{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T10:04:59Z","timestamp":1775815499493,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":65,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623173","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"1153-1167","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Devil in Disguise: Breaching Graph Neural Networks Privacy through Infiltration"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-7187-0153","authenticated-orcid":false,"given":"Lingshuo","family":"Meng","sequence":"first","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-9587-3528","authenticated-orcid":false,"given":"Yijie","family":"Bai","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1382-0679","authenticated-orcid":false,"given":"Yanjiao","family":"Chen","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-8498-8877","authenticated-orcid":false,"given":"Yutong","family":"Hu","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5043-9148","authenticated-orcid":false,"given":"Wenyuan","family":"Xu","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3005-761X","authenticated-orcid":false,"given":"Haiqin","family":"Weng","sequence":"additional","affiliation":[{"name":"Ant Group, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Training differentially private graph neural networks with random walk sampling. arXiv preprint arXiv:2301.00738","author":"Ayle Morgane","year":"2023","unstructured":"Morgane Ayle, Jan Schuchardt, Lukas Gosch, Daniel Z\u00fcgner, and Stephan G\u00fcnnemann. 2023. Training differentially private graph neural networks with random walk sampling. arXiv preprint arXiv:2301.00738 (2023)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/293"},{"key":"e_1_3_2_1_6_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Chen Yongqiang","year":"2022","unstructured":"Yongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma, Tongliang Liu, Bo Han, and James Cheng. 2022. Understanding and improving graph injection attack by promoting unnoticeability. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3560830.3563734"},{"key":"e_1_3_2_1_8_1","volume-title":"Gaurav Aggarwal, and Prateek Jain.","author":"Daigavane Ameya","year":"2021","unstructured":"Ameya Daigavane, Gagan Madan, Aditya Sinha, Abhradeep Guha Thakurta, Gaurav Aggarwal, and Prateek Jain. 2021. Node-level differentially private graph neural networks. arXiv preprint arXiv:2111.15521 (2021)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448891.3448939"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313488"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2957786"},{"key":"e_1_3_2_1_12_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Hamilton Will","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 1024--1034."},{"key":"e_1_3_2_1_13_1","volume-title":"USENIX Security Symposium. 2669--2686","author":"He Xinlei","year":"2021","unstructured":"Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. 2021a. Stealing links from graph neural networks. In USENIX Security Symposium. 2669--2686."},{"key":"e_1_3_2_1_14_1","volume-title":"Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429","author":"He Xinlei","year":"2021","unstructured":"Xinlei He, Rui Wen, Yixin Wu, Michael Backes, Yun Shen, and Yang Zhang. 2021b. Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429 (2021)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i5.16533"},{"key":"e_1_3_2_1_16_1","volume-title":"USENIX Security Symposium. 1895--1912","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans. 2019. Evaluating differentially private machine learning in practice. In USENIX Security Symposium. 1895--1912."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560663"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447556.3447566"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.14778\/3402707.3402749"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36594-2_26"},{"key":"e_1_3_2_1_21_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Keriven Nicolas","unstructured":"Nicolas Keriven and Gabriel Peyr\u00e9. 2019. Universal invariant and equivariant graph neural networks. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 7090--7099."},{"key":"e_1_3_2_1_22_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Kipf Thomas N","year":"2017","unstructured":"Thomas N Kipf and Max Welling. 2017. Semi-supervised classification with graph convolutional networks. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560705"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401253"},{"key":"e_1_3_2_1_25_1","volume-title":"Birds of a feather: Homophily in social networks. Annual review of sociology","author":"McPherson Miller","year":"2001","unstructured":"Miller McPherson, Lynn Smith-Lovin, and James M Cook. 2001. Birds of a feather: Homophily in social networks. Annual review of sociology (2001), 415--444."},{"key":"e_1_3_2_1_26_1","volume-title":"USENIX Security Symposium. 4579--4596","author":"Mehnaz Shagufta","year":"2022","unstructured":"Shagufta Mehnaz, Sayanton V Dibbo, Roberta De Viti, Ehsanul Kabir, Bj\u00f6rn B Brandenburg, Stefan Mangard, Ninghui Li, Elisa Bertino, Michael Backes, Emiliano De Cristofaro, et al. 2022. Are your sensitive attributes private? Novel model inversion attribute inference attacks on classification models. In USENIX Security Symposium. 4579--4596."},{"key":"e_1_3_2_1_27_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Rong Yu","year":"2020","unstructured":"Yu Rong, Wenbing Huang, Tingyang Xu, and Junzhou Huang. 2020. DropEdge: Towards deep graph convolutional networks on node classification. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_28_1","volume-title":"Multi-scale attributed node embedding. arXiv preprint arXiv:1909.13021","author":"Rozemberczki Benedek","year":"2019","unstructured":"Benedek Rozemberczki, Carl Allen, and Rik Sarkar. 2019. Multi-scale attributed node embedding. arXiv preprint arXiv:1909.13021 (2019)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411866"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484565"},{"key":"e_1_3_2_1_31_1","volume-title":"Aur\u00e9lien Bellet, and Daniel Gatica-Perez.","author":"Sajadmanesh Sina","year":"2022","unstructured":"Sina Sajadmanesh, Ali Shahin Shamsabadi, Aur\u00e9lien Bellet, and Daniel Gatica-Perez. 2022. GAP: Differentially private graph neural networks with aggregation perturbation. arXiv preprint arXiv:2203.00949 (2022)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"e_1_3_2_1_33_1","volume-title":"Pitfalls of graph neural network evaluation. arXiv preprint arXiv:1811.05868","author":"Shchur Oleksandr","year":"2018","unstructured":"Oleksandr Shchur, Maximilian Mumme, Aleksandar Bojchevski, and Stephan G\u00fcnnemann. 2018. Pitfalls of graph neural network evaluation. arXiv preprint arXiv:1811.05868 (2018)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559358"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833607"},{"key":"e_1_3_2_1_36_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Song Congzheng","year":"2020","unstructured":"Congzheng Song and Vitaly Shmatikov. 2020. Overlearning reveals sensitive attributes. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354211"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3201243"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380149"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482393"},{"key":"e_1_3_2_1_41_1","volume-title":"Social structure of facebook networks. Physica A: Statistical Mechanics and its Applications","author":"Traud Amanda L","year":"2012","unstructured":"Amanda L Traud, Peter J Mucha, and Mason A Porter. 2012. Social structure of facebook networks. Physica A: Statistical Mechanics and its Applications, Vol. 391, 16 (2012), 4165--4180."},{"key":"e_1_3_2_1_42_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Veli\u010dkovi\u0107 Petar","year":"2018","unstructured":"Petar Veli\u010dkovi\u0107, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, and Yoshua Bengio. 2018. Graph attention networks. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-020-00696-7"},{"key":"e_1_3_2_1_44_1","volume-title":"Attack graph convolutional networks by adding fake nodes. arXiv preprint arXiv:1810.10751","author":"Wang Xiaoyun","year":"2018","unstructured":"Xiaoyun Wang, Minhao Cheng, Joe Eaton, Cho-Jui Hsieh, and Felix Wu. 2018. Attack graph convolutional networks by adding fake nodes. arXiv preprint arXiv:1810.10751 (2018)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560662"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/108"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833806"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.2978386"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"e_1_3_2_1_50_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Xu Keyulu","year":"2019","unstructured":"Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2019. How powerful are graph neural networks?. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_51_1","volume-title":"International Conference on Machine Learning. PMLR, 40--48","author":"Yang Zhilin","year":"2016","unstructured":"Zhilin Yang, William Cohen, and Ruslan Salakhudinov. 2016. Revisiting semi-supervised learning with graph embeddings. In International Conference on Machine Learning. PMLR, 40--48."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_3_2_1_53_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Ying Zhitao","unstructured":"Zhitao Ying, Jiaxuan You, Christopher Morris, Xiang Ren, Will Hamilton, and Jure Leskovec. 2018. Hierarchical graph representation learning with differentiable pooling. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 4805--4815."},{"key":"e_1_3_2_1_54_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Zhang Muhan","unstructured":"Muhan Zhang and Yixin Chen. 2018. Link prediction based on graph neural networks. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 5171--5181."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11782"},{"key":"e_1_3_2_1_56_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Zhang Xitong","unstructured":"Xitong Zhang, Yixuan He, Nathan Brugnone, Michael Perlmutter, and Matthew Hirn. 2021a. MagNet: A neural network for directed graphs. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 27003--27015."},{"key":"e_1_3_2_1_57_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Zhang Xiang","unstructured":"Xiang Zhang and Marinka Zitnik. 2020. GNNGuard: Defending graph neural networks against adversarial attacks. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 9263--9275."},{"key":"e_1_3_2_1_58_1","volume-title":"USENIX Security Symposium. 1--18","author":"Zhang Zhikun","year":"2022","unstructured":"Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, and Yang Zhang. 2022a. Inference attacks against graph neural networks. In USENIX Security Symposium. 1--18."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.2981333"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/516"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1016\/S2589-7500(20)30192-8"},{"key":"e_1_3_2_1_62_1","volume-title":"Advances in Neural Information Processing Systems. Curran Associates","author":"Zhu Jiong","unstructured":"Jiong Zhu, Yujun Yan, Lingxiao Zhao, Mark Heimann, Leman Akoglu, and Danai Koutra. 2020. Beyond homophily in graph neural networks: Current limitations and effective designs. In Advances in Neural Information Processing Systems. Curran Associates, Inc., 7793--7804."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1093\/bioinformatics\/bty294"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467314"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623173","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623173","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:48:51Z","timestamp":1755740931000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623173"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":65,"alternative-id":["10.1145\/3576915.3623173","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623173","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}