Data-Free Graph Property Inference Attacks From Graph Embeddings: Data-Free Helps Data-Available

Document Type

Article

Publication Date

1-1-2026

Abstract

Recently, some studies have shown that it is feasible for an adversary to train a graph property inference (GPI) network to infer the privacy-sensitive properties of an original graph data from its graph embedding depending on the assumption that the adversary owns a high-quality auxiliary graph dataset. However, such a data availability assumption is too strong, making such GPI attacks impractical in many real-world attack scenarios. In this paper, we make the first systematic study on GPI attacks from graph embeddings in the data-free setting. To address the issue of no training dataset, we develop the cross-task generator transfer technique, which helps to train a fake graph generator (named GPI-generator). The well-trained GPI-generator can generate fake graph samples used for the GPI network training. In addition, we develop the knowledge distillation (KD)-accelerable adversarial training strategy and the student-aided back propagation (BP) strategy to reduce resource consumption in the GPI-generator training process. Furthermore, as a key insight of this paper, we discover that the developed attack technique in the data-free setting can be used for data augmentation and hence helps to boost the performance of multiple attacks in the data-available setting. Therefore, our study makes broader impacts on machine learning (ML) security research. Finally, we investigate the perturbation-based defenses, shedding light on more effective defense design.

Publication Title

IEEE Transactions on Dependable and Secure Computing

Share

COinS