{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:18:01Z","timestamp":1783437481536,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,11,22]],"date-time":"2026-11-22T00:00:00Z","timestamp":1795305600000},"content-version":"vor","delay-in-days":368,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2029038, CNS-2135988,CNS-2302689, CNS-2308730, CNS-2432533, CNS-2319277"],"award-info":[{"award-number":["CNS-2029038, CNS-2135988,CNS-2302689, CNS-2308730, CNS-2432533, CNS-2319277"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765173","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:37:25Z","timestamp":1763854645000},"page":"2144-2158","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Safeguarding Graph Neural Networks against Topology Inference Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9337-1452","authenticated-orcid":false,"given":"Jie","family":"Fu","sequence":"first","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, New Jersey, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4095-4506","authenticated-orcid":false,"given":"Yuan","family":"Hong","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, Connecticut, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2231-3652","authenticated-orcid":false,"given":"Zhili","family":"Chen","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3913-815X","authenticated-orcid":false,"given":"Wendy Hui","family":"Wang","sequence":"additional","affiliation":[{"name":"Stevens Institute of Technology, Hoboken, New Jersey, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/335305.335326"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/2008\/10\/P10008"},{"key":"e_1_3_2_2_3_1","unstructured":"Stacy Jo Dixon. 2025. ''Number of Instagram users worldwide from 2019 to 2028 ''. https:\/\/www.statista.com\/forecasts\/1138856\/instagram-users-in-the-world."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3448891.3448939"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_2_6_1","first-page":"211","volume-title":"Foundations and Trends\u00ae in Theoretical Computer Science","volume":"9","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork, Aaron Roth, et al., 2014. The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science, Vol. 9, 3-4 (2014), 211-407."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"crossref","unstructured":"Jie Fu Yuan Hong Zhili Chen and Wendy Hui Wang. 2025. Safeguarding Graph Neural Networks against Topology Inference Attacks (Full version). https:\/\/github.com\/JeffffffFu\/PGR\/blob\/main\/Safeguarding_Graph_Neural_Networks_against_Topology_Inference_Attacks_full_version.pdf.","DOI":"10.1145\/3719027.3765173"},{"key":"e_1_3_2_2_8_1","volume-title":"A Monte Carlo evaluation of weighted community detection algorithms. Frontiers in neuroinformatics","author":"Gates Kathleen M","year":"2016","unstructured":"Kathleen M Gates, Teague Henry, Doug Steinley, and Damien A Fair. 2016. A Monte Carlo evaluation of weighted community detection algorithms. Frontiers in neuroinformatics, Vol. 10 (2016), 45."},{"key":"e_1_3_2_2_9_1","unstructured":"Google. 2021. ''Vertex ai - google cloud''. https:\/\/cloud.google.com\/vertex-ai."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.2986316"},{"key":"e_1_3_2_2_11_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_2_12_1","volume-title":"Privacy-preserving network embedding against private link inference attacks","author":"Han Xiao","year":"2023","unstructured":"Xiao Han, Yuncong Yang, Leye Wang, and Junjie Wu. 2023. Privacy-preserving network embedding against private link inference attacks. IEEE Transactions on Dependable and Secure Computing (2023)."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2024.106574"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2024-0121"},{"key":"e_1_3_2_2_15_1","volume-title":"Neil Zhenqiang Gong, and Yang Zhang","author":"He Xinlei","year":"2021","unstructured":"Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang. 2021. Stealing links from graph neural networks. In 30th USENIX security symposium. 2669-2686."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i5.16533"},{"key":"e_1_3_2_2_17_1","unstructured":"IBM. 2018. ''Infosphere virtual data pipeline \u2014 IBM''. https:\/\/www.ibm.com\/products\/ibm-infosphere-virtual-data-pipeline."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.14778\/3402707.3402749"},{"key":"e_1_3_2_2_19_1","volume-title":"Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907","author":"Kipf Thomas N","year":"2016","unstructured":"Thomas N Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016)."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560705"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623173"},{"key":"e_1_3_2_2_22_1","volume-title":"Releasing Graph Neural Networks with Differential Privacy Guarantees. Transactions on Machine Learning Research","author":"Olatunji Iyiola Emmanuel","year":"2024","unstructured":"Iyiola Emmanuel Olatunji, Thorben Funke, and Megha Khosla. 2024. Releasing Graph Neural Networks with Differential Privacy Guarantees. Transactions on Machine Learning Research (2024)."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPSISA52974.2021.00002"},{"key":"e_1_3_2_2_24_1","unstructured":"Parlai. 2017. ''Parlai''. https:\/\/ai.facebook.com\/tools\/parlai."},{"key":"e_1_3_2_2_25_1","volume-title":"Pytorch: An imperative style, high-performance deep learning library. Advances in neural information processing systems","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al., 2019. Pytorch: An imperative style, high-performance deep learning library. Advances in neural information processing systems, Vol. 32 (2019)."},{"key":"e_1_3_2_2_26_1","volume-title":"International conference on learning representations","volume":"8","author":"Petar Veli\u010dkovi\u0107","year":"2018","unstructured":"Veli\u010dkovi\u0107 Petar, Cucurull Guillem, Casanova Arantxa, Romero Adriana, Lio Pietro, and B Yoshua. 2018. Graph attention networks. In International conference on learning representations, Vol. 8."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-10989-8_14"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411866"},{"key":"e_1_3_2_2_29_1","volume-title":"GAP: Differentially Private Graph Neural Networks with Aggregation Perturbation. In 32nd USENIX Security Symposium. 3223-3240","author":"Sajadmanesh Sina","year":"2023","unstructured":"Sina Sajadmanesh, Ali Shahin Shamsabadi, Aur\u00e9lien Bellet, and Daniel Gatica-Perez. 2023. GAP: Differentially Private Graph Neural Networks with Aggregation Perturbation. In 32nd USENIX Security Symposium. 3223-3240."},{"key":"e_1_3_2_2_30_1","volume-title":"The 22nd International Conference on Artificial Intelligence and Statistics. 1723-1732","author":"Shaban Amirreza","year":"2019","unstructured":"Amirreza Shaban, Ching-An Cheng, Nathan Hatch, and Byron Boots. 2019. Truncated back-propagation for bilevel optimization. In The 22nd International Conference on Artificial Intelligence and Statistics. 1723-1732."},{"key":"e_1_3_2_2_31_1","first-page":"12096","article-title":"Does gnn pretraining help molecular representation","volume":"35","author":"Sun Ruoxi","year":"2022","unstructured":"Ruoxi Sun, Hanjun Dai, and Adams Wei Yu. 2022. Does gnn pretraining help molecular representation? Advances in Neural Information Processing Systems, Vol. 35 (2022), 12096-12109.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2024-0084"},{"key":"e_1_3_2_2_33_1","volume-title":"Social structure of facebook networks. Physica A: Statistical Mechanics and its Applications","author":"Traud Amanda L","year":"2012","unstructured":"Amanda L Traud, Peter J Mucha, and Mason A Porter. 2012. Social structure of facebook networks. Physica A: Statistical Mechanics and its Applications, Vol. 391, 16 (2012), 4165-4180."},{"key":"e_1_3_2_2_34_1","unstructured":"Guihong Wan and Harsha Kokel. 2021. Graph sparsification via meta-learning. (2021)."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627115"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2024-0073"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2024-0116"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833806"},{"key":"e_1_3_2_2_39_1","volume-title":"International conference on machine learning. 40-48","author":"Yang Zhilin","year":"2016","unstructured":"Zhilin Yang, William Cohen, and Ruslan Salakhudinov. 2016. Revisiting semi-supervised learning with graph embeddings. In International conference on machine learning. 40-48."},{"key":"e_1_3_2_2_40_1","volume-title":"32nd USENIX Security Symposium. 3241-3258","author":"Yuan Quan","year":"2023","unstructured":"Quan Yuan, Zhikun Zhang, Linkang Du, Min Chen, Peng Cheng, and Mingyang Sun. 2023. PrivGraph: Differentially Private Graph Data Publication by Exploiting Community Information. In 32nd USENIX Security Symposium. 3241-3258."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3595791"},{"key":"e_1_3_2_2_42_1","volume-title":"31st USENIX Security Symposium. 4543-4560","author":"Zhang Zhikun","year":"2022","unstructured":"Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, and Yang Zhang. 2022. Inference attacks against graph neural networks. In 31st USENIX Security Symposium. 4543-4560."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0103"}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765173","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765173","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:25:03Z","timestamp":1766442303000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765173"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":43,"alternative-id":["10.1145\/3719027.3765173","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765173","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}