arXiv AI

Do Explanations Increase the Risk of Decision Logic Leakage? Explanation-Guided Stealing of Graph Models

arXiv:2506. 03087v2 Announce Type: replace-cross Abstract: Graph Neural Networks (GNNs) have become essential tools for analyzing graph-structured data in domains such as drug discovery and financial analysis, leading to a growing demand for model transparency.

arXiv Machine Learning
Aug 31

Can Subgraph Explanations Be Weaponized to Steal Graph Neural Networks?

Graph Machine Learning as a Service platforms now offer explainability interfaces to satisfy regulatory transparency, but this transparency can be exploited. The paper introduces a novel model extraction attack for graph classification that operates under strict black‑box constraints, using only discrete class labels and binary explanation masks. The method guides Monte Carlo edge sensitivity estimation toward decision boundaries with Hoeffding guarantees and narrows the search space using explanation subgraphs, outperforming comparable baselines on benchmark datasets.

By Ojas Nimase, Jiate Li, Yue Zhao, Yushun Dong
arXiv Machine Learning
Jun 8

ADAGE: Active Defenses Against GNN Extraction

arXiv:2503. 00065v4 Announce Type: replace-cross Abstract: Graph Neural Networks (GNNs) achieve high performance in various real-world applications, such as drug discovery, traffic states prediction, and recommendation systems.

By Jing Xu, Franziska Boenisch, Adam Dziedzic
arXiv Machine Learning
1d ago

WOMBAT: Whitebox Oracle for Molecular Benchmarking and Attribution Testing

WOMBAT is a benchmark comprising 14 whitebox graph neural networks (GNNs) whose message‑passing weights are manually set to detect specific SMARTS motifs. Each model’s decision rule is explicitly known, providing a ground truth for attribution that allows researchers to identify and study errors in post‑hoc explainers such as GNNExplainer, PGExplainer, and Integrated Gradients. The authors validate the models on millions of PubChem molecules, demonstrate how Integrated Gradients can be misled to spread attribution, and release the dataset, models, and evaluation code for future XAI tool development.

By Dominik Matuszek, Bartosz Zieli\'nski, Tomasz Danel, Dawid Rymarczyk
arXiv Machine Learning
Jul 9

Structural Adversarial Attacks on Relational Deep Learning under Integrity Constraints

arXiv:2607. 07089v1 Announce Type: new Abstract: Relational Deep Learning (RDL) has become a standard methodology for machine learning on relational databases: the database is encoded as a heterogeneous temporal graph in which tuples become nodes and primary-key to foreign-key (PK-FK) dependencies become typed edges, over which a graph neural network is trained for downstream prediction.

By Alan Gany, Bogdan Cautis, Silviu Maniu
Hugging Face Trending Papers
Jul 8

Structural Adversarial Attacks on Relational Deep Learning under Integrity Constraints

Relational Deep Learning (RDL) has become a standard methodology for machine learning on relational databases: the database is encoded as a heterogeneous temporal graph in which tuples become nodes and primary-key to foreign-key (PK-FK) dependencies become typed edges, over which a graph neural network is trained for downstream prediction. We study the adversarial robustness of this pipeline.