paper-with-me

Papers

Model Extraction Attacks on Graph Neural Networks: Taxonomy and Realization

2020-10-24 · Bang Wu, Xiangwen Yang, Shirui Pan, Xingliang Yuan

Machine learning models are shown to face a severe threat from Model Extraction Attacks, where a well-trained private model owned by a service provider can be stolen by an attacker pretending as a client. Unfortunately, prior works focus on the models trained over the Euclidean space, e.g., images and texts, while how to extract a GNN model that contains a graph structure and node features is yet to be explored. In this paper, for the first time, we comprehensively investigate and develop model extraction attacks against GNN models. We first systematically formalise the threat modelling in the context of GNN model extraction and classify the adversarial threats into seven categories by considering different background knowledge of the attacker, e.g., attributes and/or neighbour connections of the nodes obtained by the attacker. Then we present detailed methods which utilise the accessible knowledge in each threat to implement the attacks. By evaluating over three real-world datasets, our attacks are shown to extract duplicated models effectively, i.e., 84% - 89% of the inputs in the target domain have the same output predictions as the victim model.

📄 PDF Abstract BibTeX arXiv:2010.12751

Code (1)

TrustworthyGNN/MEA-GNN 공식 구현 pytorch

Tasks

Anomaly DetectionModel extraction

Similar Papers 제목 키워드 기반

SoK: Pitfalls in Evaluating Black-Box Attacks

2023-10-26 · Fnu Suya, Anshuman Suri, Tingwei Zhang, Jingtao Hong 외

Numerous works study black-box attacks on image classifiers. However, these works make different assumptions on the adversary's knowledge and current literature lacks a cohesive organization centered around the threat mo…

Optimal Controller Realizations against False Data Injections in Cooperative Driving

2024-04-08 · Mischa Huisman, Carlos Murguia, Erjen Lefeber, Nathan van de Wouw

To enhance the robustness of cooperative driving to cyberattacks, we study a controller-oriented approach to mitigate the effect of a class of False-Data Injection (FDI) attacks. By reformulating a given dynamic Cooperat…

Hybrid Control as a Proxy for Detection and Mitigation of Sensor Attacks in Cooperative Driving

2025-04-08 · Mischa Huisman, Carlos Murguia, Erjen Lefeber, Nathan van de Wouw

To enhance the robustness of cooperative driving against cyberattacks, we propose a hybrid controller scheme to detect and mitigate False-Data Injection (FDI) attacks in real-time. The core of our method builds on a give…

Stealing Links from Graph Neural Networks

2020-05-05 · Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong 외

Graph data, such as chemical networks and social networks, may be deemed confidential/private because the data owner often spends lots of resources collecting the data or the data contains sensitive information, e.g., so…

Fraud DetectionRecommendation Systems

HiFi-KPI: A Dataset for Hierarchical KPI Extraction from Earnings Filings

2025-02-21 · Rasmus Aavang, Giovanni Rizzi, Rasmus Bøggild, Alexandre Iolov 외

The U.S. Securities and Exchange Commission (SEC) requires that public companies file financial reports tagging numbers with the machine readable inline eXtensible Business Reporting Language (iXBRL) standard. However, t…