PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
October 8, 20251 citationsOpen Access

Unlearning Inversion Attacks for Graph Neural Networks

View Full Paper
JZJiahao ZhangYWYilong WangZZZhiwei Zhang

Key Points

  • The proposed inversion attack effectively reconstructs removed edges from graph neural networks.
  • Key challenges include varied probability thresholds for unlearned and retained edges, impacting model confidence.
  • By exploiting the confidence pitfall, TrendAttack significantly enhances membership inference techniques.
  • Experiments on multiple datasets validate TrendAttack as a robust method against existing graph unlearning defenses.

Abstract

Graph unlearning methods aim to efficiently remove the impact of sensitive data from trained GNNs without full retraining, assuming that deleted information cannot be recovered. In this work, we challenge this assumption by introducing the graph unlearning inversion attack: given only black-box access to an unlearned GNN and partial graph knowledge, can an adversary reconstruct the removed edges? We identify two key challenges: varying probability-similarity thresholds for unlearned versus retained edges, and the difficulty of locating unlearned edge endpoints, and address them with TrendAttack. First, we derive and exploit the confidence pitfall, a theoretical and empirical pattern showing that nodes adjacent to unlearned edges exhibit a large drop in model confidence. Second, we design an adaptive prediction mechanism that applies different similarity thresholds to unlearned and other membership edges. Our framework flexibly integrates existing membership inference techniques and extends them with trend features. Experiments on four real-world datasets demonstrate that TrendAttack significantly outperforms state-of-the-art GNN membership inference baselines, exposing a critical privacy vulnerability in current graph unlearning methods.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Zhang et al. (2025) studied this question.

synapsesocial.com/papers/68e6f342f8145af55aeacc36https://doi.org/10.48550/arxiv.2506.00808
Ask AI
Helpful
Bookmark
Share
View Full Paper