{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:00:29Z","timestamp":1781283629026,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"DOI":"10.1145\/3806007.3810958","type":"proceedings-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:29:17Z","timestamp":1781281757000},"page":"59-69","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Adversarial Attacks on Locally Private Graph Neural Networks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-6202-9356","authenticated-orcid":false,"given":"Matta","family":"Varun","sequence":"first","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-6607-6214","authenticated-orcid":false,"given":"Ajay Kumar","family":"Dhakar","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4315-7329","authenticated-orcid":false,"given":"Shamik","family":"Sural","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4095-4506","authenticated-orcid":false,"given":"Yuan","family":"Hong","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Morgane Ayle Jan Schuchardt Lukas Gosch Daniel Z\u00fcgner and Stephan G\u00fcnnemann. 2023. Training Differentially Private Graph Neural Networks with Random Walk Sampling. arXiv:2301.00738 [cs.LG] https:\/\/arxiv.org\/abs\/2301.00738"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Karuna Bhaila Wen Huang Yongkai Wu and Xintao Wu. 2024. Local Differential Privacy in Graph Neural Networks: a Reconstruction Approach. arXiv:2309.08569 [cs.LG] https:\/\/arxiv.org\/abs\/2309.08569","DOI":"10.1137\/1.9781611978032.1"},{"key":"e_1_3_2_1_3_1","unstructured":"Yongqiang Chen Han Yang Yonggang Zhang Kaili Ma Tongliang Liu Bo Han and James Cheng. 2022. Understanding and Improving Graph Injection Attack by Promoting Unnoticeability. arXiv:2202.08057 [cs.LG]"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Eli Chien Wei-Ning Chen Chao Pan Pan Li Ayfer \u00d6zg\u00fcr and Olgica Milenkovic. 2023. Differentially Private Decoupled Graph Convolutions for Multigranular Topology Protection. arXiv:2307.06422 [cs.LG] https:\/\/arxiv.org\/abs\/2307.06422","DOI":"10.52202\/075280-1966"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1109\/TP.2024.3487819","article-title":"Blockchain Based Secure Federated Learning With Local Differential Privacy and Incentivization","volume":"1","author":"Chaudhury Saptarshi De","year":"2024","unstructured":"Saptarshi De Chaudhury, Likhith Reddy Morreddigari, Matta Varun, Tirthankar Sengupta, Sandip Chakraborty, Shamik Sural, Jaideep Vaidya, and Vijayalakshmi Atluri. 2024. Blockchain Based Secure Federated Learning With Local Differential Privacy and Incentivization. IEEE Transactions on Privacy, Vol. 1 (2024), 31-44.","journal-title":"IEEE Transactions on Privacy"},{"key":"e_1_3_2_1_6_1","volume-title":"Our Data","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork, Krishnaram Kenthapadi, Frank McSherry, Ilya Mironov, and Moni Naor. 2006a. Our Data, Ourselves: Privacy Via Distributed Noise Generation. In Advances in Cryptology - EUROCRYPT 2006, Serge Vaudenay (Ed.). 486-503."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660348"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2024.3361027"},{"key":"e_1_3_2_1_11_1","article-title":"Graph neural networks: a survey on the links between privacy and security","volume":"57","author":"Guan Faqian","year":"2024","unstructured":"Faqian Guan, Tianqing Zhu, Wanlei Zhou, and Kim-Kwang Choo. 2024. Graph neural networks: a survey on the links between privacy and security. Artificial Intelligence Review, Vol. 57 (02 2024).","journal-title":"Artificial Intelligence Review"},{"key":"e_1_3_2_1_12_1","first-page":"796","article-title":"NetFense: Adversarial Defenses Against Privacy Attacks on Neural Networks for Graph Data","volume":"35","author":"Hsieh Chung","year":"2023","unstructured":"I-Chung Hsieh and Cheng-Te Li. 2023. NetFense: Adversarial Defenses Against Privacy Attacks on Neural Networks for Graph Data. IEEE Transactions on Knowledge and Data Engineering, Vol. 35, 1 (2023), 796-809.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_1_13_1","volume-title":"Article 10 (March","author":"Joshi Rucha Bhalchandra","year":"2024","unstructured":"Rucha Bhalchandra Joshi and Subhankar Mishra. 2024. Locally and Structurally Private Graph Neural Networks. Digital Threats, 1, Article 10 (March 2024), 23 pages."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1137\/090756090"},{"key":"e_1_3_2_1_15_1","volume-title":"Kipf and Max Welling","author":"Thomas","year":"2016","unstructured":"Thomas N. Kipf and Max Welling. 2016. Semi-Supervised Classification with Graph Convolutional Networks. CoRR, Vol. abs\/1609.02907 (2016). arXiv:1609.02907"},{"key":"e_1_3_2_1_16_1","volume-title":"Lapa: Multi-Label-Flipping Adversarial Attacks on Graph Neural Networks. In 2023 International Seminar on Computer Science and Engineering Technology (SCSET). 29-32.","author":"Li Jianfeng","year":"2023","unstructured":"Jianfeng Li, Haoran Li, Jing He, and Tianchen Dou. 2023. Lapa: Multi-Label-Flipping Adversarial Attacks on Graph Neural Networks. In 2023 International Seminar on Computer Science and Engineering Technology (SCSET). 29-32."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3711122"},{"key":"e_1_3_2_1_18_1","unstructured":"Jiaqi Ma Junwei Deng and Qiaozhu Mei. 2021a. Adversarial Attack on Graph Neural Networks as An Influence Maximization Problem. arXiv:2106.10785 [cs.LG]"},{"key":"e_1_3_2_1_19_1","unstructured":"Jiaqi Ma Shuangrui Ding and Qiaozhu Mei. 2021b. Towards More Practical Adversarial Attacks on Graph Neural Networks. arXiv:2006.05057 [cs.LG]"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"crossref","first-page":"112323","DOI":"10.1016\/j.knosys.2024.112323","article-title":"Classification optimization node injection attack on graph neural networks","volume":"301","author":"Ma Mingda","year":"2024","unstructured":"Mingda Ma, Hui Xia, Xin Li, Rui Zhang, and Shuo Xu. 2024. Classification optimization node injection attack on graph neural networks. Knowledge-Based Systems, Vol. 301 (2024), 112323.","journal-title":"Knowledge-Based Systems"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3228315"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Iyiola E. Olatunji Thorben Funke and Megha Khosla. 2023. Releasing Graph Neural Networks with Differential Privacy Guarantees. arXiv:2109.08907 [cs.LG]","DOI":"10.56553\/popets-2023-0041"},{"key":"e_1_3_2_1_23_1","volume-title":"Locally Private Graph Neural Networks. CoRR","author":"Sajadmanesh Sina","year":"2021","unstructured":"Sina Sajadmanesh and Daniel Gatica-Perez. 2021. Locally Private Graph Neural Networks. CoRR, Vol. abs\/2006.05535 (2021). arXiv:2006.05535"},{"key":"e_1_3_2_1_24_1","volume-title":"ProGAP: Progressive Graph Neural Networks with Differential Privacy Guarantees. In 17th ACM International Conference on Web Search and Data Mining. 596\u2013605","author":"Sajadmanesh Sina","year":"2024","unstructured":"Sina Sajadmanesh and Daniel Gatica-Perez. 2024. ProGAP: Progressive Graph Neural Networks with Differential Privacy Guarantees. In 17th ACM International Conference on Web Search and Data Mining. 596\u2013605."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.2008.2005605"},{"key":"e_1_3_2_1_26_1","volume-title":"The Web Conference","author":"Sun Yiwei","year":"2020","unstructured":"Yiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh, and Vasant Honavar. 2020. Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning Approach. In The Web Conference 2020. 673\u2013683."},{"key":"e_1_3_2_1_27_1","volume-title":"30th ACM International Conference on Information & Knowledge Management. 1794\u20131803","author":"Tao Shuchang","year":"2021","unstructured":"Shuchang Tao, Qi Cao, Huawei Shen, Junjie Huang, Yunfan Wu, and Xueqi Cheng. 2021. Single Node Injection Attack against Graph Neural Networks. In 30th ACM International Conference on Information & Knowledge Management. 1794\u20131803."},{"key":"e_1_3_2_1_28_1","unstructured":"Petar Veli\u010dkovi\u0107 Guillem Cucurull Arantxa Casanova Adriana Romero Pietro Li\u00f2 and Yoshua Bengio. 2018. Graph Attention Networks. arXiv:1710.10903 [stat.ML]"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2023.3241615"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2024.110954"},{"key":"e_1_3_2_1_31_1","volume-title":"Adversarial Label-Flipping Attack and Defense for Graph Neural Networks. In 2020 IEEE International Conference on Data Mining (ICDM). 791-800","author":"Zhang Mengmei","year":"2020","unstructured":"Mengmei Zhang, Linmei Hu, Chuan Shi, and Xiao Wang. 2020. Adversarial Label-Flipping Attack and Defense for Graph Neural Networks. In 2020 IEEE International Conference on Data Mining (ICDM). 791-800."},{"key":"e_1_3_2_1_32_1","first-page":"7497","article-title":"A Survey on Privacy in Graph Neural Networks: Attacks, Preservation, and Applications","volume":"36","author":"Zhang Yi","year":"2024","unstructured":"Yi Zhang, Yuying Zhao, Zhaoqing Li, Xueqi Cheng, Yu Wang, Olivera Kotevska, Philip S. Yu, and Tyler Derr. 2024. A Survey on Privacy in Graph Neural Networks: Attacks, Preservation, and Applications. IEEE TKDE, Vol. 36, 12 (2024), 7497-7515.","journal-title":"IEEE TKDE"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3207915"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467314"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394520"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"}],"event":{"name":"CODASPY '26: Sixteenth ACM Conference on Data and Application Security and Privacy","location":"Frankfurt am Main Germany","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 12th ACM International Workshop on Security and Privacy Analytics"],"original-title":[],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:30:08Z","timestamp":1781281808000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3806007.3810958"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":36,"alternative-id":["10.1145\/3806007.3810958","10.1145\/3806007"],"URL":"https:\/\/doi.org\/10.1145\/3806007.3810958","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}