Guard the Vertical Federated Graph Learning from Property Inference Attack
摘要
Graph Neural Networks (GNNs) have been widely applied due to their powerful feature extraction capability on graph-structured data. At practice, they typically suffer from the large-scale data collection challenge of centralized training, i.e., some institutions own some of the features of the data while they need to protect the privacy of the local data. Therefore, Vertical Federated Graph Learning (VFGL) is gaining popularity as a framework that allows multiple research institutions to jointly train GNNs by switching embedded features instead of sharing the raw data of each client. Unfortunately, there remains an inherent danger of leakage of private data during the training process of VFGL. In this work, we characterize this attack as a Property Inference Attack (PiAttack) and present a novel framework to address this problem. To be specific, we first develop a fake label generator for getting a uniform distribution of labels, and then we design a noise generator to guard sensitive attributes. Moreover, we introduce specific constraints on perturbations to maintain the accuracy of the task. An extensive evaluation of both tasks on seven real-world datasets indicates that ours achieves state-of-the-art performance at the same time as the trade-off between privacy preservation and task accuracy is maintained.