{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T05:46:47Z","timestamp":1777873607098,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2029038, CNS-2135988"],"award-info":[{"award-number":["CNS-2029038, CNS-2135988"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,3]]},"DOI":"10.1145\/3711896.3737179","type":"proceedings-article","created":{"date-parts":[[2025,8,3]],"date-time":"2025-08-03T21:07:39Z","timestamp":1754255259000},"page":"3204-3215","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Verification of Incomplete Graph Unlearning through Adversarial Perturbations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9954-0886","authenticated-orcid":false,"given":"Kun","family":"Wu","sequence":"first","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, New Jersey, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3913-815X","authenticated-orcid":false,"given":"Wendy Hui","family":"Wang","sequence":"additional","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, New Jersey, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,3]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1287\/moor.8.2.273"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00019"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5741"},{"key":"e_1_3_2_2_4_1","volume-title":"Fast gradient attack on network embedding. arXiv preprint arXiv:1809.02797","author":"Chen Jinyin","year":"2018","unstructured":"Jinyin Chen, Yangyang Wu, Xuanheng Xu, Yixian Chen, Haibin Zheng, and Qi Xuan. 2018. Fast gradient attack on network embedding. arXiv preprint arXiv:1809.02797 (2018)."},{"key":"e_1_3_2_2_5_1","volume-title":"A survey of adversarial learning on graphs. arXiv preprint arXiv:2003.05730","author":"Chen Liang","year":"2020","unstructured":"Liang Chen, Jintang Li, Jiaying Peng, Tao Xie, Zengxu Cao, Kun Xu, Xiangnan He, Zibin Zheng, and Bingzhe Wu. 2020. A survey of adversarial learning on graphs. arXiv preprint arXiv:2003.05730 (2020)."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559352"},{"key":"e_1_3_2_2_7_1","volume-title":"GNNDelete: A General Strategy for Unlearning in Graph Neural Networks. In International Conference on Learning Representations (ICLR).","author":"Cheng Jiali","year":"2023","unstructured":"Jiali Cheng, George Dasoulas, Huan He, Chirag Agarwal, and Marinka Zitnik. 2023. GNNDelete: A General Strategy for Unlearning in Graph Neural Networks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_8_1","volume-title":"Certified graph unlearning. arXiv preprint arXiv:2206.09140","author":"Chien Eli","year":"2022","unstructured":"Eli Chien, Chao Pan, and Olgica Milenkovic. 2022. Certified graph unlearning. arXiv preprint arXiv:2206.09140 (2022)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML64287.2025.00033"},{"key":"e_1_3_2_2_10_1","volume-title":"Verifi: Towards verifiable federated unlearning","author":"Gao Xiangshan","year":"2024","unstructured":"Xiangshan Gao, Xingjun Ma, Jingyi Wang, Youcheng Sun, Bo Li, Shouling Ji, Peng Cheng, and Jiming Chen. 2024. Verifi: Towards verifiable federated unlearning. IEEE Transactions on Dependable and Secure Computing (2024)."},{"key":"e_1_3_2_2_11_1","volume-title":"International Conference on Machine Learning. 2242-2251","author":"Ghorbani Amirata","year":"2019","unstructured":"Amirata Ghorbani and James Zou. 2019. Data shapley: Equitable valuation of data for machine learning. In International Conference on Machine Learning. 2242-2251."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i13.17371"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3328269"},{"key":"e_1_3_2_2_14_1","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems. 1025-1035","author":"Hamilton William L.","year":"2017","unstructured":"William L. Hamilton, Rex Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. In Proceedings of the 31st International Conference on Neural Information Processing Systems. 1025-1035."},{"key":"e_1_3_2_2_15_1","volume-title":"30th USENIX Security Symposium. 2669-2686","author":"He Xinlei","year":"2021","unstructured":"Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. 2021. Stealing links from graph neural networks. In 30th USENIX Security Symposium. 2669-2686."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447556.3447566"},{"key":"e_1_3_2_2_17_1","volume-title":"Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907","author":"Kipf Thomas N","year":"2016","unstructured":"Thomas N Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016)."},{"key":"e_1_3_2_2_18_1","volume-title":"Proceedings of the 23rd Americas Conference on Information Systems (AMCIS). 2253-2257","author":"Kwak Chanhee","year":"2017","unstructured":"Chanhee Kwak, Junyeong Lee, Kyuhong Park, and Heeseok Lee. 2017. Let Machines Unlearn-Machine Unlearning and the Right to be Forgotten. In Proceedings of the 23rd Americas Conference on Information Systems (AMCIS). 2253-2257."},{"key":"e_1_3_2_2_19_1","first-page":"82","article-title":"Adversarial Attack on Large Scale Graph","volume":"35","author":"Li Jintang","year":"2023","unstructured":"Jintang Li, Tao Xie, Liang Chen, Fenfang Xie, Xiangnan He, and Zibin Zheng. 2023. Adversarial Attack on Large Scale Graph. IEEE Transactions on Knowledge and Data Engineering, Vol. 35, 1 (2023), 82-95.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i12.29273"},{"key":"e_1_3_2_2_21_1","first-page":"68","article-title":"The California consumer privacy act: Towards a European-style privacy regime in the United States","volume":"23","author":"Pardau Stuart L","year":"2018","unstructured":"Stuart L Pardau. 2018. The California consumer privacy act: Towards a European-style privacy regime in the United States. Journal of Technology Law & Policy, Vol. 23 (2018), 68.","journal-title":"Journal of Technology Law & Policy"},{"key":"e_1_3_2_2_22_1","first-page":"1","article-title":"General data protection regulation","volume":"25","author":"Regulation Protection","year":"2018","unstructured":"Protection Regulation. 2018. General data protection regulation. Intouch, Vol. 25 (2018), 1-5.","journal-title":"Intouch"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411866"},{"key":"e_1_3_2_2_25_1","volume-title":"Markus Hagenbuchner, and Gabriele Monfardini.","author":"Scarselli Franco","year":"2008","unstructured":"Franco Scarselli, Marco Gori, Ah Chung Tsoi, Markus Hagenbuchner, and Gabriele Monfardini. 2008. The graph neural network model. IEEE transactions on neural networks, Vol. 20, 1 (2008), 61-80."},{"key":"e_1_3_2_2_26_1","volume-title":"Active learning for convolutional neural networks: A core-set approach. arXiv preprint arXiv:1708.00489","author":"Sener Ozan","year":"2017","unstructured":"Ozan Sener and Silvio Savarese. 2017. Active learning for convolutional neural networks: A core-set approach. arXiv preprint arXiv:1708.00489 (2017)."},{"key":"e_1_3_2_2_27_1","volume-title":"Pitfalls of graph neural network evaluation. arXiv preprint arXiv:1811.05868","author":"Shchur Oleksandr","year":"2018","unstructured":"Oleksandr Shchur, Maximilian Mumme, Aleksandar Bojchevski, and Stephan G\u00fcnnemann. 2018. Pitfalls of graph neural network evaluation. arXiv preprint arXiv:1811.05868 (2018)."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0072"},{"key":"e_1_3_2_2_29_1","first-page":"7693","article-title":"Adversarial attack and defense on graph data: A survey","volume":"35","author":"Sun Lichao","year":"2022","unstructured":"Lichao Sun, Yingtong Dou, Carl Yang, Kai Zhang, Ji Wang, Philip S Yu, Lifang He, and Bo Li. 2022. Adversarial attack and defense on graph data: A survey. IEEE Transactions on Knowledge and Data Engineering, Vol. 35, 8 (2022), 7693-7711.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData47090.2019.9006004"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3651578"},{"key":"e_1_3_2_2_32_1","volume-title":"31st USENIX Security Symposium. 4007-4022","author":"Thudi Anvith","year":"2022","unstructured":"Anvith Thudi, Hengrui Jia, Ilia Shumailov, and Nicolas Papernot. 2022. On the necessity of auditable algorithmic definitions for machine unlearning. In 31st USENIX Security Symposium. 4007-4022."},{"key":"e_1_3_2_2_33_1","unstructured":"Petar Velickovic Guillem Cucurull Arantxa Casanova Adriana Romero Pietro Lio Yoshua Bengio et al. 2017. Graph attention networks. stat Vol. 1050 20 (2017) 10-48550."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354206"},{"key":"e_1_3_2_2_35_1","volume-title":"32nd USENIX Security Symposium. 3205-3222","author":"Wang Cheng-Long","year":"2023","unstructured":"Cheng-Long Wang, Mengdi Huai, and Di Wang. 2023. Inductive graph unlearning. In 32nd USENIX Security Symposium. 3205-3222."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3358993"},{"key":"e_1_3_2_2_37_1","volume-title":"International conference on machine learning. 5286-5295","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In International conference on machine learning. 5286-5295."},{"key":"e_1_3_2_2_38_1","volume-title":"Linkteller: Recovering private edges from graph neural networks via influence analysis. In 2022 ieee symposium on security and privacy (S&P). 2005-2024.","author":"Wu Fan","year":"2022","unstructured":"Fan Wu, Yunhui Long, Ce Zhang, and Bo Li. 2022. Linkteller: Recovering private edges from graph neural networks via influence analysis. In 2022 ieee symposium on security and privacy (S&P). 2005-2024."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/669"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583521"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599271"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"crossref","unstructured":"Kun Wu and Wendy Hui Wang. 2025. Verification of Incomplete Graph Unlearning through Adversarial Perturbations (Full version). https:\/\/github.com\/kunwu522\/unlearning-verification-gnn\/blob\/master\/full_paper\/Verification-of-Incomplete-Graph-Unlearning-through-Adversarial-Perturbations-full-version.pdf.","DOI":"10.1145\/3711896.3737179"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1561\/9781638281436"},{"key":"e_1_3_2_2_44_1","volume-title":"arXiv preprint arXiv:2406.10953","author":"Xu Heng","year":"2024","unstructured":"Heng Xu, Tianqing Zhu, Lefeng Zhang, and Wanlei Zhou. 2024. Really Unlearned? Verifying Machine Unlearning via Influential Sample Pairs. arXiv preprint arXiv:2406.10953 (2024)."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/550"},{"key":"e_1_3_2_2_46_1","volume-title":"International Conference on Learning Representations.","author":"Xu Keyulu","year":"2019","unstructured":"Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2019b. How Powerful are Graph Neural Networks?. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML54575.2023.00027"},{"key":"e_1_3_2_2_48_1","volume-title":"International conference on machine learning. 40-48","author":"Yang Zhilin","year":"2016","unstructured":"Zhilin Yang, William Cohen, and Ruslan Salakhudinov. 2016. Revisiting semi-supervised learning with graph embeddings. In International conference on machine learning. 40-48."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131372"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/3692070.3694492"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3651265"},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.sbi.2021.102327"},{"key":"e_1_3_2_2_53_1","volume-title":"Graph Unlearning Using Knowledge Distillation. In International Conference on Information and Communications Security. 485-501","author":"Zheng Wenyue","year":"2023","unstructured":"Wenyue Zheng, Ximeng Liu, Yuyang Wang, and Xuanwei Lin. 2023. Graph Unlearning Using Knowledge Distillation. In International Conference on Information and Communications Security. 485-501."},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"},{"key":"e_1_3_2_2_55_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Z\u00fcgner Daniel","year":"2019","unstructured":"Daniel Z\u00fcgner and Stephan G\u00fcnnemann. 2019a. Adversarial Attacks on Graph Neural Networks via Meta Learning. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330905"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403217"}],"event":{"name":"KDD '25: The 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Toronto ON Canada","acronym":"KDD '25","sponsor":["SIGKDD ACM Special Interest Group on Knowledge Discovery in Data","SIGMOD ACM Special Interest Group on Management of Data"]},"container-title":["Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3711896.3737179","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T18:06:17Z","timestamp":1777572377000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711896.3737179"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,3]]},"references-count":57,"alternative-id":["10.1145\/3711896.3737179","10.1145\/3711896"],"URL":"https:\/\/doi.org\/10.1145\/3711896.3737179","relation":{},"subject":[],"published":{"date-parts":[[2025,8,3]]},"assertion":[{"value":"2025-08-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}