Revisiting Asymmetries in Black-box Link Stealing against Graph Neural Networks
Abstract
Lay Summary
Graph Neural Networks (GNNs) are widely used to analyze connected data such as social networks, recommendation systems, and healthcare records. Although these systems typically expose only prediction outputs, our work shows that these outputs can still reveal private relationships hidden in the original data. We study whether an attacker can determine if two people or records were connected in the training data simply by observing a model’s predictions. Unlike prior work that focuses on average attack performance, we examine high-risk situations where attackers aim to make very few mistakes while still uncovering sensitive links. Our results show that these privacy risks remain significant even under strict conditions. We also develop a new method that exposes hidden vulnerabilities missed by existing evaluations, revealing that current graph-based AI systems may leak more sensitive relationship information than previously understood.