Defending against Model Extraction for GNNs with Model Reprogramming
arXiv:2608. 11495v1 Announce Type: new Abstract: Graph Neural Networks (GNNs) serve as the backbone for high-stakes applications in Machine-Learning-as-a-Service (MLaaS).
arXiv:2607. 18567v1 Announce Type: new Abstract: A graph foundation model generalizes across graph domains by mapping every input into one shared representation before any task reasoning.
arXiv:2608. 11495v1 Announce Type: new Abstract: Graph Neural Networks (GNNs) serve as the backbone for high-stakes applications in Machine-Learning-as-a-Service (MLaaS).
arXiv:2606. 29748v1 Announce Type: new Abstract: The application of graph data in numerous disciplines raises the need for gathering and analyzing huge volumes of data, some of which is private and sensitive.
arXiv:2606. 08067v1 Announce Type: new Abstract: Graph neural networks (GNNs) are widely deployed on relational data, yet they can leak sensitive or proprietary information about the training graph adjacency, e.
Kernel-Complexity Edge Sanitization (KCES) is a training‑free, model‑agnostic defense for Graph Neural Networks that identifies and removes edges with high Kernel‑Complexity (KC) scores, which are indicative of structural influence on the graph kernel complexity metric. KCES leverages a theoretical upper bound on GNN test error derived from the graph Gram matrix to compute edge‑specific KC scores, pruning edges that are empirically enriched with adversarial perturbations. The method is computationally efficient, scalable to large graphs, and consistently outperforms representative robust baselines across diverse attack settings without requiring retraining.
arXiv:2608.29054v1 Announce Type: new Abstract: Graph Neural Networks (GNNs) have emerged as a cornerstone for representing complex relational dependencies in diverse multimedia tasks, particularly i...
arXiv:2609.37972v1 Announce Type: cross Abstract: As Graph Neural Networks (GNNs) are widely deployed as Machine Learning-as-a-Service (MLaaS) APIs, model stealing attacks have emerged as a critical...
arXiv:2606. 08467v1 Announce Type: cross Abstract: While confidence calibration is essential for trustworthy decision-making in safety-critical applications, the robustness of calibrated GNNs to adversarial structural perturbations remains largely unexplored.
Graph Machine Learning as a Service platforms now offer explainability interfaces to satisfy regulatory transparency, but this transparency can be exploited. The paper introduces a novel model extraction attack for graph classification that operates under strict black‑box constraints, using only discrete class labels and binary explanation masks. The method guides Monte Carlo edge sensitivity estimation toward decision boundaries with Hoeffding guarantees and narrows the search space using explanation subgraphs, outperforming comparable baselines on benchmark datasets.
arXiv:2606. 29240v1 Announce Type: new Abstract: Heterogeneous graph neural networks (HGNNs) have achieved strong performance in modeling complex graph-structured data with multiple node and relation types.
arXiv:2503. 00065v4 Announce Type: replace-cross Abstract: Graph Neural Networks (GNNs) achieve high performance in various real-world applications, such as drug discovery, traffic states prediction, and recommendation systems.
arXiv:2511.10936v3 Announce Type: replace-cross Abstract: Graph unlearning (GU) has emerged as a promising solution to comply with "the right to be forgotten" regulations by enabling the removal of s...
The paper introduces STAG, a stealthy trojan attack framework targeting Graph Foundation Models (GFMs) that operate on text‑attributed graphs (TAGs). STAG jointly generates graph triggers and soft‑prompt text cues so that both modalities converge to a malicious target class while keeping the trigger subgraph structurally similar to the original and the trigger text readable. Experiments on several TAG datasets and GFMs confirm that STAG achieves high attack success rates while remaining difficult to detect.