REVIEW 3 major objections 6 minor 1 cited by
Stealing Training Graphs from Graph Neural Networks
T0 review · 3 major / 6 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read This paper claims that a white-box attacker can recover private training molecules from a released Graph Neural Network by generating candidate graphs with a diffusion model and selecting those whose gradients reconstruct the model's…
desk verdict GraphSteal is a genuinely new and empirically strong graph-stealing attack, but its theoretical justification is mostly borrowed and the key selection step has no proven selectivity guarantee. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the parameter–gradient identity of Theorem 4.1, inherited from homogeneous neural network theory: for a homogeneous ReLU GNN trained by gradient flow to a KKT point of the max-margin problem, the final weights are a nonnegative linear combination of logit-margin gradients evaluated at the training graphs, with coefficients positive only on margin-saturating examples. The paper couples this with a discrete graph diffusion generator (DiGress) trained on the auxiliary set, a diffusion-noise optimization that adjusts adjacency matrices and node features of selected auxiliary graphs by minimizing the target classifier's loss, and SDEdit-style partial denoising to turn those optimized graphs into realistic candidates. The selection stage then treats each candidate's gradient as a dictionary atom and solves the nonnegatively constrained least-squares fit of Eq. (15) to the released parameters; the fitted coefficients λ_i are the selection scores, and the top-k candidates form the reconstructed set.
What would settle it
Train two homogeneous GNNs on disjoint but same-domain molecule sets that share the same auxiliary pool, then run GraphSteal's selection on the same candidate graph pool for both models; if the top-k selected graphs are largely identical or the fit quality is equal for both, the selection mask is not tracking the specific training set, and the reconstruction rates reported for a single dataset would be evidence of distribution overlap rather than membership recovery.
Extended reading notes
Core claim
For homogeneous GNNs (ReLU activations, no bias or skip connections) trained with gradient flow on cross-entropy, the converged parameter vector θ̃ equals Σ λ_i (∇_θ f_{θ̃}(G_i)_{y_i} − ∇_θ max_{j≠y_i} f_{θ̃}(G_i)_j) over the training graphs, with λ_i ≥ 0 and λ_i = 0 unless the margin β_i(θ̃) equals 1 (Theorem 4.1). Consequently the model parameters encode the training graphs through their gradients, and GraphSteal exploits this by generating candidate graphs with a diffusion model and solving a nonnegative least-squares problem to find a set of candidates whose gradients reconstruct θ; the top-k by λ are reported as stolen training graphs. The paper reports exact reconstruction rates of 50.4% on FreeSolv, 8.6% on ESOL, and 29.2% on QM9 with high validity (about 98%) for the top-100 selections against GCN, with similar trends for GIN and a graph transformer, and shows in ablations that both the diffusion generator and the parameter-guided selection contribute to the result.
Load-bearing premise
The load-bearing premise is that fitting the released weights with a nonnegative combination of gradients of generated candidate graphs singles out the true training graphs; the theorem only guarantees such a representation exists for the actual training set, not that it is unique, sparse, or selective for training members among an overcomplete pool of generated graphs.
Editorial extensions
If this is right
- A model provider who releases a homogeneous GNN's parameters alongside its architecture is effectively sharing a fingerprint of the training set, at least when an adversary has in-domain auxiliary data.
- The attack transfers across GNN architectures: the paper demonstrates reconstruction against GCN, GIN, and a 9-layer graph transformer.
- Differential privacy added during training, at the noise scales tested, reduces but does not eliminate the exact reconstruction rate, so standard DP is not a sufficient defense by itself.
- The number of exactly recoverable graphs is bounded by the effective number of margin-saturating training examples, so requesting more reconstructed graphs raises recall but lowers precision.
- The scheme does not require any partial information about the target dataset beyond the auxiliary manifold assumption.
Reading between the lines
- The sparsity of λ is not guaranteed: Theorem 4.1 gives existence of a nonnegative representation over the true training set, but over an overcomplete dictionary of generated candidates the least-squares fit may assign high weight to graphs that are not training members, so the reported reconstruction rates likely mix exact recovery with near-distribution artifacts.
- The same parameter-gradient identity could be turned into a defense: adding noise or regularization that breaks the nonnegative representability of θ (for example, clipping gradients, adding bias or skip connections, or training with weight decay that changes the KKT characterization) may reduce the attack's precision, a testable design direction the paper does not pursue.
- The method's dependence on exact SMILES matching means the reconstruction rate is a lower bound on effective leakage; molecules that are chemically equivalent but canonically different, or near-identical scaffolds, are counted as misses, so the true privacy exposure may be larger than the reported numbers.
- For non-molecular graph domains where exact graph isomorphism is the matching criterion, the same pipeline should be testable, with the auxiliary-manifold assumption being the main transfer risk.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces GraphSteal, a white-box attack that aims to recover private training graphs from a released GNN classifier. The method first trains a DiGress graph diffusion model on an auxiliary dataset, selects high-confidence auxiliary graphs, optimizes their adjacency matrices and node features against the target model (Eq. 6), and then uses SDEdit to generate candidate graphs. A parameter-guided selection step (Eq. 15) fits the target parameters as a nonnegative linear combination of gradients of the candidates and keeps the top-k coefficients. The theoretical foundation is Theorem 4.1, which states that at a KKT point of the max-margin problem, the parameters of a homogeneous GNN are a nonnegative combination of gradients at the true training graphs. Experiments on FreeSolv, ESOL, and QM9 against GCN, GIN, and GTN report exact-match reconstruction rates up to 50.4% and better FCD and validity than baselines. Ablations and robustness checks under differential privacy, distribution shift, and split ratios are included. The paper claims that the theoretical analysis confirms a strong connection between GNN parameters and training graphs and that GraphSteal effectively recreates training graphs by leveraging these parameters.
Significance. If the empirical results are reproducible, the paper identifies a new privacy threat and provides a useful benchmark for graph-level model inversion. Strengths include public code, multiple datasets and architectures, exact graph matching as an evaluation metric, and ablations that separate the generation, noise-optimization, and selection components. The main weakness is that the theoretical bridge from Theorem 4.1 to the selection step is not established; the selection is an empirically motivated heuristic, and the abstract and Sec. 1 overstate the theoretical support. Nevertheless, the attack itself may be effective, and the empirical findings are valuable regardless of the theory's precise scope.
major comments (3)
- [Sec. 4.2.2, Eq. (15)] The selection step is the load-bearing bridge from theory to attack, but Theorem 4.1 does not imply that the nonnegative least-squares fit in Eq. (15) is selective. The theorem states only that, at a KKT point, the target parameters equal a nonnegative combination of gradients at the true training graphs with complementary-slackness coefficients; it gives no sparsity, uniqueness, or discriminativity condition for an overcomplete dictionary of generated graphs. In the high-dimensional gradient space, many subsets of the candidate set can approximate the target parameters to small residual, so the top-k lambda values need not correspond to training graphs. The GraphSteal/S ablation shows that the selection component helps empirically, but it does not identify the mechanism as the margin/KKT structure rather than a general similarity between candidate gradients and target gradients. Please either add an explicit selectivity condition with proof, or revise the abstract and Sec. 1 so that the theory is presented as motivation rather than as a guarantee that selected graphs are training graphs.
- [Theorem 4.1 and Sec. 5.2.2] Theorem 4.1 applies only to homogeneous GNNs without bias terms or skip connections, and its proof relies on Lyu and Li's gradient-flow directional-convergence result. The evaluated architectures (standard 2-layer GCN, 2-layer GIN, and 9-layer GTN) are not shown to satisfy the homogeneity premise; typical implementations of these models include bias terms, and GTN includes normalization, skip, and attention components. Moreover, the theorem assumes convergence in direction to a KKT point under gradient flow, while the experiments use a standard optimizer on finite training runs. The paper should either verify the premise by configuring bias-free and skip-free target models and reporting these settings, or explicitly state that Eq. (11) holds only under idealized conditions and is used as motivation for the experiments rather than as a description of the evaluated models.
- [Sec. 5.3, Fig. 4] The explanation of the decreasing reconstruction rate invokes Theorem 4.1, saying that there is 'a theoretical upper bound to the number of graphs that can be reconstructed based on θ'. Theorem 4.1 bounds the number of nonzero lambda_i in the KKT representation for the true training set; it does not bound the number of exact graph matches an attacker can recover from an overcomplete candidate set, and it says nothing about the generated set D_g. This inference is unsupported and should be removed or replaced with an empirical explanation of the observed saturation.
minor comments (6)
- [Sec. 4.3, Algorithm 1] The text refers to 'Algorithm 10' when discussing the reconstruction algorithm; it should refer to Algorithm 1.
- [Algorithm 1, line 8] Line 8 contains a typo: 'gradient decent' should be 'gradient descent'.
- [Appendix A.2.2, Eq. (31)] Equation (31) has a typo: the right-hand side should be sigma times f^{(i)}(H^{(i-1)}; theta^{(i)}), not sigma times f^{(i)}(H^{(i-1)}; sigma theta^{(i)}).
- [Sec. 5.3 and Table 3] The absolute exact-match counts for QM9 in Table 3 (100 matches at k=200 and 121.5 matches at k=500) are inconsistent with the monotone decrease of reconstruction rate described in the text and shown in Fig. 4; please reconcile the numbers or the description.
- [Table 4] The FCD values in Table 4 are labeled with '%', but FCD is not a percentage; the unit should be removed.
- [Sec. 1] There is an empty citation placeholder in the sentence 'such as node classification [] and graph classifications [18]'; the missing citation should be added.
Circularity Check
No significant circularity: the central theoretical input is an external cited result and the reconstruction-rate evaluation is against the true target set, not the fitted objective.
full rationale
The paper's claimed derivation chain is not circular in a load-bearing way. Theorem 4.1 is an instantiation of the KKT characterization of gradient descent for homogeneous networks from Lyu and Li [49]; the paper cites that external result as Lemma 4.1 and then provides its own proof of the GNN specialization. This is independent mathematical support, not a self-citation chain. The selection step in Sec. 4.2.2 solves the nonnegative least-squares problem in Eq. (15) to fit the target parameters theta using gradient differences of generated candidate graphs. This fit is a heuristic: Theorem 4.1 guarantees that the true training graphs admit such a representation, but it does not by itself guarantee that decoy graphs cannot also fit theta, so the selectivity of the top-lambda rule is not theoretically forced. However, that is a validity gap about an unproven heuristic, not circularity. The reconstruction-rate and FCD evaluations are performed against the actual held-out target training set, i.e., external ground truth not used in the fitting objective, so the empirical claims are falsifiable outside the fitted values. The paper contains multiple self-citations, but they appear in related work and background and do not carry the central derivation. No uniqueness theorem is imported from the authors' own prior work, and no known result is merely renamed. An empty citation appears in Sec. 2, but that is an editorial defect and does not affect circularity. Overall, the central claim has independent empirical content and the score reflects only minor, non-load-bearing self-citations.
Assumptions & free parameters
free parameters (5)
- k (number of final selected graphs) =
100 (main results); varied 10-500
- m (top-confidence auxiliary graphs per class) =
not reported
- alpha (balance weight in Eq. 17) =
not reported
- K (SDEdit diffusion steps) =
not reported
- lambda_i selection masks =
optimized via Eq. (15)
assumptions (5)
- domain assumption Homogeneous ReLU GNN with no bias or skip connections, except possibly in the first layer
- standard math Gradient flow directional convergence to a KKT point of the max-margin problem (Lemma 4.1 from Lyu and Li)
- domain assumption Auxiliary dataset D_a shares a similar low-dimensional manifold with target dataset D_t, and D_a and D_t are disjoint
- standard math Mangasarian-Fromovitz Constraint Qualification holds for the max-margin problem
- domain assumption The graph diffusion model trained on D_a, after SDEdit, generates graphs that follow the target distribution D_t
Cite this review
Pith. "Pith review of Stealing Training Graphs from Graph Neural Networks." pith.science (2026). https://pith.science/paper/OCH4OQWF
@misc{pith2026241111197,
author = {Pith},
title = {Pith review of: Stealing Training Graphs from Graph Neural Networks},
year = {2026},
howpublished = {\url{https://pith.science/paper/OCH4OQWF}},
note = {Machine review of arXiv:2411.11197}
}
read the original abstract
Graph Neural Networks (GNNs) have shown promising results in modeling graphs in various tasks. The training of GNNs, especially on specialized tasks such as bioinformatics, demands extensive expert annotations, which are expensive and usually contain sensitive information of data providers. The trained GNN models are often shared for deployment in the real world. As neural networks can memorize the training samples, the model parameters of GNNs have a high risk of leaking private training data. Our theoretical analysis shows the strong connections between trained GNN parameters and the training graphs used, confirming the training graph leakage issue. However, explorations into training data leakage from trained GNNs are rather limited. Therefore, we investigate a novel problem of stealing graphs from trained GNNs. To obtain high-quality graphs that resemble the target training set, a graph diffusion model with diffusion noise optimization is deployed as a graph generator. Furthermore, we propose a selection method that effectively leverages GNN model parameters to identify training graphs from samples generated by the graph diffusion model. Extensive experiments on real-world datasets demonstrate the effectiveness of the proposed framework in stealing training graphs from the trained GNN.
Figures
Figures from the paper (3 more)
Forward citations
Cited by 1 Pith paper
-
Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses
A systematic review that organizes graph-ML IP protection into model-level and data-level attacks and defenses, and ships a benchmark library, PyGIP.
Reference graph
Works this paper leans on
-
[1]
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications security. 308–318
2016
-
[2]
Yogesh Balaji, Seungjun Nah, Xun Huang, Arash Vahdat, Jiaming Song, Karsten Kreis, Miika Aittala, Timo Aila, Samuli Laine, Bryan Catanzaro, et al. 2022. ediffi: Text-to-image diffusion models with an ensemble of expert denoisers. arXiv preprint arXiv:2211.01324 (2022)
arXiv 2022
-
[3]
Ting Chen. 2023. On the importance of noise scheduling for diffusion models. arXiv preprint arXiv:2301.10972 (2023)
arXiv 2023
-
[4]
Enyan Dai and Jie Chen. 2022. Graph-augmented normalizing flows for anomaly detection of multiple time series. arXiv preprint arXiv:2202.07857 (2022)
arXiv 2022
-
[5]
Enyan Dai, Limeng Cui, Zhengyang Wang, Xianfeng Tang, Yinghan Wang, Mon- ica Cheng, Bing Yin, and Suhang Wang. 2023. A unified framework of graph information bottleneck for robustness and membership privacy. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 368–379
2023
-
[6]
Enyan Dai, Minhua Lin, and Suhang Wang. 2024. PreGIP: Watermarking the Pretraining of Graph Neural Networks for Deep Intellectual Property Protection. arXiv preprint arXiv:2402.04435 (2024)
arXiv 2024
-
[7]
Enyan Dai, Minhua Lin, Xiang Zhang, and Suhang Wang. 2023. Unnoticeable backdoor attacks on graph neural networks. In Proceedings of the ACM Web Conference 2023. 2263–2273
2023
-
[8]
Enyan Dai and Suhang Wang. 2021. Say no to the discrimination: Learning fair graph neural networks with limited sensitive attribute information. InProceedings of the 14th ACM International Conference on Web Search and Data Mining . 680– 688
2021
Show all 88 references
-
[9]
Enyan Dai and Suhang Wang. 2021. Towards self-explainable graph neural network. In Proceedings of the 30th ACM International Conference on Information & Knowledge Management. 302–311
2021
-
[10]
Enyan Dai and Suhang Wang. 2022. Learning fair graph neural networks with lim- ited and private sensitive attribute information. IEEE Transactions on Knowledge and Data Engineering 35, 7 (2022), 7103–7117
2022
-
[11]
Enyan Dai and Suhang Wang. 2022. Towards prototype-based self-explainable graph neural network. ACM Transactions on Knowledge Discovery from Data (2022)
2022
-
[12]
Enyan Dai, Tianxiang Zhao, Huaisheng Zhu, Junjie Xu, Zhimeng Guo, Hui Liu, Jiliang Tang, and Suhang Wang. 2022. A comprehensive survey on trustworthy graph neural networks: Privacy, robustness, fairness, and explainability. arXiv preprint arXiv:2204.08570 (2022)
2022 arXiv
-
[13]
Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding.arXiv preprint arXiv:1810.04805 (2018)
2018 arXiv
-
[14]
Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xi- aohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et al. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv prepri...
2020 arXiv
-
[15]
Simon Shaolei Du, Wei Hu, Sham M Kakade, Jason D Lee, and Qi Lei. 2020. Few-Shot Learning via Learning the Representation, Provably. In ICLR
2020
-
[16]
Vasisht Duddu, Antoine Boutet, and Virat Shejwalkar. 2020. Quantifying privacy leakage in graph embedding. In MobiQuitous 2020-17th EAI International Con- ference on Mobile and Ubiquitous Systems: Computing, Networking and Services . 76–85
2020
-
[17]
Vijay Prakash Dwivedi and Xavier Bresson. 2021. A Generalization of Trans- former Networks to Graphs.AAAI Workshop on Deep Learning on Graphs: Methods and Applications (2021)
2021
-
[18]
Federico Errica, Marco Podda, Davide Bacciu, and Alessio Micheli. 2019. A Fair Comparison of Graph Neural Networks for Graph Classification. In ICLR
2019
-
[19]
Wenqi Fan, Yao Ma, Qing Li, Yuan He, Eric Zhao, Jiliang Tang, and Dawei Yin
-
[20]
Xiang Fang, Arvind Easwaran, Blaise Genest, and Ponnuthurai Nagaratnam Sug- anthan. 2025. Your data is not perfect: Towards cross-domain out-of-distribution detection in class-imbalanced data. Expert Systems with Applications 267 (2025), 126031
2025
-
[21]
Xiang Fang, Wanlong Fang, Daizong Liu, Xiaoye Qu, Jianfeng Dong, Pan Zhou, Renfu Li, Zichuan Xu, Lixing Chen, Panpan Zheng, et al. 2024. Not all inputs are valid: Towards open-set video moment retrieval using language. In ACM MM
2024
-
[22]
Xiang Fang, Daizong Liu, Wanlong Fang, Pan Zhou, Yu Cheng, Keke Tang, and Kai Zou. 2023. Annotations Are Not All You Need: A Cross-modal Knowledge Transfer Network for Unsupervised Temporal Sentence Grounding. In Findings of EMNLP
2023
-
[23]
Elyas Goli, Sagar Vyas, Seid Koric, Nahil Sobh, and Philippe H Geubelle. 2020. Chemnet: A deep neural network for advanced composites manufacturing. The Journal of Physical Chemistry B 124, 42 (2020), 9428–9437
2020
-
[24]
Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. NeurIPS 30 (2017)
2017
-
[25]
Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang
-
[26]
Xinlei He, Rui Wen, Yixin Wu, Michael Backes, Yun Shen, and Yang Zhang. 2021. Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429 (2021)
2021 arXiv
-
[27]
Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, and Sepp Hochreiter. 2017. Gans trained by a two time-scale update rule converge to a local nash equilibrium. NeurIPS 30 (2017)
2017
-
[28]
Jonathan Ho, William Chan, Chitwan Saharia, Jay Whang, Ruiqi Gao, Alexey Gritsenko, Diederik P Kingma, Ben Poole, Mohammad Norouzi, David J Fleet, et al. 2022. Imagen video: High definition video generation with diffusion models. arXiv preprint arXiv:2210.02303 (2022)
2022 arXiv
-
[29]
Jonathan Ho, Ajay Jain, and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. NeurIPS 33 (2020), 6840–6851
2020
-
[30]
Emiel Hoogeboom, Vıctor Garcia Satorras, Clément Vignac, and Max Welling
-
[31]
Zhichao Hou, Minhua Lin, MohamadAli Torkamani, Suhang Wang, and Xiaorui Liu. 2024. Adversarial Robustness in Graph Neural Networks: Recent Advances and New Frontier. In 2024 IEEE 11th International Conference on Data Science and Advanced Analytics (DSAA). IEEE, 1–2
2024
-
[32]
Adrián Javaloy, Pablo Sanchez Martin, Amit Levi, and Isabel Valera. 2023. Learn- able Graph Convolutional Attention Networks. In International Conference on Learning Representations (ICLR). https://openreview.net/forum?id=WsUMeHPo- 2
2023
-
[33]
Ziwei Ji and Matus Telgarsky. 2020. Directional convergence and alignment in deep learning. NeurIPS 33 (2020), 17176–17186
2020
-
[34]
Jaehyeong Jo, Seul Lee, and Sung Ju Hwang. 2022. Score-based generative model- ing of graphs via the system of stochastic differential equations. In International Conference on Machine Learning . PMLR, 10362–10383
2022
-
[35]
Kipf and Max Welling
Thomas N. Kipf and Max Welling. 2017. Semi-Supervised Classification with Graph Convolutional Networks. In ICLR
2017
-
[36]
Greg Landrum. 2013. Rdkit documentation. Release 1, 1-79 (2013), 4. KDD ’25, August 3–7, 2025, Toronto, ON, Canada Minhua Lin, Enyan Dai, Junjie Xu, Jinyuan Jia, Xiang Zhang, and Suhang Wang
2013
-
[37]
O-Joun Lee et al. 2024. Transitivity-Preserving Graph Representation Learning for Bridging Local Connectivity and Role-Based Similarity. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 38. 12456–12465
2024
-
[38]
Xiaoxiao Li, Yuan Zhou, Nicha Dvornek, Muhan Zhang, Siyuan Gao, Juntang Zhuang, Dustin Scheinost, Lawrence H Staib, Pamela Ventola, and James S Dun- can. 2021. Braingnn: Interpretable brain graph neural network for fmri analysis. Medical Image Analysis 74 (2021), 102233
2021
-
[39]
Yang Li, Buyue Qian, Xianli Zhang, and Hui Liu. 2020. Graph neural network- based diagnosis prediction. Big Data 8, 5 (2020), 379–390
2020
-
[40]
Ke Liang, Lingyuan Meng, Hao Li, Meng Liu, Siwei Wang, Sihang Zhou, Xinwang Liu, and Kunlun He. 2024. MGKsite: Multi-Modal Knowledge-Driven Site Selec- tion via Intra and Inter-Modal Graph Fusion. IEEE Transactions on Multimedia (2024)
2024
-
[41]
Ke Liang, Lingyuan Meng, Meng Liu, Yue Liu, Wenxuan Tu, Siwei Wang, Sihang Zhou, Xinwang Liu, Fuchun Sun, and Kunlun He. 2024. A survey of knowl- edge graph reasoning on graph types: Static, dynamic, and multi-modal. IEEE Transactions on Pattern Analysis and Machine Intelligen...
2024
-
[42]
Ke Liang, Lingyuan Meng, Yue Liu, Meng Liu, Wei Wei, Suyuan Liu, Wenxuan Tu, Siwei Wang, Sihang Zhou, and Xinwang Liu. 2024. Simple Yet Effective: Structure Guided Pre-trained Transformer for Multi-modal Knowledge Graph Reasoning. In Proceedings of the 32nd ACM International C...
2024
-
[43]
Ke Liang, Sihang Zhou, Meng Liu, Yue Liu, Wenxuan Tu, Yi Zhang, Liming Fang, Zhe Liu, and Xinwang Liu. 2024. Hawkes-enhanced spatial-temporal hypergraph contrastive learning based on criminal correlations. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. ...
2024
-
[44]
Minhua Lin, Zhengzhang Chen, Yanchi Liu, Xujiang Zhao, Zongyu Wu, Junxiang Wang, Xiang Zhang, Suhang Wang, and Haifeng Chen. 2024. Decoding Time Series with LLMs: A Multi-Agent Framework for Cross-Domain Annotation. arXiv preprint arXiv:2410.17462 (2024)
2024 arXiv
-
[45]
Minhua Lin, Teng Xiao, Enyan Dai, Xiang Zhang, and Suhang Wang. 2024. Certifi- ably robust graph contrastive learning. Advances in Neural Information Processing Systems 36 (2024)
2024
-
[46]
Minhua Lin, Zhiwei Zhang, Enyan Dai, Zongyu Wu, Yilong Wang, Xiang Zhang, and Suhang Wang. 2024. Trojan Prompt Attacks on Graph Neural Networks. arXiv preprint arXiv:2410.13974 (2024)
2024 arXiv
-
[47]
Yi Liu, Limei Wang, Meng Liu, Yuchao Lin, Xuan Zhang, Bora Oztekin, and Shuiwang Ji. 2022. Spherical message passing for 3d molecular graphs. In ICLR
2022
-
[48]
Tianze Luo, Zhanfeng Mo, and Sinno Jialin Pan. 2023. Fast graph generation via spectral diffusion. IEEE Transactions on Pattern Analysis and Machine Intelligence (2023)
2023
-
[49]
Kaifeng Lyu and Jian Li. 2020. Gradient Descent Maximizes the Margin of Homogeneous Neural Networks. In ICLR
2020
-
[50]
Chenlin Meng, Yutong He, Yang Song, Jiaming Song, Jiajun Wu, Jun-Yan Zhu, and Stefano Ermon. 2022. SDEdit: Guided Image Synthesis and Editing with Stochastic Differential Equations. In ICLR
2022
-
[51]
Luis Müller, Mikhail Galkin, Christopher Morris, and Ladislav Rampášek. 2023. Attending to graph transformers. arXiv preprint arXiv:2302.04181 (2023)
2023 arXiv
-
[52]
Mor Shpigel Nacson, Suriya Gunasekar, Jason Lee, Nathan Srebro, and Daniel Soudry. [n. d.]. Lexicographic and depth-sensitive margins in homogeneous and non-homogeneous deep models. In ICML
-
[53]
Iyiola E Olatunji, Wolfgang Nejdl, and Megha Khosla. 2021. Membership inference attack on graph neural networks. In 2021 Third IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA) . IEEE, 11–20
2021
-
[54]
Noel M O’Boyle and Roger A Sayle. 2016. Comparing structural fingerprints using a literature-based similarity benchmark. Journal of cheminformatics 8 (2016), 1–14
2016
-
[55]
Kristina Preuer, Philipp Renz, Thomas Unterthiner, Sepp Hochreiter, and Günter Klambauer. 2018. Fréchet ChemNet Distance: A Metric for Generative Models for Molecules in Drug Discovery. Journal of Chemical Information and Modeling 58, 9 (2018), 1736–1741
2018
-
[56]
Aditya Ramesh, Prafulla Dhariwal, Alex Nichol, Casey Chu, and Mark Chen
-
[57]
Ladislav Rampášek, Michael Galkin, Vijay Prakash Dwivedi, Anh Tuan Luu, Guy Wolf, and Dominique Beaini. 2022. Recipe for a general, powerful, scalable graph transformer. Advances in Neural Information Processing Systems 35 (2022), 14501–14515
2022
-
[58]
Yang Song, Jascha Sohl-Dickstein, Diederik P Kingma, Abhishek Kumar, Ste- fano Ermon, and Ben Poole. 2021. Score-Based Generative Modeling through Stochastic Differential Equations. In ICLR. https://openreview.net/forum?id= PxTIG12RRHS
2021
-
[59]
Leonid Nisonovich Vaserstein. 1969. Markov processes over denumerable prod- ucts of spaces, describing large systems of automata. Problemy Peredachi Infor- matsii 5, 3 (1969), 64–72
1969
-
[60]
arXiv preprint arXiv:2204.06125 1, 2 (2022), 3
Hierarchical text-conditional image generation with clip latents. arXiv preprint arXiv:2204.06125 1, 2 (2022), 3
2022 arXiv
-
[61]
Binghui Wang, Minhua Lin, Tianxiang Zhou, Pan Zhou, Ang Li, Meng Pang, Hai Li, and Yiran Chen. 2024. Efficient, direct, and restricted black-box graph evasion attacks to any-layer graph neural networks via influence function. In Proceedings of the 17th ACM International Confer...
2024
-
[62]
Daixin Wang, Jianbin Lin, Peng Cui, Quanhui Jia, Zhen Wang, Yanming Fang, Quan Yu, Jun Zhou, Shuang Yang, and Yuan Qi. 2019. A Semi-supervised Graph Attentive Network for Financial Fraud Detection. In ICDM. 598–607
2019
-
[63]
Yuyang Wang, Jianren Wang, Zhonglin Cao, and Amir Barati Farimani. 2022. Molecular contrastive learning of representations via graph neural networks. Nature Machine Intelligence 4, 3 (2022), 279–287
2022
-
[64]
Clement Vignac, Igor Krawczuk, Antoine Siraudin, Bohan Wang, Volkan Cevher, and Pascal Frossard. 2023. DiGress: Discrete Denoising diffusion for graph generation. In ICLR
2023
-
[65]
Bang Wu, Xiangwen Yang, Shirui Pan, and Xingliang Yuan. 2022. Model extraction attacks on graph neural networks: Taxonomy and realisation. In Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security . 337–350
2022
-
[66]
Felix Wu, Amauri Souza, Tianyi Zhang, Christopher Fifty, Tao Yu, and Kilian Weinberger. 2019. Simplifying graph convolutional networks. In International conference on machine learning . 6861–6871
2019
-
[67]
Yixin Wu, Xinlei He, Pascal Berrang, Mathias Humbert, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. 2024. Link Stealing Attacks Against Inductive Graph Neural Networks. arXiv preprint arXiv:2405.05784 (2024)
2024 arXiv
-
[68]
David Weininger. 1988. SMILES, a chemical language and information system. 1. Introduction to methodology and encoding rules. Journal of chemical information and computer sciences 28, 1 (1988), 31–36
1988
-
[69]
Junjie Xu, Zongyu Wu, Minhua Lin, Xiang Zhang, and Suhang Wang. 2024. LLM and GNN are Complementary: Distilling LLM for Multimodal Graph Learning. arXiv preprint arXiv:2406.01032 (2024)
2024 arXiv
-
[70]
Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2018. How Powerful are Graph Neural Networks?. In ICLR
2018
-
[71]
Minkai Xu, Meng Liu, Wengong Jin, Shuiwang Ji, Jure Leskovec, and Stefano Ermon. 2023. Graph and geometry generative modeling for drug discovery. In SIGKDD. 5833–5834
2023
-
[72]
Zhenqin Wu, Bharath Ramsundar, Evan N Feinberg, Joseph Gomes, Caleb Ge- niesse, Aneesh S Pappu, Karl Leswing, and Vijay Pande. 2018. MoleculeNet: a benchmark for molecular machine learning.Chemical science 9, 2 (2018), 513–530
2018
-
[73]
Haotian Xue, Alexandre Araujo, Bin Hu, and Yongxin Chen. 2023. Diffusion-Based Adversarial Sample Generation for Improved Stealthiness and Controllability. In Thirty-seventh Conference on Neural Information Processing Systems
2023
-
[74]
Chengxuan Ying, Tianle Cai, Shengjie Luo, Shuxin Zheng, Guolin Ke, Di He, Yanming Shen, and Tie-Yan Liu. 2021. Do transformers really perform badly for graph representation? NeurIPS 34 (2021), 28877–28888
2021
-
[75]
Rex Ying, Ruining He, Kaifeng Chen, Pong Eksombatchai, William L Hamilton, and Jure Leskovec. 2018. Graph convolutional neural networks for web-scale recommender systems. In SIGKDD. 974–983
2018
-
[76]
Minkai Xu, Lantao Yu, Yang Song, Chence Shi, Stefano Ermon, and Jian Tang. 2022. Geodiff: A geometric diffusion model for molecular conformation generation. arXiv preprint arXiv:2203.02923 (2022)
2022 arXiv
-
[77]
Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals
-
[78]
Jiawei Zhang, Haopeng Zhang, Congying Xia, and Li Sun. 2020. Graph-bert: Only attention is needed for learning graph representations. arXiv preprint arXiv:2001.05140 (2020)
2020 arXiv
-
[79]
Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, and Yang Zhang. 2022. Infer- ence attacks against graph neural networks. In 31st USENIX Security Symposium (USENIX Security 22). 4543–4560
2022
-
[80]
Hao Yuan, Jiliang Tang, Xia Hu, and Shuiwang Ji. 2020. Xgnn: Towards model- level explanations of graph neural networks. In SIGKDD. 430–438
2020
-
[81]
Zhiwei Zhang, Minhua Lin, Junjie Xu, Zongyu Wu, Enyan Dai, and Suhang Wang
-
[82]
Understanding deep learning (still) requires rethinking generalization. Commun. ACM 64, 3 (2021), 107–115
2021
-
[85]
Zhiwei Zhang, Minhua Lin, Enyan Dai, and Suhang Wang. 2024. Rethinking graph backdoor attacks: A distribution-preserving perspective. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 4386–4397
2024
-
[88]
Zaixi Zhang, Qi Liu, Zhenya Huang, Hao Wang, Chengqiang Lu, Chuanren Liu, and Enhong Chen. 2021. GraphMI: Extracting Private Graph Data from Graph Neural Networks. In Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, IJCAI-21. 3749–3755. S...
2021
-
[2019]
In The world wide web conference
Graph neural networks for social recommendation. In The world wide web conference. 417–426
-
[2021]
In 30th USENIX Security Sym- posium (USENIX Security 21)
Stealing links from graph neural networks. In 30th USENIX Security Sym- posium (USENIX Security 21) . 2669–2686
-
[2022]
In International confer- ence on machine learning
Equivariant diffusion for molecule generation in 3d. In International confer- ence on machine learning . PMLR, 8867–8887
-
[2024]
arXiv preprint arXiv:2406.09836 (2024)
Robustness-Inspired Defense Against Backdoor Attacks on Graph Neural Networks. arXiv preprint arXiv:2406.09836 (2024)
2024 arXiv
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.