{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T14:42:44Z","timestamp":1777473764815,"version":"3.51.4"},"reference-count":27,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T00:00:00Z","timestamp":1777248000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Machine unlearning in federated graph learning must satisfy the multi-level indistinguishability requirement of the deletion of a target node being undetectable at the level of the global model, of the unlearning client\u2019s local model, and of every non-target client\u2019s local model. Approximate unlearning methods that pass confidence-based audits may still leave geometric traces through embedding drift at one or more of these K+1 levels. We formalize this requirement, introduce a five-model threat taxonomy, and extend the Hub\u2013Ripple embedding drift audit to global, local, and cross-client levels. Across 31,900 trials spanning five graph benchmarks, five federated unlearning methods, and four supplementary ablations (K-value, cross-edge handling, control sampling, and DP-SGD defense), we find that all approximate methods fail the following multi-level requirement: the Confidence\u2013Embedding Gap persists at 0.12 (versus 0.35 centralized), cross-client leakage correlates with shared cross-edge count (r=0.56, p&lt;10\u2212160), and a federated participant outperforms a white-box external auditor (AUC 0.83 versus 0.81). Client-level unlearning is more detectable at the global level than node-level unlearning (AUC 0.81 versus 0.77), contradicting the intuition that coarser deletion yields stronger privacy. FedRetrain satisfies global and local indistinguishability but exhibits residual cross-client leakage (Cross-Mean L2 AUC =0.62\u00b10.04) because re-aggregation itself perturbs the global parameter vector. No method evaluated achieves full multi-level indistinguishability. Supplementary studies confirm that this is a structural property of FedAvg; DP-SGD reduces Cross L2 AUC by only 0.013 at the cost of a 79% accuracy drop, and FedSage-like neighbor sharing does not change the leakage profile. Multi-level geometric auditing, spanning all K+1 models, is the necessary evaluation floor that any method claiming verifiable privacy compliance must satisfy.<\/jats:p>","DOI":"10.3390\/info17050424","type":"journal-article","created":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T13:26:41Z","timestamp":1777382801000},"page":"424","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Federated Illusion: Multi-Level Geometric Privacy Audit for Federated Graph Unlearning"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-8476-1710","authenticated-orcid":false,"given":"Haoke","family":"Han","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Qingdao University, Qingdao 266071, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7775-4597","authenticated-orcid":false,"given":"Yan","family":"Huang","sequence":"additional","affiliation":[{"name":"Department of Software Engineering and Game Development, Kennesaw State University, Kennesaw, GA 30144, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8907-2064","authenticated-orcid":false,"given":"Zhenzhen","family":"Xie","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Shandong University, Qingdao 266237, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9647-5582","authenticated-orcid":false,"given":"Junjie","family":"Pang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Qingdao University, Qingdao 266071, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,4,27]]},"reference":[{"key":"#cr-split#-ref_1.1","unstructured":"European Parliament and Council of the European Union (2016). Regulation"},{"key":"#cr-split#-ref_1.2","unstructured":"(EU) 2016\/679 of the European Parliament and of the Council, European Union. Regulation (EU)."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Cao, Y., and Yang, J. (2015). Towards making systems forget with machine unlearning. Proceedings of the 2015 IEEE Symposium on Security and Privacy, IEEE.","DOI":"10.1109\/SP.2015.35"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"100254","DOI":"10.1016\/j.hcc.2024.100254","article-title":"An overview of machine unlearning","volume":"5","author":"Li","year":"2025","journal-title":"High-Confid. Comput."},{"key":"ref_4","unstructured":"Cheng, J., Dasoulas, G., He, H., Agarwal, C., and Zitnik, M. (2023). Gnndelete: A general strategy for unlearning in graph neural networks. arXiv."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Wu, J., Yang, Y., Qian, Y., Sui, Y., Wang, X., and He, X. (2023). Gif: A general graph unlearning strategy via influence function. Proceedings of the ACM Web Conference 2023, Association for Computing Machinery.","DOI":"10.1145\/3543507.3583521"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Chen, M., Zhang, Z., Wang, T., Backes, M., Humbert, M., and Zhang, Y. (2022). Graph unlearning. Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery.","DOI":"10.1145\/3548606.3559352"},{"key":"ref_7","unstructured":"Kipf, T.N., and Welling, M. (2016). Semi-supervised classification with graph convolutional networks. arXiv."},{"key":"ref_8","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and y Arcas, B.A. (2017). Communication-efficient learning of deep networks from decentralized data. Proceedings of the Artificial Intelligence and Statistics, PMLR."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Bourtoule, L., Chandrasekaran, V., Choquette-Choo, C.A., Jia, H., Travers, A., Zhang, B., Lie, D., and Papernot, N. (2021). Machine unlearning. Proceedings of the 2021 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP40001.2021.00019"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Liu, G., Ma, X., Yang, Y., Wang, C., and Liu, J. (2021). Federaser: Enabling efficient client-level data removal from federated learning models. Proceedings of the 2021 IEEE\/ACM 29th International Symposium on Quality of Service (IWQOS), IEEE.","DOI":"10.1109\/IWQOS52092.2021.9521274"},{"key":"ref_11","unstructured":"He, X., Wen, R., Wu, Y., Backes, M., Shen, Y., and Zhang, Y. (2021). Node-level membership inference attacks against graph neural networks. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Song, C., and Raghunathan, A. (2020). Information leakage in embedding models. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery.","DOI":"10.1145\/3372297.3417270"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019). Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP.2019.00065"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Xiao, Y., Ma, Z., Huang, W., Qiao, C., Zhao, B., Zhang, D., and Pei, Q. (2025). Pure-GNN: A Lightweight Purified Graph Neural Network against Adversarial Attacks. Tsinghua Sci. Technol.","DOI":"10.26599\/TST.2025.9010034"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Chen, K., Li, W., Cao, J., Mi, B., and Shen, J. (2025). Optimizing Federated Incremental Learning: Efficient Malicious Data Removal for Big Data Analytics. Tsinghua Sci. Technol.","DOI":"10.26599\/TST.2025.901002"},{"key":"ref_16","first-page":"234","article-title":"Reliable and Secure Anomaly Detection in Heterogeneous Federated Learning: A Comprehensive Review","volume":"8","author":"Xiang","year":"2025","journal-title":"Big Data Min. Anal."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"189","DOI":"10.26599\/BDMA.2024.9020053","article-title":"BPS-FL: Blockchain-Based Privacy-Preserving and Secure Federated Learning","volume":"8","author":"Yu","year":"2025","journal-title":"Big Data Min. Anal."},{"key":"ref_18","first-page":"6671","article-title":"Subgraph federated learning with missing neighbor generation","volume":"34","author":"Zhang","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_19","unstructured":"He, C., Balasubramanian, K., Ceyani, E., Yang, C., Xie, H., Sun, L., He, L., Yang, L., Yu, P.S., and Rong, Y. (2021). Fedgraphnn: A federated learning system and benchmark for graph neural networks. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017). Membership inference attacks against machine learning models. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP.2017.41"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., and Tramer, F. (2022). Membership inference attacks from first principles. Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), IEEE.","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"359","DOI":"10.1137\/S1064827595287997","article-title":"A fast and high quality multilevel scheme for partitioning irregular graphs","volume":"20","author":"Karypis","year":"1998","journal-title":"SIAM J. Sci. Comput."},{"key":"ref_23","first-page":"65","article-title":"A simple sequentially rejective multiple test procedure","volume":"6","author":"Holm","year":"1979","journal-title":"Scand. J. Stat."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K., and Zhang, L. (2016). Deep learning with differential privacy. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery.","DOI":"10.1145\/2976749.2978318"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"100302","DOI":"10.1016\/j.hcc.2025.100302","article-title":"FedViTBloc: Secure and privacy-enhanced medical image analysis with federated vision transformer and blockchain","volume":"5","author":"Amaizu","year":"2025","journal-title":"High-Confid. Comput."},{"key":"ref_26","unstructured":"Nguyen, J., Malik, K., Zhan, H., Yousefpour, A., Rabbat, M., Esmaeili, M., and Huba, D. (2022). Federated learning with buffered asynchronous aggregation. Proceedings of the International Conference on Artificial Intelligence and Statistics, PMLR."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/5\/424\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T13:47:38Z","timestamp":1777384058000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/5\/424"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,27]]},"references-count":27,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2026,5]]}},"alternative-id":["info17050424"],"URL":"https:\/\/doi.org\/10.3390\/info17050424","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,27]]}}}