Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Bayesian Membership Privacy for Graph Neural Networks

About

Existing privacy analyses for Graph Neural Networks (GNNs) largely inherit assumptions from non-graph settings, overlooking structural correlations and stochastic training-graph sampling. In particular, node-dependent priors make type-I and type-II errors alone insufficient to characterize the best membership inference test. To address this, we introduce Bayesian Membership Privacy (BMP), a sampling-aware formulation of node-level membership privacy that incorporates node-dependent priors and treats graph sampling probabilities as part of the adversary's knowledge. BMP casts membership inference as a Bayesian hypothesis test and accordingly quantifies membership privacy in terms of posterior membership probability. We explore theoretical properties of BMP in relation to the existing definitions in the literature. We further propose a practical, sampling-aware auditing mechanism to estimate the parameters of BMP as a measure of node-level privacy leakage in GNNs. We conduct experiments on benchmark graph datasets and show that BMP yields fine-grained privacy insights that are not visible through global attack accuracy alone.

Sinan Y{\i}ld{\i}r{\i}m, Megha Khosla• 2026

Related benchmarks

TaskDatasetResultRank
Membership Privacy EstimationCiteSeer 50% nodes sampled
P5 Estimate3.7
64
Membership Inference AttackCora 25% nodes (train)
p5 Score6.9
64
Privacy Parameter EstimationCiteSeer 25% nodes sampled (train)
P58.2
64
Privacy Parameter EstimationCora 50% nodes sampled (train)
p5 Estimate2.4
22
Showing 4 of 4 rows

Other info

Follow for update