{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T13:01:42Z","timestamp":1785502902059,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":82,"publisher":"ACM","funder":[{"name":"the National Key Research and Development Program of China","award":["2024YFF0907401"],"award-info":[{"award-number":["2024YFF0907401"]}]},{"name":"the National Natural Science Foundation of China","award":["62072052"],"award-info":[{"award-number":["62072052"]}]},{"name":"the National Natural Science Foundation of China","award":["62202164"],"award-info":[{"award-number":["62202164"]}]},{"name":"the Shandong Provincial Natural Science Foundation","award":["ZR2025MS1038"],"award-info":[{"award-number":["ZR2025MS1038"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,8,9]]},"DOI":"10.1145\/3770854.3780158","type":"proceedings-article","created":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T12:07:40Z","timestamp":1785499660000},"page":"395-406","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Devil's Hand: Data Poisoning Attacks to Locally Private Graph Learning Protocols"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-7842-6605","authenticated-orcid":false,"given":"Longzhu","family":"He","sequence":"first","affiliation":[{"name":"Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8179-7503","authenticated-orcid":false,"given":"Chaozhuo","family":"Li","sequence":"additional","affiliation":[{"name":"Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1304-8401","authenticated-orcid":false,"given":"Peng","family":"Tang","sequence":"additional","affiliation":[{"name":"Shandong University, Qingdao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4562-2279","authenticated-orcid":false,"given":"Li","family":"Sun","sequence":"additional","affiliation":[{"name":"Beijing University of Post and Telecommunications, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4266-7527","authenticated-orcid":false,"given":"Sen","family":"Su","sequence":"additional","affiliation":[{"name":"Beijing University of Posts and Telecommunications, Beijing, China and Chongqing University of Posts and Telecommunications, Chongqing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3491-5968","authenticated-orcid":false,"given":"Philip S.","family":"Yu","sequence":"additional","affiliation":[{"name":"University of Illinois Chicago, Chicago, Illinois, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,20]]},"reference":[{"key":"e_1_3_2_2_1_1","first-page":"21","volume-title":"International Conference on Machine Learning (ICML","author":"Abu-El-Haija Sami","year":"2019","unstructured":"Sami Abu-El-Haija, Bryan Perozzi, Amol Kapoor, Nazanin Alipourfard, Kristina Lerman, Hrayr Harutyunyan, Greg Ver Steeg, and Aram Galstyan. 2019. Mixhop: Higher-order graph convolutional architectures via sparsified neighborhood mixing. In International Conference on Machine Learning (ICML 2019). PMLR, 21-29."},{"key":"e_1_3_2_2_2_1","first-page":"71","article-title":"Learning with privacy at scale","volume":"1","author":"Apple D","year":"2017","unstructured":"D Apple. 2017. Learning with privacy at scale. Apple Machine Learning Journal, Vol. 1, 8 (2017), 71.","journal-title":"Apple Machine Learning Journal"},{"key":"e_1_3_2_2_3_1","first-page":"947","volume-title":"30th USENIX Security Symposium (USENIX Security","author":"Cao Xiaoyu","year":"2021","unstructured":"Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2021. Data poisoning attacks to local differential privacy protocols. In 30th USENIX Security Symposium (USENIX Security 2021). 947-964."},{"key":"e_1_3_2_2_4_1","volume-title":"Narcissism on Facebook: Self-promotional and anti-social behavior. Personality and individual differences","author":"Carpenter Christopher J","year":"2012","unstructured":"Christopher J Carpenter. 2012. Narcissism on Facebook: Self-promotional and anti-social behavior. Personality and individual differences, Vol. 52, 4 (2012), 482-486."},{"key":"e_1_3_2_2_5_1","volume-title":"International Conference on Learning Representations (ICLR","author":"Chen Yongqiang","year":"2022","unstructured":"Yongqiang Chen, Han Yang, Yonggang Zhang, MA KAILI, Tongliang Liu, Bo Han, and James Cheng. 2022. Understanding and Improving Graph Injection Attack by Promoting Unnoticeability. In International Conference on Learning Representations (ICLR 2022)."},{"key":"e_1_3_2_2_6_1","volume-title":"Jo ao S Resende, and Lu\u00eds Antunes","author":"Cirne Andr\u00e9","year":"2024","unstructured":"Andr\u00e9 Cirne, Patr\u00edcia R Sousa, Jo ao S Resende, and Lu\u00eds Antunes. 2024. Hardware security for Internet of Things identity assurance. IEEE Communications Surveys & Tutorials (2024)."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183713.3197390"},{"key":"e_1_3_2_2_8_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2017","volume":"30","author":"Ding Bolin","year":"2017","unstructured":"Bolin Ding, Janardhan Kulkarni, and Sergey Yekhanin. 2017. Collecting telemetry data privately. Advances in Neural Information Processing Systems (NeurIPS 2017), Vol. 30 (2017)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"},{"key":"e_1_3_2_2_11_1","first-page":"4776","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2022","volume":"35","author":"Feng Jiarui","year":"2022","unstructured":"Jiarui Feng, Yixin Chen, Fuhai Li, Anindya Sarkar, and Muhan Zhang. 2022. How powerful are k-hop message passing graph neural networks. Advances in Neural Information Processing Systems (NeurIPS 2022), Vol. 35 (2022), 4776-4790."},{"key":"e_1_3_2_2_12_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2017","volume":"30","author":"Fout Alex","year":"2017","unstructured":"Alex Fout, Jonathon Byrd, Basir Shariat, and Asa Ben-Hur. 2017. Protein interface prediction using graph convolutional networks. Advances in Neural Information Processing Systems (NeurIPS 2017), Vol. 30 (2017)."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.122653799"},{"key":"e_1_3_2_2_14_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-01588-5"},{"key":"e_1_3_2_2_16_1","first-page":"22548","volume-title":"Proceedings of the 42nd International Conference on Machine Learning (ICML","volume":"267","author":"He Longzhu","year":"2025","unstructured":"Longzhu He, Chaozhuo Li, Peng Tang, and Sen Su. 2025b. Going Deeper into Locally Differentially Private Graph Neural Networks. In Proceedings of the 42nd International Conference on Machine Learning (ICML 2025), Vol. 267. PMLR, 22548-22565."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2025.104150"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE65448.2025.00079"},{"key":"e_1_3_2_2_19_1","first-page":"89","article-title":"Degree-Preserving Randomized Response for Graph Neural Networks under Local Differential Privacy","volume":"17","author":"Hidano Seira","year":"2024","unstructured":"Seira Hidano and Takao Murakami. 2024. Degree-Preserving Randomized Response for Graph Neural Networks under Local Differential Privacy. Transactions on Data Privacy, Vol. 17, 2 (2024), 89-121.","journal-title":"Transactions on Data Privacy"},{"key":"e_1_3_2_2_20_1","unstructured":"I Hsu Chih-Hsun Lin Chia-Mu Yu Sy-Yen Kuo Chun-Ying Huang et al. 2025. Poisoning Attacks to Local Differential Privacy Protocols for Trajectory Data. arXiv preprint arXiv:2503.07483 (2025)."},{"key":"e_1_3_2_2_21_1","first-page":"2436","volume-title":"International Conference on Machine Learning (ICML","author":"Kairouz Peter","year":"2016","unstructured":"Peter Kairouz, Keith Bonawitz, and Daniel Ramage. 2016. Discrete distribution estimation under local privacy. In International Conference on Machine Learning (ICML 2016). PMLR, 2436-2444."},{"key":"e_1_3_2_2_22_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2014","volume":"27","author":"Kairouz Peter","year":"2014","unstructured":"Peter Kairouz, Sewoong Oh, and Pramod Viswanath. 2014. Extremal mechanisms for local differential privacy. Advances in Neural Information Processing Systems (NeurIPS 2014), Vol. 27 (2014)."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0165"},{"key":"e_1_3_2_2_24_1","volume-title":"Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980","author":"Kingma Diederik P","year":"2014","unstructured":"Diederik P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014)."},{"key":"e_1_3_2_2_25_1","volume-title":"Semi-Supervised Classification with Graph Convolutional Networks. In 5th International Conference on Learning Representations (ICLR","author":"Thomas","year":"2017","unstructured":"Thomas N. Kipf and Max Welling. 2017. Semi-Supervised Classification with Graph Convolutional Networks. In 5th International Conference on Learning Representations (ICLR 2017)."},{"key":"e_1_3_2_2_26_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2017","volume":"30","author":"Klambauer G\u00fcnter","year":"2017","unstructured":"G\u00fcnter Klambauer, Thomas Unterthiner, Andreas Mayr, and Sepp Hochreiter. 2017. Self-normalizing neural networks. Advances in Neural Information Processing Systems (NeurIPS 2017), Vol. 30 (2017)."},{"key":"e_1_3_2_2_27_1","volume-title":"NATO group catfished soldiers to prove a point about privacy. Wired","author":"Lapowsky Issie","year":"2019","unstructured":"Issie Lapowsky. 2019. NATO group catfished soldiers to prove a point about privacy. Wired (2019)."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714555"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3644993"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11604"},{"key":"e_1_3_2_2_32_1","first-page":"1739","volume-title":"32nd USENIX Security Symposium (USENIX Security","author":"Li Xiaoguang","year":"2023","unstructured":"Xiaoguang Li, Ninghui Li, Wenhai Sun, Neil Zhenqiang Gong, and Hui Li. 2023. Fine-grained poisoning attack to local differential privacy protocols for mean and variance estimation. In 32nd USENIX Security Symposium (USENIX Security 2023). 1739-1756."},{"key":"e_1_3_2_2_33_1","first-page":"465","volume-title":"16th USENIX Symposium on Operating Systems Design and Implementation (OSDI","author":"Li Xupeng","year":"2022","unstructured":"Xupeng Li, Xuheng Li, Christoffer Dall, Ronghui Gu, Jason Nieh, Yousuf Sait, and Gareth Stockwell. 2022. Design and verification of the arm confidential compute architecture. In 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2022). 465-484."},{"key":"e_1_3_2_2_34_1","first-page":"3835","volume-title":"International Conference on Machine Learning (ICML","author":"Li Yujia","year":"2019","unstructured":"Yujia Li, Chenjie Gu, Thomas Dullien, Oriol Vinyals, and Pushmeet Kohli. 2019. Graph matching networks for learning the similarity of graph structured objects. In International Conference on Machine Learning (ICML 2019). PMLR, 3835-3845."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627673.3679759"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3389700"},{"key":"e_1_3_2_2_37_1","volume-title":"Data Poisoning Attacks to Locally Differentially Private Range Query Protocols. arXiv preprint arXiv:2503.03454","author":"Liao Ting-Wei","year":"2025","unstructured":"Ting-Wei Liao, Chih-Hsun Lin, Yu-Lin Tsai, Takao Murakami, Chia-Mu Yu, Jun Sakuma, Chun-Ying Huang, and Hiroaki Kikuchi. 2025. Data Poisoning Attacks to Locally Differentially Private Range Query Protocols. arXiv preprint arXiv:2503.03454 (2025)."},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(02)00060-2"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3198283"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3118815"},{"key":"e_1_3_2_2_41_1","volume-title":"Birds of a feather: Homophily in social networks. Annual review of sociology","author":"McPherson Miller","year":"2001","unstructured":"Miller McPherson, Lynn Smith-Lovin, and James M Cook. 2001. Birds of a feather: Homophily in social networks. Annual review of sociology, Vol. 27, 1 (2001), 415-444."},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623173"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00057"},{"key":"e_1_3_2_2_44_1","volume-title":"Friendship selection in the social internet of things: challenges and possible strategies","author":"Nitti Michele","year":"2014","unstructured":"Michele Nitti, Luigi Atzori, and Irena Pletikosa Cvijikj. 2014. Friendship selection in the social internet of things: challenges and possible strategies. IEEE Internet of things journal, Vol. 2, 3 (2014), 240-247."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2018.2820126"},{"key":"e_1_3_2_2_46_1","volume-title":"Privacy-enhanced graph neural network for decentralized local graphs","author":"Pei Xinjun","year":"2023","unstructured":"Xinjun Pei, Xiaoheng Deng, Shengwei Tian, Jianqing Liu, and Kaiping Xue. 2023. Privacy-enhanced graph neural network for decentralized local graphs. IEEE Transactions on Information Forensics and Security (2023)."},{"key":"e_1_3_2_2_47_1","volume-title":"International Workshop on Federated and Transfer Learning for Data Sparsity and Confidentiality in Conjunction with IJCAI.","author":"Pei Yang","year":"2021","unstructured":"Yang Pei, Renxin Mao, Yang Liu, Chaoran Chen, Shifeng Xu, Feng Qiang, and Blue Elephant Tech. 2021. Decentralized federated graph neural networks. In International Workshop on Federated and Transfer Learning for Data Sparsity and Confidentiality in Conjunction with IJCAI."},{"key":"e_1_3_2_2_48_1","first-page":"593","volume-title":"LinkGuard: Link Locally Privacy-Preserving Graph Neural Networks with Integrated Denoising and Private Learning. In Companion Proceedings of the ACM on Web Conference 2024 (WWW","author":"Qi Yuxin","year":"2024","unstructured":"Yuxin Qi, Xi Lin, Ziyao Liu, Gaolei Li, Jingyu Wang, and Jianhua Li. 2024. LinkGuard: Link Locally Privacy-Preserving Graph Neural Networks with Integrated Denoising and Private Learning. In Companion Proceedings of the ACM on Web Conference 2024 (WWW 2024). 593-596."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1093\/comnet\/cnab014"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411866"},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484565"},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"e_1_3_2_2_53_1","volume-title":"Scientists found over 1,000 AI bots on X stealing selfies to create fake accounts. New York Post","author":"Shannon Thaler","year":"2023","unstructured":"Thaler Shannon. 2023. Scientists found over 1,000 AI bots on X stealing selfies to create fake accounts. New York Post (2023)."},{"key":"e_1_3_2_2_54_1","first-page":"7693","article-title":"Adversarial attack and defense on graph data: A survey","volume":"35","author":"Sun Lichao","year":"2022","unstructured":"Lichao Sun, Yingtong Dou, Carl Yang, Kai Zhang, Ji Wang, S Yu Philip, Lifang He, and Bo Li. 2022a. Adversarial attack and defense on graph data: A survey. IEEE Transactions on Knowledge and Data Engineering, Vol. 35, 8 (2022), 7693-7711.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i4.20333"},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE60146.2024.00132"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670298"},{"key":"e_1_3_2_2_58_1","first-page":"991","volume-title":"27th USENIX Security Symposium (USENIX Security","author":"Bulck Jo Van","year":"2018","unstructured":"Jo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel kingdom with transient execution. In 27th USENIX Security Symposium (USENIX Security 2018). 991-1008."},{"key":"e_1_3_2_2_59_1","volume-title":"Graph Attention Networks. In 6th International Conference on Learning Representations (ICLR","author":"Velickovic Petar","year":"2018","unstructured":"Petar Velickovic, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Li\u00f2, and Yoshua Bengio. 2018. Graph Attention Networks. In 6th International Conference on Learning Representations (ICLR 2018)."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2019.00063"},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3299869.3319891"},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560662"},{"key":"e_1_3_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330950"},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3542609"},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3494523"},{"key":"e_1_3_2_2_66_1","first-page":"519","volume-title":"31st USENIX Security Symposium (USENIX Security","author":"Wu Yongji","year":"2022","unstructured":"Yongji Wu, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2022a. Poisoning attacks to local differential privacy protocols for data. In 31st USENIX Security Symposium (USENIX Security 2022). 519-536."},{"key":"e_1_3_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2023.103827"},{"key":"e_1_3_2_2_68_1","first-page":"40","volume-title":"International Conference on Machine Learning (ICML","author":"Yang Zhilin","year":"2016","unstructured":"Zhilin Yang, William Cohen, and Ruslan Salakhudinov. 2016. Revisiting semi-supervised learning with graph embeddings. In International Conference on Machine Learning (ICML 2016). PMLR, 40-48."},{"key":"e_1_3_2_2_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219890"},{"key":"e_1_3_2_2_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978326"},{"key":"e_1_3_2_2_71_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.112488"},{"key":"e_1_3_2_2_72_1","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2018","volume":"31","author":"Zhang Muhan","year":"2018","unstructured":"Muhan Zhang and Yixin Chen. 2018. Link prediction based on graph neural networks. Advances in Neural Information Processing Systems (NeurIPS 2018), Vol. 31 (2018)."},{"key":"e_1_3_2_2_73_1","first-page":"9263","volume-title":"Advances in Neural Information Processing Systems (NeurIPS 2020","volume":"33","author":"Zhang Xiang","year":"2020","unstructured":"Xiang Zhang and Marinka Zitnik. 2020. Gnnguard: Defending graph neural networks against adversarial attacks. Advances in Neural Information Processing Systems (NeurIPS 2020), Vol. 33 (2020), 9263-9275."},{"key":"e_1_3_2_2_74_1","volume-title":"Graph neural networks and their current applications in bioinformatics. Frontiers in genetics","author":"Zhang Xiao-Meng","year":"2021","unstructured":"Xiao-Meng Zhang, Li Liang, Lin Liu, and Ming-Jing Tang. 2021. Graph neural networks and their current applications in bioinformatics. Frontiers in genetics, Vol. 12 (2021), 690049."},{"key":"e_1_3_2_2_75_1","volume-title":"A survey on privacy in graph neural networks: Attacks, preservation, and applications","author":"Zhang Yi","year":"2024","unstructured":"Yi Zhang, Yuying Zhao, Zhaoqing Li, Xueqi Cheng, Yu Wang, Olivera Kotevska, S Yu Philip, and Tyler Derr. 2024b. A survey on privacy in graph neural networks: Attacks, preservation, and applications. IEEE Transactions on Knowledge and Data Engineering (2024)."},{"key":"e_1_3_2_2_76_1","first-page":"4543","volume-title":"31st USENIX Security Symposium (USENIX Security","author":"Zhang Zhikun","year":"2022","unstructured":"Zhikun Zhang, Min Chen, Michael Backes, Yun Shen, and Yang Zhang. 2022. Inference attacks against graph neural networks. In 31st USENIX Security Symposium (USENIX Security 2022). 4543-4560."},{"key":"e_1_3_2_2_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3672061"},{"key":"e_1_3_2_2_78_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"e_1_3_2_2_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623165"},{"key":"e_1_3_2_2_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467314"},{"key":"e_1_3_2_2_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"},{"key":"e_1_3_2_2_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394520"}],"event":{"name":"KDD '26: The 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Jeju Island Republic of Korea","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3770854.3780158","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T12:08:13Z","timestamp":1785499693000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3770854.3780158"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,20]]},"references-count":82,"alternative-id":["10.1145\/3770854.3780158","10.1145\/3770854"],"URL":"https:\/\/doi.org\/10.1145\/3770854.3780158","relation":{},"subject":[],"published":{"date-parts":[[2026,4,20]]},"assertion":[{"value":"2026-04-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}