Pith. sign in

REVIEW 5 cited by

Node-Level Membership Inference Attacks Against Graph Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2102.05429 v1 pith:LSFQRXRJ submitted 2021-02-10 cs.CR cs.LG

classification cs.CRcs.LG
keywords attacksgnnsgraphinferencemembershipmodelsnode-leveldata
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Many real-world data comes in the form of graphs, such as social networks and protein structure. To fully utilize the information contained in graph data, a new family of machine learning (ML) models, namely graph neural networks (GNNs), has been introduced. Previous studies have shown that machine learning models are vulnerable to privacy attacks. However, most of the current efforts concentrate on ML models trained on data from the Euclidean space, like images and texts. On the other hand, privacy risks stemming from GNNs remain largely unstudied. In this paper, we fill the gap by performing the first comprehensive analysis of node-level membership inference attacks against GNNs. We systematically define the threat models and propose three node-level membership inference attacks based on an adversary's background knowledge. Our evaluation on three GNN structures and four benchmark datasets shows that GNNs are vulnerable to node-level membership inference even when the adversary has minimal background knowledge. Besides, we show that graph density and feature similarity have a major impact on the attack's success. We further investigate two defense mechanisms and the empirical results indicate that these defenses can reduce the attack performance but with moderate utility loss.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Impact of Graph Structure on Membership-Inference Risk for Graph Neural Networks

    cs.LG 2026-01 conditional novelty 6.0 of 10

    Graph construction and inference-time edge access modulate node-level membership-inference advantage in GNNs, and the generalization gap is an incomplete proxy.

  2. Who Owns This Sample: Cross-Client Membership Inference Attack in Federated Graph Neural Networks

    cs.LG 2025-07 reject novelty 6.0 of 10

    A malicious client in federated graph learning can infer which client owns a node by combining gradient eavesdropping, graph reconstruction, and class-prototype matching.

  3. SoK: Data Reconstruction Attacks Against Machine Learning Models: Definition, Metrics, and Benchmark

    cs.CR 2025-06 conditional novelty 5.0 of 10

    The authors define data reconstruction attacks and measure them with dataset-level FID, sample-level distance and coverage, and an LLM visual judge, finding reconstruction quality tracks memorization.

  4. An Out-Of-Distribution Membership Inference Attack Approach for Cross-Domain Graph Attacks

    cs.LG 2025-05 reject novelty 5.0 of 10

    GOOD-MIA combines invariant risk minimization, a graph information bottleneck, and risk extrapolation to run membership inference attacks against graph neural networks across different data domains.

  5. Intellectual Property in Graph-Based Machine Learning as a Service: Attacks and Defenses

    cs.CR 2025-08 conditional novelty 4.0 of 10

    A systematic review that organizes graph-ML IP protection into model-level and data-level attacks and defenses, and ships a benchmark library, PyGIP.

Pith tools