{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T07:37:27Z","timestamp":1783409847141,"version":"3.54.6"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Australia ARC","award":["LP220100453"],"award-info":[{"award-number":["LP220100453"]}]},{"name":"ARC","award":["DP200101374"],"award-info":[{"award-number":["DP200101374"]}]},{"name":"ARC","award":["DP240100955"],"award-info":[{"award-number":["DP240100955"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Cogn. Commun. Netw."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tccn.2025.3589652","type":"journal-article","created":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T17:40:04Z","timestamp":1752687604000},"page":"2131-2145","source":"Crossref","is-referenced-by-count":1,"title":["Information Bottleneck-Based Subgraphs Defending Against Inference Attacks in Federated Graph Learning Systems"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2352-0485","authenticated-orcid":false,"given":"Chenhan","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7905-3126","authenticated-orcid":false,"given":"Weiqi","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8905-0941","authenticated-orcid":false,"given":"Zhiyi","family":"Tian","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4485-6743","authenticated-orcid":false,"given":"Shui","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/LCOMM.2018.2870886"},{"key":"ref2","article-title":"Task-oriented communication for graph data: A graph information bottleneck approach","author":"Li","year":"2024","journal-title":"arXiv:2409.02728"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.002.2400034"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3661821"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3651544"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TCCN.2024.3349452"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TCCN.2024.3431923"},{"key":"ref8","first-page":"2669","article-title":"Stealing links from graph neural networks","volume-title":"Proc. USENIX Security Symp.","author":"He"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/516"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref11","article-title":"FedGNN: Federated graph neural network for privacy-preserving recommendation","author":"Wu","year":"2021","journal-title":"arXiv:2102.04925"},{"key":"ref12","first-page":"1","article-title":"Inference attacks against graph neural networks","volume-title":"Proc. USENIX Security Symp.","author":"Zhang"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484565"},{"key":"ref14","first-page":"1","article-title":"Subgraph federated learning with missing neighbor generation","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Zhang"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2013.2253320"},{"key":"ref16","first-page":"368","article-title":"The information bottleneck method","volume-title":"Proc. Annu. Allerton Conf. Commun. Control Comput.","author":"Tishby"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ITW.2014.6970882"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2968188"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3112205"},{"key":"ref20","article-title":"A comprehensive survey on trustworthy graph neural networks: Privacy, robustness, fairness, and explainability","author":"Dai","year":"2022","journal-title":"arXiv:2204.08570"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3595791"},{"key":"ref22","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref24","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","volume-title":"Proc. USENIX Security Symp. (USENIX Security)","author":"Fredrikson"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/tkde.2022.3201243"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/669"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3510032"},{"key":"ref29","first-page":"1","article-title":"Deep variational information bottleneck","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Alemi"},{"key":"ref30","first-page":"9908","article-title":"Learning efficient multi-agent communication: An information bottleneck approach","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang"},{"key":"ref31","first-page":"1","article-title":"Learning deep representations by mutual information estimation and maximization","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Hjelm"},{"key":"ref32","first-page":"1","article-title":"Deep graph infomax","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Velickovic"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380112"},{"key":"ref34","first-page":"1","article-title":"InfoGraph: Unsupervised and semi-supervised graph-level representation learning via mutual information maximization","volume-title":"Proc. Int. Conf. Learning Represent.","author":"Sun"},{"key":"ref35","first-page":"20437","article-title":"Graph information bottleneck","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Wu"},{"key":"ref36","first-page":"1","article-title":"Graph information bottleneck for subgraph recognition","volume-title":"Proc. Int. Conf. Learning Represent.","author":"Yu"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i4.20335"},{"key":"ref38","article-title":"Peer-to-peer federated learning on graphs","author":"Lalitha","year":"2019","journal-title":"arXiv:1901.11173"},{"key":"ref39","article-title":"SpreadGNN: Serverless multi-task federated learning for graph neural networks","author":"He","year":"2021","journal-title":"arXiv:2106.02743"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-021-01074-w"},{"key":"ref41","first-page":"1025","article-title":"Inductive representation learning on large graphs","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Hamilton"},{"key":"ref42","article-title":"GraphFL: A federated learning framework for semi-supervised node classification on graphs","author":"Wang","year":"2020","journal-title":"arXiv:2012.04187"},{"key":"ref43","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Artif. Intell. Stat.","author":"McMahan"},{"key":"ref44","article-title":"Relational inductive biases, deep learning, and graph networks","author":"Battaglia","year":"2018","journal-title":"arXiv:1806.01261"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref48","first-page":"1","article-title":"f-GAN: Training generative neural samplers using variational divergence minimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"29","author":"Nowozin"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"ref50","first-page":"1707","article-title":"QSGD: Communication-efficient SGD via gradient quantization and encoding","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Alistarh"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/Trustcom.2015.357"},{"key":"ref52","article-title":"Expanding the reach of federated learning by reducing client resource requirements","author":"Caldas","year":"2018","journal-title":"arXiv:1812.07210"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3510587"},{"key":"ref54","first-page":"1","article-title":"On the convergence of FedAvg on non-iid data","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Li"},{"key":"ref55","article-title":"Parallel SGD: When does averaging help?","author":"Zhang","year":"2016","journal-title":"arXiv:1606.07365"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v29i3.2157"},{"key":"ref57","first-page":"1","article-title":"Query-driven active surveying for collective classification","volume-title":"Proc. Int. Workshop Min. Learn. Graphs","volume":"8","author":"Namata"},{"key":"ref58","article-title":"METIS: A software package for partitioning unstructured graphs, partitioning meshes, and computing fill-reducing orderings of sparse matrices","author":"Karypis","year":"1997"},{"key":"ref59","first-page":"1","article-title":"Semi-supervised classification with graph convolutional networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kipf"},{"key":"ref60","first-page":"1","article-title":"Graph attention networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Veli\u010dkovi\u0107"},{"key":"ref61","first-page":"1","article-title":"FedGCN: Convergence-communication tradeoffs in federated training of graph convolutional networks","volume-title":"Proc. NeurIPS","author":"Yao"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1137\/090756090"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1063\/1.5040897"}],"container-title":["IEEE Transactions on Cognitive Communications and Networking"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6687307\/11304002\/11082378.pdf?arnumber=11082378","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,19]],"date-time":"2026-01-19T20:56:08Z","timestamp":1768856168000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11082378\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/tccn.2025.3589652","relation":{},"ISSN":["2332-7731","2372-2045"],"issn-type":[{"value":"2332-7731","type":"electronic"},{"value":"2372-2045","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}