arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.37972cs.CRcs.AIcs.LG

Dagger:基于解耦的图神经网络模型窃取攻击

Dagger: Decoupling-based Model Stealing Attack against Graph Neural Networks

Ying Song, Xiaowei Jia, Balaji Palanisamy

首次发表
浏览论文内容

中文总结 AI 辅助

针对图神经网络模型窃取攻击,提出两阶段解耦攻击框架Dagger,在严格黑盒硬标签和有限查询预算下,通过解耦信息传播与流形混合及类别平衡微调,实现高保真窃取,查询效率显著提升。

中文摘要 AI 辅助

随着图神经网络(GNNs)作为机器学习即服务(MLaaS)API被广泛部署,模型窃取攻击已成为一个关键的安全威胁。通过查询受害者模型的黑盒API,攻击者可以构建一个功能等效的替代模型,从而危及专有知识产权和下游安全。然而,现有的GNN窃取攻击依赖于过于宽松的假设,例如软标签输出、大量查询预算、全图查询访问以及受害者骨干网络的先验知识,这些假设在现实部署中很少成立。在这项工作中,我们形式化了一个严格受限的黑盒、硬标签且骨干无关的GNN窃取攻击威胁模型,并设置了严格的查询预算。鉴于这些现实限制,我们识别出四个基本挑战:稀疏局部结构和孤立节点降低了受害者标签质量,监督信号不足,系统性的类别不平衡且类别覆盖不完整,以及骨干网络不匹配。为了解决这些相互关联的障碍,我们提出了Dagger,一种新颖的两阶段基于解耦的攻击框架。具体而言,在第一阶段,Dagger使用解耦信息传播预训练替代模型,以在稀疏局部子图上保留结构上下文,同时处理孤立节点,并结合流形级节点混合来合成连续的监督信号并平滑决策边界。在第二阶段,Dagger冻结编码器,并通过类别平衡采样结合对数调整来微调分类器头,以纠正严重的查询不平衡,而无需额外的受害者查询。在四个基准图和四个GNN骨干网络上的大量实验表明,Dagger始终优于最先进的GNN窃取攻击,在仅使用比最强基线少12.23倍的查询的情况下,实现了高达18.16%更高的保真度。

英文摘要

As Graph Neural Networks (GNNs) are widely deployed as Machine Learning-as-a-Service (MLaaS) APIs, model stealing attacks have emerged as a critical security threat. By querying a victim model's black-box API, an adversary can construct a functionally equivalent surrogate model, compromising proprietary intellectual property and downstream security. Existing GNN stealing attacks, however, rely on overly permissive assumptions, such as soft-label outputs, large query budgets, full-graph query access, and prior knowledge of victim backbones that rarely hold in real-world deployments. In this work, we formalize a strictly constrained black-box, hard-label and backbone-agnostic threat model for GNN stealing attacks under a tight query budget. Given these realistic restrictions, we identify four fundamental challenges: sparse local structures and isolated nodes that degrade victim label quality, insufficient supervision signals, systematic imbalance with incomplete class coverage, and backbone mismatch. To address these interlocking barriers, we propose Dagger, a novel two-phase decoupling-based attack framework. Specifically, in Phase 1, Dagger pre-trains a surrogate using decoupled information propagation to preserve structural context over sparse local subgraphs while handling isolated nodes, combined with manifold-level node mixup to synthesize continuous supervision signals and smooth decision boundaries. In Phase 2, Dagger freezes the encoder and fine-tunes the classifier head via class-balanced sampling paired with logit adjustment to rectify severe query imbalance without requiring extra victim queries. Extensive experiments across four benchmark graphs and four GNN backbones demonstrate that Dagger consistently outperforms state-of-the-art GNN stealing attacks, achieving up to 18.16\% higher fidelity while only utilizing 12.23$\times$ fewer queries than the strongest baseline.

发表机构

  • University of Pittsburgh(匹兹堡大学)
  • Rutgers University(罗格斯大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑