Defenses against adversarial attacks on neural networks for graph data via encryption and disturbing
Abstract
The recent progress in exploiting neural networks based on graphs (GNNs) and safeguarding nodes anonymity on graph data has garnered a lot of interest. These two crucial functions are not yet integrated by the eye. Envision a scenario where an adversary in a community of people may deduce users' private labels using the strong GNNs. How can we protect disturbed graphs against privacy attacks in an adversarial way without sacrificing their usefulness? To combat adversarial defenses to GNN-based privacy assaults, a new area of study, we introduce NetFense, a graph perturbation-based method. At the same time that it can preserve data utility by reducing the prediction confidence of private label categorization and keep graph data undetected capacity (i.e., having limited changes on the graph framework), NetFense can also reduce forecasting confidence of targeted label classification and protect node privacy. The perturbed graphs generated by NetFense can successfully preserve data utility (i.e., model unnoticed ability) on targeted label classification while drastically lowering the prediction confidence of private label categorization (i.e., privacy protection), according to experiments performed on ingle- and multiple-target perturbations using three real graph datasets. The adaptability of NetFense, the maintenance of local neighborhoods in data undetected capabilities, and improved privacy protection for high-degree nodes are only a few of the discoveries that have been uncovered by extensive experiments.
How this paper connects to the literature. Drag to explore, click any node to open that paper.
