AIセキュリティポータル K Program
Label Inference Attacks against Node-level Vertical Federated GNNs
Share
Abstract
Federated learning enables collaborative training of machine learning models by keeping the raw data of the involved workers private. Three of its main objectives are to improve the models' privacy, security, and scalability. Vertical Federated Learning (VFL) offers an efficient cross-silo setting where a few parties collaboratively train a model without sharing the same features. In such a scenario, classification labels are commonly considered sensitive information held exclusively by one (active) party, while other (passive) parties use only their local information. Recent works have uncovered important flaws of VFL, leading to possible label inference attacks under the assumption that the attacker has some, even limited, background knowledge on the relation between labels and data. In this work, we are the first (to the best of our knowledge) to investigate label inference attacks on VFL using a zero-background knowledge strategy. To formulate our proposal, we focus on Graph Neural Networks (GNNs) as a target model for the underlying VFL. In particular, we refer to node classification tasks, which are widely studied, and GNNs have shown promising results. Our proposed attack, BlindSage, provides impressive results in the experiments, achieving nearly 100% accuracy in most cases. Even when the attacker has no information about the used architecture or the number of classes, the accuracy remains above 90% in most instances. Finally, we observe that well-known defenses cannot mitigate our attack without affecting the model's performance on the main classification task.
The political blogosphere and the 2004 US election: divided they blog
Lada A Adamic, Natalie Glance
Published: 2005
On the bottleneck of graph neural networks and its practical implications
Uri Alon, Eran Yahav
Published: 2020
signsgd: Compressed optimisation for non-convex problems
Jeremy Bernstein, Yu-Xiang Wang, Kamyar Azizzadenesheli, Animashree Anandkumar
Published: 2018
A model to support multi-social-network applications
Francesco Buccafurri, Gianluca Lax, Serena Nicolazzo, Antonino Nocera
Published: 2014
Discovering missing me edges across social networks
Francesco Buccafurri, Gianluca Lax, Antonino Nocera, Domenico Ursino
Published: 2015
Graph-fraudster: Adversarial attacks on graph neural network-based vertical federated learning
J. Chen, G. Huang, H. Zheng, S. Yu, W. Jiang, C. Cui
Published: 2022
Estimating the optimal number of clusters in categorical data clustering by silhouette coefficient
Duy-Tai Dinh, Tsutomu Fujinami, Van-Nam Huynh
Published: 2019
Label inference attacks against vertical federated learning
C. Fu, X. Zhang, S. Ji, J. Chen, J. Wu, S. Guo, J. Zhou, A. X. Liu, T. Wang
Published: 2022
Deep learning with label differential privacy
Badih Ghazi, Noah Golowich, Ravi Kumar, Pasin Manurangsi, Chiyuan Zhang
Published: 2021
Citeseer: An automatic citation indexing system
C Lee Giles, Kurt D Bollacker, Steve Lawrence
Published: 1998
Inductive representation learning on large graphs
Will Hamilton, Zhitao Ying, Jure Leskovec
Published: 2017
Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
Briland Hitaj, Giuseppe Ateniese, Fernando Perez-Cruz
Published: 2017.2.24
Open graph benchmark: Datasets for machine learning on graphs
Weihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong, Hongyu Ren, Bowen Liu, Michele Catasta, Jure Leskovec
Published: 2021
Advances and open problems in federated learning
Peter Kairouz, H. Brendan McMahan, Brendan Avent, Aurélien Bellet, Mehdi Bennis, Arjun Nitin Bhagoji, Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, Rafael G. L. D’Oliveira, Hubert Eichner, Salim El Rouayheb, David Evans, Josh Gardner, Zachary Garrett, Adrià Gascón, Badih Ghazi, Phillip B. Gibbons, Marco Gruteser, Zaid Harchaoui, Chaoyang He, Lie He, Zhouyuan Huo, Ben Hutchinson, Justin Hsu, Martin Jaggi, Tara Javidi, Gauri Joshi, Mikhail Khodak, Jakub Konecný, Aleksandra Korolova, Farinaz Koushanfar, Sanmi Koyejo, Tancrède Lepoint, Yang Liu, Prateek Mittal, Mehryar Mohri, Richard Nock, Ayfer Özgür, Rasmus Pagh, Hang Qi, Daniel Ramage, Ramesh Raskar, Mariana Raykova, Dawn Song, Weikang Song, Sebastian U. Stich, Ziteng Sun, Ananda Theertha Suresh, Florian Tramèr, Praneeth Vepakomma, Jianyu Wang, Li Xiong, Zheng Xu, Qiang Yang, Felix X. Yu, Han Yu, Sen Zhao
Published: 2021
Semi-supervised classification with graph convolutional networks
Thomas N Kipf, Max Welling
Published: 2017
Federated Learning: Strategies for Improving Communication Efficiency
Jakub Konečný, H. Brendan McMahan, Felix X. Yu, Peter Richtárik, Ananda Theertha Suresh, Dave Bacon
Published: 2016.10.18
Label leakage and protection in two-party split learning
O. Li, J. Sun, X. Yang, W. Gao, H. Zhang, J. Xie, V. Smith, C. Wang
Published: 2022
A survey on federated learning systems: Vision, hype and reality for data privacy and protection
Qinbin Li, Zeyi Wen, Zhaomin Wu, Sixu Hu, Naibo Wang, Yuan Li, Xu Liu, Bingsheng He
Published: 2021
Alleviating the inconsistency problem of applying graph neural network to fraud detection
Zhiwei Liu, Yingtong Dou, Philip S Yu, Yutong Deng, Hao Peng
Published: 2020
Federated social recommendation with graph neural network
Zhiwei Liu, Liangwei Yang, Ziwei Fan, Hao Peng, Philip S Yu
Published: 2022
Heterogeneous graph neural networks for malicious account detection
Ziqi Liu, Chaochao Chen, Xinxing Yang, Jun Zhou, Xiaolong Li, Le Song
Published: 2018
Feature inference attack on model predictions in vertical federated learning
X. Luo, Y. Wu, X. Xiao, B. C. Ooi
Published: 2021
Automating the construction of internet portals with machine learning
Andrew Kachites McCallum, Kamal Nigam, Jason Rennie, Kristie Seymore
Published: 2000
hdbscan: Hierarchical density based clustering
Leland McInnes, John Healy, Steve Astels
Published: 2017
Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
Milad Nasr, Reza Shokri, Amir Houmansadr
Published: 2018.12.4
Graph neural networks exponentially lose expressive power for node classification
Kenta Oono, Taiji Suzuki
Published: 2019
Privacy-preserving news recommendation model learning
Tao Qi, Fangzhao Wu, Chuhan Wu, Yongfeng Huang, Xing Xie
Published: 2020
Your labels are selling you out: Relation leaks in vertical federated learning
Pengyu Qiu, Xuhong Zhang, Shouling Ji, Tianyu Du, Yuwen Pu, Jun Zhou, Ting Wang
Published: 2022
Collective classification in network data
Prithviraj Sen, Galileo Namata, Mustafa Bilgic, Lise Getoor, Brian Galligher, Tina Eliassi-Rad
Published: 2008
Privacy-preserving deep learning
Reza Shokri, Vitaly Shmatikov
Published: 2015
Linking accounts across social networks: the case of stackoverflow, github and twitter
Giuseppe Silvestri, Jie Yang, Alessandro Bozzon, Andrea Tagarelli
Published: 2015
Soft-label dataset distillation and text dataset distillation
Ilia Sucholutsky, Matthias Schonlau
Published: 2021
Graph Attention Networks
Petar Velickovic, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, Yoshua Bengio
Published: 2018
User identification across multiple social networks
Jan Vosecky, Dan Hong, Vincent Y Shen
Published: 2009
Graphfl: A federated learning framework for semi-supervised node classification on graphs
Binghui Wang, Ang Li, Meng Pang, Hai Li, Yiran Chen
Published: 2022
Graph neural networks: foundation, frontiers and applications
Lingfei Wu, Peng Cui, Jian Pei, Liang Zhao, Xiaojie Guo
Published: 2022
How powerful are graph neural networks?
K. Xu, W. Hu, J. Leskovec, S. Jegelka
Published: 2019
Federated machine learning: Concept and applications
Qiang Yang, Yang Liu, Tianjian Chen, Yongxin Tong
Published: 2019
Graph convolutional neural networks for web-scale recommender systems
Rex Ying, Ruining He, Kaifeng Chen, Pong Eksombatchai, William L Hamilton, Jure Leskovec
Published: 2018
Asfgnn: Automated separated-federated graph neural network
Longfei Zheng, Jun Zhou, Chaochao Chen, Bingzhe Wu, Li Wang, Benyu Zhang
Published: 2021
Graph neural networks: A review of methods and applications
Jie Zhou, Ganqu Cui, Shengding Hu, Zhengyan Zhang, Cheng Yang, Zhiyuan Liu, Lifeng Wang, Changcheng Li, Maosong Sun
Published: 2020
Defending batch-level label inference and replacement attacks in vertical federated learning
T. Zou, Y. Liu, Y. Kang, W. Liu, Y. He, Z. Yi, Q. Yang, Y.-Q. Zhang
Published: 2022
Share