{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T10:05:12Z","timestamp":1775815512491,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["2135988"],"award-info":[{"award-number":["2135988"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,7]]},"DOI":"10.1145\/3548606.3560662","type":"proceedings-article","created":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T11:41:28Z","timestamp":1667821288000},"page":"2871-2884","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Group Property Inference Attacks Against Graph Neural Networks"],"prefix":"10.1145","author":[{"given":"Xiuling","family":"Wang","sequence":"first","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wendy Hui","family":"Wang","sequence":"additional","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Amazon aws. https:\/\/aws.amazon.com\/marketplace\/solutions\/machine-learning.  Amazon aws. https:\/\/aws.amazon.com\/marketplace\/solutions\/machine-learning."},{"key":"e_1_3_2_1_2_1","unstructured":"Bigml inc. https:\/\/bigml.com\/.  Bigml inc. https:\/\/bigml.com\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Caffe model zoo. https:\/\/caffe.berkeleyvision.org\/model_zoo.html.  Caffe model zoo. https:\/\/caffe.berkeleyvision.org\/model_zoo.html."},{"key":"e_1_3_2_1_4_1","unstructured":"Google cloud. https:\/\/www.googleadservices.com\/.  Google cloud. https:\/\/www.googleadservices.com\/."},{"key":"e_1_3_2_1_5_1","unstructured":"Modzy: Ai model marketplace. https:\/\/www.modzy.com\/marketplace\/.  Modzy: Ai model marketplace. https:\/\/www.modzy.com\/marketplace\/."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_7_1","first-page":"798","volume-title":"Workshop on link analysis, counterterrorism and security","volume":"30","author":"Hasan Mohammad Al","year":"2006","unstructured":"Mohammad Al Hasan , Vineet Chaoji , Saeed Salem , and Mohammed Zaki . Link prediction using supervised learning . In Workshop on link analysis, counterterrorism and security , volume 30 , pages 798 -- 805 , 2006 . Mohammad Al Hasan, Vineet Chaoji, Saeed Salem, and Mohammed Zaki. Link prediction using supervised learning. In Workshop on link analysis, counterterrorism and security, volume 30, pages 798--805, 2006."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2011.6126555"},{"key":"e_1_3_2_1_10_1","volume-title":"Property inference from poisoning. arXiv preprint arXiv:2101.11073","author":"Chase Melissa","year":"2021","unstructured":"Melissa Chase , Esha Ghosh , and Saeed Mahloujifar . Property inference from poisoning. arXiv preprint arXiv:2101.11073 , 2021 . Melissa Chase, Esha Ghosh, and Saeed Mahloujifar. Property inference from poisoning. arXiv preprint arXiv:2101.11073, 2021."},{"key":"e_1_3_2_1_11_1","volume-title":"The frontiers of fairness in machine learning. arXiv preprint arXiv:1810.08810","author":"Chouldechova Alexandra","year":"2018","unstructured":"Alexandra Chouldechova and Aaron Roth . The frontiers of fairness in machine learning. arXiv preprint arXiv:1810.08810 , 2018 . Alexandra Chouldechova and Aaron Roth. The frontiers of fairness in machine learning. arXiv preprint arXiv:1810.08810, 2018."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448891.3448939"},{"key":"e_1_3_2_1_13_1","volume-title":"The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3--4):211--407","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork , Aaron Roth , The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3--4):211--407 , 2014 . Cynthia Dwork, Aaron Roth, et al. The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3--4):211--407, 2014."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384290"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_16_1","first-page":"17","volume-title":"Proceedings of 23rd USENIX Security Symposium","author":"Fredrikson Matthew","year":"2014","unstructured":"Matthew Fredrikson , Eric Lantz , Somesh Jha , Simon Lin , David Page , and Thomas Ristenpart . Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing . In Proceedings of 23rd USENIX Security Symposium , pages 17 -- 32 , 2014 . Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart. Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In Proceedings of 23rd USENIX Security Symposium, pages 17--32, 2014."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401051"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of the Conference on Neural Information Processing Systems","author":"Hamilton William L.","year":"2018","unstructured":"William L. Hamilton , Rex Ying , and Jure Leskovec . Inductive representation learning on large graphs . In Proceedings of the Conference on Neural Information Processing Systems , 2018 . William L. Hamilton, Rex Ying, and Jure Leskovec. Inductive representation learning on large graphs. In Proceedings of the Conference on Neural Information Processing Systems, 2018."},{"key":"e_1_3_2_1_20_1","first-page":"2669","volume-title":"Proceedings of the 30th USENIX Security Symposium","author":"He Xinlei","year":"2021","unstructured":"Xinlei He , Jinyuan Jia , Michael Backes , Neil Zhenqiang Gong , and Yang Zhang . Stealing links from graph neural networks . In Proceedings of the 30th USENIX Security Symposium , pages 2669 -- 2686 , 2021 . Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. Stealing links from graph neural networks. In Proceedings of the 30th USENIX Security Symposium, pages 2669--2686, 2021."},{"key":"e_1_3_2_1_21_1","volume-title":"Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429","author":"He Xinlei","year":"2021","unstructured":"Xinlei He , Rui Wen , Yixin Wu , Michael Backes , Yun Shen , and Yang Zhang . Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429 , 2021 . Xinlei He, Rui Wen, Yixin Wu, Michael Backes, Yun Shen, and Yang Zhang. Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429, 2021."},{"key":"e_1_3_2_1_22_1","volume-title":"Reducing the dimensionality of data with neural networks. science, 313(5786):504--507","author":"Hinton Geoffrey E","year":"2006","unstructured":"Geoffrey E Hinton and Ruslan R Salakhutdinov . Reducing the dimensionality of data with neural networks. science, 313(5786):504--507 , 2006 . Geoffrey E Hinton and Ruslan R Salakhutdinov. Reducing the dimensionality of data with neural networks. science, 313(5786):504--507, 2006."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361469"},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of International Conference on Learning Representations (ICLR)","author":"Thomas","year":"2017","unstructured":"Thomas N. Kipf and Max Welling. Semi-supervised classification with graph convolutional networks . In Proceedings of International Conference on Learning Representations (ICLR) , 2017 . Thomas N. Kipf and Max Welling. Semi-supervised classification with graph convolutional networks. In Proceedings of International Conference on Learning Representations (ICLR), 2017."},{"key":"e_1_3_2_1_25_1","first-page":"1885","volume-title":"Proceedings of International Conference on Machine Learning","author":"Koh Pang Wei","year":"2017","unstructured":"Pang Wei Koh and Percy Liang . Understanding black-box predictions via influence functions . In Proceedings of International Conference on Machine Learning , pages 1885 -- 1894 , 2017 . Pang Wei Koh and Percy Liang. Understanding black-box predictions via influence functions. In Proceedings of International Conference on Machine Learning, pages 1885--1894, 2017."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_27_1","first-page":"21","volume-title":"Proceedings of the Network and Distributed System Security (NDSS) Symposium","volume":"16","author":"Liu Changchang","year":"2016","unstructured":"Changchang Liu , Supriyo Chakraborty , and Prateek Mittal . Dependence makes you vulnberable: Differential privacy under dependent tuples . In Proceedings of the Network and Distributed System Security (NDSS) Symposium , volume 16 , pages 21 -- 24 , 2016 . Changchang Liu, Supriyo Chakraborty, and Prateek Mittal. Dependence makes you vulnberable: Differential privacy under dependent tuples. In Proceedings of the Network and Distributed System Security (NDSS) Symposium, volume 16, pages 21--24, 2016."},{"key":"e_1_3_2_1_28_1","volume-title":"Link prediction in complex networks: A survey. Physica A: statistical mechanics and its applications, 390(6):1150--1170","author":"L\u00fc Linyuan","year":"2011","unstructured":"Linyuan L\u00fc and Tao Zhou . Link prediction in complex networks: A survey. Physica A: statistical mechanics and its applications, 390(6):1150--1170 , 2011 . Linyuan L\u00fc and Tao Zhou. Link prediction in complex networks: A survey. Physica A: statistical mechanics and its applications, 390(6):1150--1170, 2011."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_30_1","volume-title":"Automatic choice of dimensionality for pca. Advances in neural information processing systems, 13","author":"Minka Thomas","year":"2000","unstructured":"Thomas Minka . Automatic choice of dimensionality for pca. Advances in neural information processing systems, 13 , 2000 . Thomas Minka. Automatic choice of dimensionality for pca. Advances in neural information processing systems, 13, 2000."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5220\/0010555600002998"},{"key":"e_1_3_2_1_33_1","volume-title":"A review on fairness in machine learning. ACM Computing Surveys (CSUR), 55(3):1--44","author":"Pessach Dana","year":"2022","unstructured":"Dana Pessach and Erez Shmueli . A review on fairness in machine learning. ACM Computing Surveys (CSUR), 55(3):1--44 , 2022 . Dana Pessach and Erez Shmueli. A review on fairness in machine learning. ACM Computing Surveys (CSUR), 55(3):1--44, 2022."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417270"},{"key":"e_1_3_2_1_36_1","volume-title":"ICML Workshop on Theory and Practice of Differential Privacy","author":"Suri Anshuman","year":"2021","unstructured":"Anshuman Suri and David Evans . Formalizing and estimating distribution inference risks . ICML Workshop on Theory and Practice of Differential Privacy , 2021 . Anshuman Suri and David Evans. Formalizing and estimating distribution inference risks. ICML Workshop on Theory and Practice of Differential Privacy, 2021."},{"key":"e_1_3_2_1_37_1","volume-title":"Visualizing data using t-sne. Journal of machine learning research, 9(11)","author":"der Maaten Laurens Van","year":"2008","unstructured":"Laurens Van der Maaten and Geoffrey Hinton . Visualizing data using t-sne. Journal of machine learning research, 9(11) , 2008 . Laurens Van der Maaten and Geoffrey Hinton. Visualizing data using t-sne. Journal of machine learning research, 9(11), 2008."},{"key":"e_1_3_2_1_38_1","volume-title":"Proceedings of International Conference on Learning Representations","author":"Velivckovic Petar","year":"2018","unstructured":"Petar Velivckovic , Guillem Cucurull , Arantxa Casanova , Adriana Romero , Pietro Li\u00f2 , and Yoshua Bengio . Graph attention networks . In Proceedings of International Conference on Learning Representations , 2018 . Petar Velivckovic, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Li\u00f2, and Yoshua Bengio. Graph attention networks. In Proceedings of International Conference on Learning Representations, 2018."},{"key":"e_1_3_2_1_39_1","volume-title":"Eavesdrop the composition proportion of training labels in federated learning. arXiv preprint arXiv:1910.06044","author":"Wang Lixu","year":"2019","unstructured":"Lixu Wang , Shichao Xu , Xiao Wang , and Qi Zhu . Eavesdrop the composition proportion of training labels in federated learning. arXiv preprint arXiv:1910.06044 , 2019 . Lixu Wang, Shichao Xu, Xiao Wang, and Qi Zhu. Eavesdrop the composition proportion of training labels in federated learning. arXiv preprint arXiv:1910.06044, 2019."},{"key":"e_1_3_2_1_40_1","volume-title":"Full paper: Group property inference attacks against graph neural networks. https:\/\/arxiv.org\/abs\/2209.01100","author":"Wang Xiuling","year":"2022","unstructured":"Xiuling Wang and Wendy Hui Wang . Full paper: Group property inference attacks against graph neural networks. https:\/\/arxiv.org\/abs\/2209.01100 , 2022 . Xiuling Wang and Wendy Hui Wang. Full paper: Group property inference attacks against graph neural networks. https:\/\/arxiv.org\/abs\/2209.01100, 2022."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462915"},{"key":"e_1_3_2_1_43_1","first-page":"576","volume-title":"Proceedings of IJCNN International Joint Conference on Neural Networks","volume":"1","author":"Weng Juyang","year":"1992","unstructured":"Juyang Weng , Narendra Ahuja , and Thomas S Huang . Cresceptron : a selforganizing neural network which grows adaptively . In Proceedings of IJCNN International Joint Conference on Neural Networks , volume 1 , pages 576 -- 581 , 1992 . Juyang Weng, Narendra Ahuja, and Thomas S Huang. Cresceptron: a selforganizing neural network which grows adaptively. In Proceedings of IJCNN International Joint Conference on Neural Networks, volume 1, pages 576--581, 1992."},{"key":"e_1_3_2_1_44_1","volume-title":"Proceedings of the 17th ACM ASIA Conference on Computer and Communications Security (ASIACCS)","author":"Wu Bang","year":"2021","unstructured":"Bang Wu , Xiangwen Yang , Shirui Pan , and Xingliang Yuan . Model extraction attacks on graph neural networks: Taxonomy and realization . In Proceedings of the 17th ACM ASIA Conference on Computer and Communications Security (ASIACCS) , 2021 . Bang Wu, Xiangwen Yang, Shirui Pan, and Xingliang Yuan. Model extraction attacks on graph neural networks: Taxonomy and realization. In Proceedings of the 17th ACM ASIA Conference on Computer and Communications Security (ASIACCS), 2021."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833806"},{"key":"e_1_3_2_1_46_1","first-page":"355","volume-title":"Proceedings of the 29th IEEE Computer Security Foundations Symposium (CSF)","author":"Fredrikson Matthew","year":"2016","unstructured":"XiWu, Matthew Fredrikson , Somesh Jha , and Jeffrey F Naughton . A methodology for formalizing model-inversion attacks . In Proceedings of the 29th IEEE Computer Security Foundations Symposium (CSF) , pages 355 -- 370 , 2016 . XiWu, Matthew Fredrikson, Somesh Jha, and Jeffrey F Naughton. A methodology for formalizing model-inversion attacks. In Proceedings of the 29th IEEE Computer Security Foundations Symposium (CSF), pages 355--370, 2016."},{"key":"e_1_3_2_1_47_1","first-page":"2687","volume-title":"Proceedings of the 30th USENIX Security Symposium","author":"Zhang Wanrong","year":"2021","unstructured":"Wanrong Zhang , Shruti Tople , and Olga Ohrimenko . Leakage of dataset properties in multi-party machine learning . In Proceedings of the 30th USENIX Security Symposium , pages 2687 -- 2704 , 2021 . Wanrong Zhang, Shruti Tople, and Olga Ohrimenko. Leakage of dataset properties in multi-party machine learning. In Proceedings of the 30th USENIX Security Symposium, pages 2687--2704, 2021."},{"key":"e_1_3_2_1_48_1","first-page":"1","volume-title":"Proceedings of the 31th USENIX Security Symposium","author":"Zhang Zhikun","year":"2022","unstructured":"Zhikun Zhang , Min Chen , Michael Backes , Yun Shen , and Yang Zhang . Inference attacks against graph neural networks . In Proceedings of the 31th USENIX Security Symposium , pages 1 -- 18 , 2022 . Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, and Yang Zhang. Inference attacks against graph neural networks. In Proceedings of the 31th USENIX Security Symposium, pages 1--18, 2022."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23019"}],"event":{"name":"CCS '22: 2022 ACM SIGSAC Conference on Computer and Communications Security","location":"Los Angeles CA USA","acronym":"CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3548606.3560662","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3548606.3560662","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:48:59Z","timestamp":1750182539000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3548606.3560662"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":49,"alternative-id":["10.1145\/3548606.3560662","10.1145\/3548606"],"URL":"https:\/\/doi.org\/10.1145\/3548606.3560662","relation":{},"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2022-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}