Query-Efficient Adversarial Attack Against Vertical Federated Graph Learning
摘要
Graph neural networks (GNNs) are becoming more widely used due to their capacity to understand graph structures and learn graph representations of data. However, the performance of GNN is limited by distributing data silos. Vertical federated learning (VFL) enables GNN to process distributed graph-structured data. While vertical federated graph learning (VFGL) has experienced prosperous development, its robustness against adversarial attacks has not been fully explored. Although there have been numerous adversarial attacks against centralized GNNs, their effectiveness in a VFGL scenario is questionable. This paper proposes the first adversarial attack against VFGL, using a query-efficient hybrid adversarial attack framework, \(\underline{N }\) euron-based \(\underline{A }\) dversarial \(\underline{A }\) ttack. In this scenario, a deceitful client alters its own local training data in a covert manner to enhance its overall contribution. Then, a shadow model is created using the manipulated data to imitate the behavior of the server model in VFGL. Consequently, the shadow model can significantly boost the success rate of centralized attacks with minimal queries. Multiple tests conducted on four real-world benchmarks show that our method can enhance the performance of centralized adversarial attacks against VFGL, surpassing existing standards, even in cases where the defender is aware of the attack method. Moreover, we offer clear and understandable tests of the effectiveness of ours through identifying sensitive neurons and visualizing t-SNE.