arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

隐私保护知识图谱上的链接推断攻击

Link Inference Attack on Privacy-Preserving Knowledge Graphs

Emna Bouguerra, Ibtissam Harrouche, Ferran Alborch, Melek Önen

arXiv 2609.39362首次发表:更新:

发表机构

EURECOM(欧瑞康研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出一种针对隐私保护知识图谱的链接推断攻击,利用公开图谱的拓扑结构痕迹高精度恢复被隐藏的关系,并揭示隐私风险在不同实体和关系间的不均匀分布。

AI 中文摘要

知识图谱(KGs)被广泛用于在医疗、金融和社交网络等敏感领域中存储和共享结构化信息。一种常见的隐私保护做法是在发布图谱前删除敏感关系,其假设是移除边足以防止这些关系被恢复。在本文中,我们挑战了这一假设,并表明即使某个关系被完全或部分隐藏,其存在仍会在公开图谱中留下结构痕迹,这些痕迹可以被利用来以高精度恢复该关系。为此,我们提出了一种基于公开图谱拓扑结构的链接推断攻击,并在两种隐私场景下对其进行评估,这两种场景的区别在于攻击者如何利用其可获取的知识。在第一种场景中,攻击者利用所有拓扑信息,攻击达到了近乎完美的区分能力(AP = 0.949,ROC-AUC = 0.999);而在更现实的场景中,攻击者利用部分语义信息,能够恢复高达74%的隐藏边。基于这些结果,我们进一步进行了结构分析,以识别图谱中哪些拓扑属性驱动了攻击的成功,揭示出隐私风险在不同实体间并非均匀分布,且某些结构模式使特定关系比其他关系更容易受到推断攻击。

英文摘要

Knowledge Graphs (KGs) are widely used to store and share structured information across sensitive domains such as healthcare, fi- nance, and social networks. A common privacy practice is to delete sen- sitive relations before publishing the graph, under the assumption that removing edges is sufficient to prevent their recovery. In this paper, we challenge this assumption and show that even when a relation is fully or partially hidden, its existence leaves structural traces in the public graph that can be exploited to recover it with high accuracy. To this end, we propose a link inference attack that operates on the topology of the public graph, and evaluate it under two privacy scenarios that differ in how the adversary exploits the knowledge available to him. In the first setting where the adversary exploits all topological information, the attack achieves near-perfect discrimination (AP = 0.949, ROC-AUC = 0.999), while in the more realistic one where the adversary makes use of some semantic information, it recovers up to 74% of hidden edges. Build- ing on these results, we further conduct a structural analysis to identify which topological properties of the graph drive the attack success, re- vealing that privacy risk is not uniform across entities and that certain structural patterns make specific relations significantly more vulnerable to inference than others.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑