{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T05:48:48Z","timestamp":1777873728398,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,3]]},"DOI":"10.1145\/3711896.3736848","type":"proceedings-article","created":{"date-parts":[[2025,8,1]],"date-time":"2025-08-01T13:30:13Z","timestamp":1754055013000},"page":"322-333","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-2309-4321","authenticated-orcid":false,"given":"Zhan","family":"Cheng","sequence":"first","affiliation":[{"name":"University of Wisconsin - Madison, Madison, WI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6471-9183","authenticated-orcid":false,"given":"Bolin","family":"Shen","sequence":"additional","affiliation":[{"name":"Florida State University, Tallahassee, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3218-2804","authenticated-orcid":false,"given":"Tianming","family":"Sha","sequence":"additional","affiliation":[{"name":"Arizona State University, Tempe, Arizona, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-1852-5010","authenticated-orcid":false,"given":"Yuan","family":"Gao","sequence":"additional","affiliation":[{"name":"University of Wisconsin - Madison, Madison, WI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1076-282X","authenticated-orcid":false,"given":"Shibo","family":"Li","sequence":"additional","affiliation":[{"name":"Florida State University, Tallahassee, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7504-6159","authenticated-orcid":false,"given":"Yushun","family":"Dong","sequence":"additional","affiliation":[{"name":"Florida State University, Tallahassee, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,3]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-11154-9_11"},{"key":"e_1_3_2_2_2_1","unstructured":"Hongyun Cai Vincent W Zheng and Kevin Chen-Chuan Chang. 2017. Active learning for graph embedding. arXiv preprint arXiv:1705.05085(2017)."},{"key":"e_1_3_2_2_3_1","volume-title":"Dynamarks: Defending against deep learning model extraction using dynamic watermarking. arXiv preprint arXiv:2207.13321(2022).","author":"Chakraborty Abhishek","year":"2022","unstructured":"Abhishek Chakraborty, Daniel Xing, Yuntao Liu, and Ankur Srivastava. 2022. Dynamarks: Defending against deep learning model extraction using dynamic watermarking. arXiv preprint arXiv:2207.13321(2022)."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2023.110854"},{"key":"e_1_3_2_2_5_1","volume-title":"Caglar Gulcehre, Dzmitry Bahdanau, Fethi Bougares, Holger Schwenk, and Yoshua Bengio.","author":"Cho Kyunghyun","year":"2014","unstructured":"Kyunghyun Cho, Bart Van Merri\u00ebnboer, Caglar Gulcehre, Dzmitry Bahdanau, Fethi Bougares, Holger Schwenk, and Yoshua Bengio. 2014. Learning phrase representations using RNN encoder-decoder for statistical machine translation. arXiv preprint arXiv:1406.1078(2014)."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13321-024-00937-7"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671744"},{"key":"e_1_3_2_2_8_1","volume-title":"ELEGANT: Certified defense on the fairness of graph neural networks. arXiv preprint arXiv:2311.02757(2023).","author":"Dong Yushun","year":"2023","unstructured":"Yushun Dong, Binchi Zhang, Hanghang Tong, and Jundong Li. 2023. ELEGANT: Certified defense on the fairness of graph neural networks. arXiv preprint arXiv:2311.02757(2023)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11227-024-06420-2"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3501396"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.112144"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.79.8.2554"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3108"},{"key":"e_1_3_2_2_15_1","volume-title":"Deep learning for time series classification: a review. Data mining and knowledge discovery","author":"Fawaz Hassan Ismail","year":"2019","unstructured":"Hassan Ismail Fawaz, Germain Forestier, Jonathan Weber, Lhassane Idoumghar, and Pierre-Alain Muller. 2019. Deep learning for time series classification: a review. Data mining and knowledge discovery, Vol. 33, 4 (2019), 917-963."},{"key":"e_1_3_2_2_16_1","volume-title":"30th USENIX security symposium (USENIX Security 21). 1937-1954.","author":"Jia Hengrui","unstructured":"Hengrui Jia, Christopher A Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2021. Entangled watermarks as a defense against model extraction. In 30th USENIX security symposium (USENIX Security 21). 1937-1954."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_2_2_18_1","unstructured":"Thomas N Kipf and Max Welling. 2016a. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907(2016)."},{"key":"e_1_3_2_2_19_1","unstructured":"Thomas N Kipf and Max Welling. 2016b. Variational graph auto-encoders. arXiv preprint arXiv:1611.07308(2016)."},{"key":"e_1_3_2_2_20_1","volume-title":"Identifying appropriate intellectual property protection mechanisms for machine learning models: A systematization of watermarking, fingerprinting, model access, and attacks","author":"Lederer Isabell","year":"2023","unstructured":"Isabell Lederer, Rudolf Mayer, and Andreas Rauber. 2023. Identifying appropriate intellectual property protection mechanisms for machine learning models: A systematization of watermarking, fingerprinting, model access, and attacks. IEEE Transactions on Neural Networks and Learning Systems(2023)."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3657002"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCSI53130.2021.9736204"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17140-6_30"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449989"},{"key":"e_1_3_2_2_26_1","unstructured":"Yong Liu Tengge Hu Haoran Zhang Haixu Wu Shiyu Wang Lintao Ma and Mingsheng Long. 2023. itransformer: Inverted transformers are effective for time series forecasting. arXiv preprint arXiv:2310.06625(2023)."},{"key":"e_1_3_2_2_27_1","unstructured":"Nils Lukas Yuxuan Zhang and Florian Kerschbaum. 2019. Deep neural network fingerprinting by conferrable adversarial examples. arXiv preprint arXiv:1912.00888(2019)."},{"key":"e_1_3_2_2_28_1","unstructured":"Pratyush Maini Mohammad Yaghini and Nicolas Papernot. 2021. Dataset inference: Ownership resolution in machine learning. arXiv preprint arXiv:2104.10706(2021)."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2022.11.185"},{"key":"e_1_3_2_2_30_1","unstructured":"Yuqi Nie Nam H Nguyen Phanwadee Sinthong and Jayant Kalagnanam. 2022. A time series is worth 64 words: Long-term forecasting with transformers. arXiv preprint arXiv:2211.14730(2022)."},{"key":"e_1_3_2_2_31_1","unstructured":"Soham Pal Yash Gupta Aditya Kanade and Shirish Shevade. 2021. Stateful detection of model extraction attacks. arXiv preprint arXiv:2107.05166(2021)."},{"key":"e_1_3_2_2_32_1","volume-title":"Bioinformatics","volume":"39","author":"R\u00e9au Manon","year":"2023","unstructured":"Manon R\u00e9au, Nicolas Renaud, Li C Xue, and Alexandre MJJ Bonvin. 2023. DeepRank-GNN: a graph neural network framework to learn patterns in protein-protein interfaces. Bioinformatics, Vol. 39, 1 (2023), btac759."},{"key":"e_1_3_2_2_33_1","volume-title":"Learning representations by back-propagating errors. nature","author":"Rumelhart David E","year":"1986","unstructured":"David E Rumelhart, Geoffrey E Hinton, and Ronald J Williams. 1986. Learning representations by back-propagating errors. nature, Vol. 323, 6088 (1986), 533-536."},{"key":"e_1_3_2_2_34_1","volume-title":"Markus Hagenbuchner, and Gabriele Monfardini.","author":"Scarselli Franco","year":"2008","unstructured":"Franco Scarselli, Marco Gori, Ah Chung Tsoi, Markus Hagenbuchner, and Gabriele Monfardini. 2008. The graph neural network model. IEEE transactions on neural networks, Vol. 20, 1 (2008), 61-80."},{"key":"e_1_3_2_2_35_1","unstructured":"John Schulman Filip Wolski Prafulla Dhariwal Alec Radford and Oleg Klimov. 2017. Proximal policy optimization algorithms. arXiv preprint arXiv:1707.06347(2017)."},{"key":"e_1_3_2_2_36_1","unstructured":"Burr Settles. 2009. Active learning literature survey. (2009)."},{"key":"e_1_3_2_2_37_1","volume-title":"33rd USENIX Security Symposium (Security","author":"Tang Minxue","year":"2024","unstructured":"Minxue Tang, Anna Dai, Louis DiValentin, Aolin Ding, Amin Hass, Neil Zhenqiang Gong, and Yiran Chen. 2024. Modelguard: Information-theoretic defense against model extraction attacks. In 33rd USENIX Security Symposium (Security 2024)."},{"key":"e_1_3_2_2_38_1","volume-title":"25th USENIX security symposium (USENIX Security 16). 601-618.","author":"Tram\u00e8r Florian","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction {APIs}. In 25th USENIX security symposium (USENIX Security 16). 601-618."},{"key":"e_1_3_2_2_39_1","unstructured":"A Vaswani. 2017. Attention is all you need. Advances in Neural Information Processing Systems(2017)."},{"key":"e_1_3_2_2_40_1","volume-title":"2024 IEEE Symposium on Security and Privacy (SP). 2460-2477","author":"Waheed Asim","unstructured":"Asim Waheed, Vasisht Duddu, and N. Asokan. 2024. GrOVe: Ownership Verification of Graph Neural Networks using Embeddings. In 2024 IEEE Symposium on Security and Privacy (SP). 2460-2477."},{"key":"e_1_3_2_2_41_1","unstructured":"Song Wang Yushun Dong Binchi Zhang Zihan Chen Xingbo Fu Yinhan He Cong Shen Chuxu Zhang Nitesh V Chawla and Jundong Li. 2024. Safety in graph machine learning: Threats and safeguards. arXiv preprint arXiv:2405.11034(2024)."},{"key":"e_1_3_2_2_42_1","volume-title":"CrossFormer: A versatile vision transformer hinging on cross-scale attention. arXiv","author":"Wang W","year":"2021","unstructured":"W Wang, L Yao, L Chen, B Lin, D Cai, X He, and W Liu. 2021. CrossFormer: A versatile vision transformer hinging on cross-scale attention. arXiv 2021. arXiv preprint arXiv:2108.00154(2021)."},{"key":"e_1_3_2_2_43_1","first-page":"945","volume-title":"19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22)","author":"Weng Qizhen","year":"2022","unstructured":"Qizhen Weng, Wencong Xiao, Yinghao Yu, Wei Wang, Cheng Wang, Jian He, Yong Li, Liping Zhang, Wei Lin, and Yu Ding. 2022. {MLaaS} in the wild: Workload analysis and scheduling in {Large-Scale} heterogeneous {GPU} clusters. In 19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22). 945-960."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3497753"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00110"},{"key":"e_1_3_2_2_46_1","volume-title":"Timesnet: Temporal 2d-variation modeling for general time series analysis. arXiv preprint arXiv:2210.02186(2022).","author":"Wu Haixu","year":"2022","unstructured":"Haixu Wu, Tengge Hu, Yong Liu, Hang Zhou, Jianmin Wang, and Mingsheng Long. 2022a. Timesnet: Temporal 2d-variation modeling for general time series analysis. arXiv preprint arXiv:2210.02186(2022)."},{"key":"e_1_3_2_2_47_1","volume-title":"Autoformer: Decomposition transformers with auto-correlation for long-term series forecasting. Advances in neural information processing systems","author":"Wu Haixu","year":"2021","unstructured":"Haixu Wu, Jiehui Xu, Jianmin Wang, and Mingsheng Long. 2021. Autoformer: Decomposition transformers with auto-correlation for long-term series forecasting. Advances in neural information processing systems, Vol. 34 (2021), 22419-22430."},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26702"},{"key":"e_1_3_2_2_49_1","first-page":"102","article-title":"CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples","volume":"38","author":"Yu Honggang","year":"2020","unstructured":"Honggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai, Tsung-Yi Ho, and Yier Jin. 2020. CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples.. In NDSS, Vol. 38. 102.","journal-title":"NDSS"},{"key":"e_1_3_2_2_50_1","unstructured":"Wentao Zhang Yexin Wang Zhenbang You Meng Cao Ping Huang Jiulong Shan Zhi Yang and Bin Cui. 2022. Information gain propagation: a new way to graph active learning with soft labels. arXiv preprint arXiv:2203.01093(2022)."},{"key":"e_1_3_2_2_51_1","volume-title":"Grain: Improving data efficiency of graph neural networks via diversified influence maximization. arXiv preprint arXiv:2108.00219(2021).","author":"Zhang Wentao","year":"2021","unstructured":"Wentao Zhang, Zhi Yang, Yexin Wang, Yu Shen, Yang Li, Liang Wang, and Bin Cui. 2021c. Grain: Improving data efficiency of graph neural networks via diversified influence maximization. arXiv preprint arXiv:2108.00219(2021)."},{"key":"e_1_3_2_2_52_1","volume-title":"SD-Attack: Targeted Spectral Attacks on Graphs. In Pacific-Asia Conference on Knowledge Discovery and Data Mining. Springer, 352-363","author":"Zhang Xianren","year":"2024","unstructured":"Xianren Zhang, Jing Ma, Yushun Dong, Chen Chen, Min Gao, and Jundong Li. 2024. SD-Attack: Targeted Spectral Attacks on Graphs. In Pacific-Asia Conference on Knowledge Discovery and Data Mining. Springer, 352-363."},{"key":"e_1_3_2_2_53_1","volume-title":"Graph neural networks and their current applications in bioinformatics. Frontiers in genetics","author":"Zhang Xiao-Meng","year":"2021","unstructured":"Xiao-Meng Zhang, Li Liang, Lin Liu, and Ming-Jing Tang. 2021b. Graph neural networks and their current applications in bioinformatics. Frontiers in genetics, Vol. 12 (2021), 690049."},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486863"},{"key":"e_1_3_2_2_55_1","volume-title":"Yue Zhao, and Yushun Dong.","author":"Zhao Kaixiang","year":"2025","unstructured":"Kaixiang Zhao, Lincan Li, Kaize Ding, Neil Zhenqiang Gong, Yue Zhao, and Yushun Dong. 2025. A Survey of Model Extraction Attacks and Defenses in Distributed Computing Environments. arXiv preprint arXiv:2502.16065(2025)."},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17325"}],"event":{"name":"KDD '25: The 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Toronto ON Canada","acronym":"KDD '25","sponsor":["SIGKDD ACM Special Interest Group on Knowledge Discovery in Data","SIGMOD ACM Special Interest Group on Management of Data"]},"container-title":["Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3711896.3736848","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T18:16:03Z","timestamp":1777572963000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711896.3736848"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,3]]},"references-count":56,"alternative-id":["10.1145\/3711896.3736848","10.1145\/3711896"],"URL":"https:\/\/doi.org\/10.1145\/3711896.3736848","relation":{},"subject":[],"published":{"date-parts":[[2025,8,3]]},"assertion":[{"value":"2025-08-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}