, Daizong Liu, Wanlong Fang, Pan Zhou, Yu Cheng, Keke Tang, and Kai Zou. 2023. Annotations Are Not All You Need: A Cross-modal Knowledge Transfer Network for Unsupervised Temporal Sentence Grounding. In Findings of EMNLP

  15. [23]

    Elyas Goli, Sagar Vyas, Seid Koric, Nahil Sobh, and Philippe H Geubelle. 2020. Chemnet: A deep neural network for advanced composites manufacturing. The Journal of Physical Chemistry B 124, 42 (2020), 9428–9437

  16. [24]

    Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. NeurIPS 30 (2017)

  17. [25]

    Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang

  18. [26]

    Xinlei He, Rui Wen, Yixin Wu, Michael Backes, Yun Shen, and Yang Zhang. 2021. Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429 (2021)

  19. [27]

    Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, and Sepp Hochreiter. 2017. Gans trained by a two time-scale update rule converge to a local nash equilibrium. NeurIPS 30 (2017)

  20. [28]

    Jonathan Ho, William Chan, Chitwan Saharia, Jay Whang, Ruiqi Gao, Alexey Gritsenko, Diederik P Kingma, Ben Poole, Mohammad Norouzi, David J Fleet, et al. 2022. Imagen video: High definition video generation with diffusion models. arXiv preprint arXiv:2210.02303 (2022)

  21. [29]

    Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. NeurIPS 33 (2020), 6840–6851

  22. [30]

    Emiel Hoogeboom, Vıctor Garcia Satorras, Clément Vignac, and Max Welling

  23. [31]

    Zhichao Hou, Minhua Lin, MohamadAli Torkamani, Suhang Wang, and Xiaorui Liu. 2024. Adversarial Robustness in Graph Neural Networks: Recent Advances and New Frontier. In 2024 IEEE 11th International Conference on Data Science and Advanced Analytics (DSAA). IEEE, 1–2

  24. [32]

    Adrián Javaloy, Pablo Sanchez Martin, Amit Levi, and Isabel Valera. 2023. Learn- able Graph Convolutional Attention Networks. In International Conference on Learning Representations (ICLR). https://openreview.net/forum?id=WsUMeHPo- 2

  25. [33]

    Ziwei Ji and Matus Telgarsky. 2020. Directional convergence and alignment in deep learning. NeurIPS 33 (2020), 17176–17186

  26. [34]

    Jaehyeong Jo, Seul Lee, and Sung Ju Hwang. 2022. Score-based generative model- ing of graphs via the system of stochastic differential equations. In International Conference on Machine Learning . PMLR, 10362–10383

  27. [35]

    Kipf and Max Welling

    Thomas N. Kipf and Max Welling. 2017. Semi-Supervised Classification with Graph Convolutional Networks. In ICLR

  28. [36]

    Greg Landrum. 2013. Rdkit documentation. Release 1, 1-79 (2013), 4. KDD ’25, August 3–7, 2025, Toronto, ON, Canada Minhua Lin, Enyan Dai, Junjie Xu, Jinyuan Jia, Xiang Zhang, and Suhang Wang

  29. [37]

    O-Joun Lee et al. 2024. Transitivity-Preserving Graph Representation Learning for Bridging Local Connectivity and Role-Based Similarity. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 38. 12456–12465

  30. [38]

    Xiaoxiao Li, Yuan Zhou, Nicha Dvornek, Muhan Zhang, Siyuan Gao, Juntang Zhuang, Dustin Scheinost, Lawrence H Staib, Pamela Ventola, and James S Dun- can. 2021. Braingnn: Interpretable brain graph neural network for fmri analysis. Medical Image Analysis 74 (2021), 102233

  31. [39]

    Yang Li, Buyue Qian, Xianli Zhang, and Hui Liu. 2020. Graph neural network- based diagnosis prediction. Big Data 8, 5 (2020), 379–390

  32. [40]

    Ke Liang, Lingyuan Meng, Hao Li, Meng Liu, Siwei Wang, Sihang Zhou, Xinwang Liu, and Kunlun He. 2024. MGKsite: Multi-Modal Knowledge-Driven Site Selec- tion via Intra and Inter-Modal Graph Fusion. IEEE Transactions on Multimedia (2024)

  33. [41]

    Ke Liang, Lingyuan Meng, Meng Liu, Yue Liu, Wenxuan Tu, Siwei Wang, Sihang Zhou, Xinwang Liu, Fuchun Sun, and Kunlun He. 2024. A survey of knowl- edge graph reasoning on graph types: Static, dynamic, and multi-modal. IEEE Transactions on Pattern Analysis and Machine Intelligen...

  34. [42]

    Ke Liang, Lingyuan Meng, Yue Liu, Meng Liu, Wei Wei, Suyuan Liu, Wenxuan Tu, Siwei Wang, Sihang Zhou, and Xinwang Liu. 2024. Simple Yet Effective: Structure Guided Pre-trained Transformer for Multi-modal Knowledge Graph Reasoning. In Proceedings of the 32nd ACM International C...

  35. [43]

    Ke Liang, Sihang Zhou, Meng Liu, Yue Liu, Wenxuan Tu, Yi Zhang, Liming Fang, Zhe Liu, and Xinwang Liu. 2024. Hawkes-enhanced spatial-temporal hypergraph contrastive learning based on criminal correlations. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. ...

  36. [44]

    Minhua Lin, Zhengzhang Chen, Yanchi Liu, Xujiang Zhao, Zongyu Wu, Junxiang Wang, Xiang Zhang, Suhang Wang, and Haifeng Chen. 2024. Decoding Time Series with LLMs: A Multi-Agent Framework for Cross-Domain Annotation. arXiv preprint arXiv:2410.17462 (2024)

  37. [45]

    Minhua Lin, Teng Xiao, Enyan Dai, Xiang Zhang, and Suhang Wang. 2024. Certifi- ably robust graph contrastive learning. Advances in Neural Information Processing Systems 36 (2024)

  38. [46]

    Minhua Lin, Zhiwei Zhang, Enyan Dai, Zongyu Wu, Yilong Wang, Xiang Zhang, and Suhang Wang. 2024. Trojan Prompt Attacks on Graph Neural Networks. arXiv preprint arXiv:2410.13974 (2024)

  39. [47]

    Yi Liu, Limei Wang, Meng Liu, Yuchao Lin, Xuan Zhang, Bora Oztekin, and Shuiwang Ji. 2022. Spherical message passing for 3d molecular graphs. In ICLR

  40. [48]

    Tianze Luo, Zhanfeng Mo, and Sinno Jialin Pan. 2023. Fast graph generation via spectral diffusion. IEEE Transactions on Pattern Analysis and Machine Intelligence (2023)

  41. [49]

    Kaifeng Lyu and Jian Li. 2020. Gradient Descent Maximizes the Margin of Homogeneous Neural Networks. In ICLR

  42. [50]

    Chenlin Meng, Yutong He, Yang Song, Jiaming Song, Jiajun Wu, Jun-Yan Zhu, and Stefano Ermon. 2022. SDEdit: Guided Image Synthesis and Editing with Stochastic Differential Equations. In ICLR

  43. [51]

    Luis Müller, Mikhail Galkin, Christopher Morris, and Ladislav Rampášek. 2023. Attending to graph transformers. arXiv preprint arXiv:2302.04181 (2023)

  44. [52]

    Mor Shpigel Nacson, Suriya Gunasekar, Jason Lee, Nathan Srebro, and Daniel Soudry. [n. d.]. Lexicographic and depth-sensitive margins in homogeneous and non-homogeneous deep models. In ICML

  45. [53]

    Iyiola E Olatunji, Wolfgang Nejdl, and Megha Khosla. 2021. Membership inference attack on graph neural networks. In 2021 Third IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA) . IEEE, 11–20

  46. [54]

    Noel M O’Boyle and Roger A Sayle. 2016. Comparing structural fingerprints using a literature-based similarity benchmark. Journal of cheminformatics 8 (2016), 1–14

  47. [55]

    Kristina Preuer, Philipp Renz, Thomas Unterthiner, Sepp Hochreiter, and Günter Klambauer. 2018. Fréchet ChemNet Distance: A Metric for Generative Models for Molecules in Drug Discovery. Journal of Chemical Information and Modeling 58, 9 (2018), 1736–1741

  48. [56]

    Aditya Ramesh, Prafulla Dhariwal, Alex Nichol, Casey Chu, and Mark Chen

  49. [57]

    Ladislav Rampášek, Michael Galkin, Vijay Prakash Dwivedi, Anh Tuan Luu, Guy Wolf, and Dominique Beaini. 2022. Recipe for a general, powerful, scalable graph transformer. Advances in Neural Information Processing Systems 35 (2022), 14501–14515

  50. [58]

    Yang Song, Jascha Sohl-Dickstein, Diederik P Kingma, Abhishek Kumar, Ste- fano Ermon, and Ben Poole. 2021. Score-Based Generative Modeling through Stochastic Differential Equations. In ICLR. https://openreview.net/forum?id= PxTIG12RRHS

  51. [59]

    Leonid Nisonovich Vaserstein. 1969. Markov processes over denumerable prod- ucts of spaces, describing large systems of automata. Problemy Peredachi Infor- matsii 5, 3 (1969), 64–72

  52. [60]

    arXiv preprint arXiv:2204.06125 1, 2 (2022), 3

    Hierarchical text-conditional image generation with clip latents. arXiv preprint arXiv:2204.06125 1, 2 (2022), 3

  53. [61]

    Binghui Wang, Minhua Lin, Tianxiang Zhou, Pan Zhou, Ang Li, Meng Pang, Hai Li, and Yiran Chen. 2024. Efficient, direct, and restricted black-box graph evasion attacks to any-layer graph neural networks via influence function. In Proceedings of the 17th ACM International Confer...

  54. [62]

    Daixin Wang, Jianbin Lin, Peng Cui, Quanhui Jia, Zhen Wang, Yanming Fang, Quan Yu, Jun Zhou, Shuang Yang, and Yuan Qi. 2019. A Semi-supervised Graph Attentive Network for Financial Fraud Detection. In ICDM. 598–607

  55. [63]

    Yuyang Wang, Jianren Wang, Zhonglin Cao, and Amir Barati Farimani. 2022. Molecular contrastive learning of representations via graph neural networks. Nature Machine Intelligence 4, 3 (2022), 279–287

  56. [64]

    Clement Vignac, Igor Krawczuk, Antoine Siraudin, Bohan Wang, Volkan Cevher, and Pascal Frossard. 2023. DiGress: Discrete Denoising diffusion for graph generation. In ICLR

  57. [65]

    Bang Wu, Xiangwen Yang, Shirui Pan, and Xingliang Yuan. 2022. Model extraction attacks on graph neural networks: Taxonomy and realisation. In Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security . 337–350

  58. [66]

    Felix Wu, Amauri Souza, Tianyi Zhang, Christopher Fifty, Tao Yu, and Kilian Weinberger. 2019. Simplifying graph convolutional networks. In International conference on machine learning . 6861–6871

  59. [67]

    Yixin Wu, Xinlei He, Pascal Berrang, Mathias Humbert, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. 2024. Link Stealing Attacks Against Inductive Graph Neural Networks. arXiv preprint arXiv:2405.05784 (2024)

  60. [68]

    David Weininger. 1988. SMILES, a chemical language and information system. 1. Introduction to methodology and encoding rules. Journal of chemical information and computer sciences 28, 1 (1988), 31–36

  61. [69]

    Junjie Xu, Zongyu Wu, Minhua Lin, Xiang Zhang, and Suhang Wang. 2024. LLM and GNN are Complementary: Distilling LLM for Multimodal Graph Learning. arXiv preprint arXiv:2406.01032 (2024)

  62. [70]

    Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2018. How Powerful are Graph Neural Networks?. In ICLR

  63. [71]

    Minkai Xu, Meng Liu, Wengong Jin, Shuiwang Ji, Jure Leskovec, and Stefano Ermon. 2023. Graph and geometry generative modeling for drug discovery. In SIGKDD. 5833–5834

  64. [72]

    Zhenqin Wu, Bharath Ramsundar, Evan N Feinberg, Joseph Gomes, Caleb Ge- niesse, Aneesh S Pappu, Karl Leswing, and Vijay Pande. 2018. MoleculeNet: a benchmark for molecular machine learning.Chemical science 9, 2 (2018), 513–530

  65. [73]

    Haotian Xue, Alexandre Araujo, Bin Hu, and Yongxin Chen. 2023. Diffusion-Based Adversarial Sample Generation for Improved Stealthiness and Controllability. In Thirty-seventh Conference on Neural Information Processing Systems

  66. [74]

    Chengxuan Ying, Tianle Cai, Shengjie Luo, Shuxin Zheng, Guolin Ke, Di He, Yanming Shen, and Tie-Yan Liu. 2021. Do transformers really perform badly for graph representation? NeurIPS 34 (2021), 28877–28888

  67. [75]

    Rex Ying, Ruining He, Kaifeng Chen, Pong Eksombatchai, William L Hamilton, and Jure Leskovec. 2018. Graph convolutional neural networks for web-scale recommender systems. In SIGKDD. 974–983

  68. [76]

    Minkai Xu, Lantao Yu, Yang Song, Chence Shi, Stefano Ermon, and Jian Tang. 2022. Geodiff: A geometric diffusion model for molecular conformation generation. arXiv preprint arXiv:2203.02923 (2022)

  69. [77]

    Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals

  70. [78]

    Jiawei Zhang, Haopeng Zhang, Congying Xia, and Li Sun. 2020. Graph-bert: Only attention is needed for learning graph representations. arXiv preprint arXiv:2001.05140 (2020)

  71. [79]

    Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, and Yang Zhang. 2022. Infer- ence attacks against graph neural networks. In 31st USENIX Security Symposium (USENIX Security 22). 4543–4560

  72. [80]

    Hao Yuan, Jiliang Tang, Xia Hu, and Shuiwang Ji. 2020. Xgnn: Towards model- level explanations of graph neural networks. In SIGKDD. 430–438

  73. [81]

    Zhiwei Zhang, Minhua Lin, Junjie Xu, Zongyu Wu, Enyan Dai, and Suhang Wang

  74. [82]

    Understanding deep learning (still) requires rethinking generalization. Commun. ACM 64, 3 (2021), 107–115

  75. [85]

    Zhiwei Zhang, Minhua Lin, Enyan Dai, and Suhang Wang. 2024. Rethinking graph backdoor attacks: A distribution-preserving perspective. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 4386–4397

  76. [88]

    Zaixi Zhang, Qi Liu, Zhenya Huang, Hao Wang, Chengqiang Lu, Chuanren Liu, and Enhong Chen. 2021. GraphMI: Extracting Private Graph Data from Graph Neural Networks. In Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, IJCAI-21. 3749–3755. S...

  77. [2019]

    In The world wide web conference

    Graph neural networks for social recommendation. In The world wide web conference. 417–426

  78. [2021]

    In 30th USENIX Security Sym- posium (USENIX Security 21)

    Stealing links from graph neural networks. In 30th USENIX Security Sym- posium (USENIX Security 21) . 2669–2686

  79. [2022]

    In International confer- ence on machine learning

    Equivariant diffusion for molecule generation in 3d. In International confer- ence on machine learning . PMLR, 8867–8887

  80. [2024]

    arXiv preprint arXiv:2406.09836 (2024)

    Robustness-Inspired Defense Against Backdoor Attacks on Graph Neural Networks. arXiv preprint arXiv:2406.09836 (2024)

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.