MARATTO

article

Can Diffusion-Based Posterior Smoothing Secure GNNs from Membership Inference Attacks?

Abstract

Graph Neural Networks (GNNs) are increasingly applied in domains such as drug discovery, medical diagnostics, and community detection. Despite their powerful predictive capabilities, GNNs remain vulnerable to privacy threats, particularly in sensitive contexts like healthcare and finance where data confidentiality is paramount. This study targets a pressing security concern in GNNs by addressing the risk of data exposure through Membership Inference Attacks (MIA). We propose a novel, model agnostic defense framework based on Diffusion based Posterior Smoothing (DPS), which enhances the privacy of node level predictions by perturbing class probabilities through a learned diffusion denoising process. Unlike prior methods, DPS maintains the predictive utility of the GNN while significantly reducing the information leakage exploited by MIA adversaries. Empirical evaluations across diverse datasets and GNN architectures confirm that DPS provides robust protection against inference attacks with minimal compromise to node classification accuracy.

Research topics

  • Advanced Graph Neural Networks
  • Adversarial Robustness in Machine Learning
  • Privacy-Preserving Technologies in Data

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/aiccsa66935.2025.11315227

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.