{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T21:03:37Z","timestamp":1780002217317,"version":"3.53.1"},"reference-count":0,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["PoPETs"],"abstract":"<jats:p>Graph Neural Networks (GNNs) are deep learning models designed to address the complexities of graph-structured, non-Euclidean data. Due to their complexity, knowledge distillation (KD) is often employed to transfer knowledge from a GNN to a simpler, more efficient student model, such as a Multi-Layer Perceptron (MLP), enabling deployment in large-scale industrial applications. However, KD can inadvertently leak sensitive information from the teacher to the student, posing significant privacy risks. We present the first membership inference attacks targeting GNNs in KD pipeline, showing that student MLPs can reveal whether a node appeared in the teacher\u2019s training data. Our attacks operate in a black-box setting, requiring access only to the student outputs, and remain effective in cross-dataset scenarios. Experimental evaluations across four GNN models and eight datasets show the effectiveness of our approach, achieving up to 0.9014 precision under low FPR of 1% in cross-dataset settings. These results expose significant vulnerabilities in GNN-based KD frameworks, emphasizing the need for strong security measures during the KD process involving GNNs.<\/jats:p>","DOI":"10.56553\/popets-2026-0050","type":"journal-article","created":{"date-parts":[[2026,5,22]],"date-time":"2026-05-22T23:10:41Z","timestamp":1779491441000},"page":"318-335","source":"Crossref","is-referenced-by-count":0,"title":["Unveiling Graph Copycats: Inference Attacks with Student Models"],"prefix":"10.56553","volume":"2026","author":[{"given":"Paul","family":"Agbaje","sequence":"first","affiliation":[{"name":"University of Texas at Arlington"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Afia","family":"Anjum","sequence":"additional","affiliation":[{"name":"University of Texas at Arlington"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Arkajyoti","family":"Mitra","sequence":"additional","affiliation":[{"name":"University of Texas at Arlington"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Habeeb","family":"Olufowobi","sequence":"additional","affiliation":[{"name":"University of Texas at Arlington"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"35752","published-online":{"date-parts":[[2026,4]]},"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"deposited":{"date-parts":[[2026,5,28]],"date-time":"2026-05-28T20:21:14Z","timestamp":1779999674000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2026\/popets-2026-0050.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4]]},"references-count":0,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2026,4]]}},"alternative-id":["10.56553\/popets-2026-0050"],"URL":"https:\/\/doi.org\/10.56553\/popets-2026-0050","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4]]}}}