Existing privacy analyses for Graph Neural Networks (GNNs) largely inherit assumptions from non-graph settings, overlooking structural correlations and stochastic training-graph sampling. In particular, node-dependent priors make type-I and type-II errors alone insufficient to characterize the best membership inference test. To address this, we introduce Bayesian Membership Privacy (BMP), a sampling-aware formulation of node-level membership privacy that incorporates node-dependent priors and treats graph sampling probabilities as part of the adversary's knowledge. BMP casts membership inference as a Bayesian hypothesis test and accordingly quantifies membership privacy in terms of posterior membership probability. We explore theoretical properties of BMP in relation to the existing definitions in the literature. We further propose a practical, sampling-aware auditing mechanism to estimate the parameters of BMP as a measure of node-level privacy leakage in GNNs. We conduct experiments on benchmark graph datasets and show that BMP yields fine-grained privacy insights that are not visible through global attack accuracy alone.
翻译:现有的图神经网络(GNN)隐私分析很大程度上继承了非图场景的假设,忽视了结构相关性和随机训练图采样。具体而言,节点相关先验使得仅凭第一类和第二类错误不足以刻画最优成员推断测试。为此,我们提出贝叶斯成员隐私(BMP)——一种融合采样感知的节点级成员隐私形式化框架,该框架将节点相关先验纳入考量,并将图采样概率视为攻击者先验知识的一部分。BMP将成员推断视为贝叶斯假设检验,并据此通过后验成员概率量化成员隐私。我们探讨了BMP与文献中现有定义之间的理论关联,进一步提出一种实用的采样感知审计机制,用于估计BMP参数以度量GNN节点级隐私泄露程度。在基准图数据集上的实验表明,BMP能揭示仅凭全局攻击准确率无法观测到的细粒度隐私洞察。