GrOVe: Ownership Verification of Graph Neural Networks using Embeddings

Asim Waheed*, Vasisht Duddu, N. Asokan

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference article in proceedingsScientificpeer-review

4 Citations (Scopus)

Abstract

Graph neural networks (GNNs) have emerged as a state-of-the-art approach to model and draw inferences from large scale graph-structured data in various application settings such as social networking. The primary goal of a GNN is to learn an embedding for each graph node in a dataset that encodes both the node features and the local graph structure around the node.Prior work has shown that GNNs are prone to model extraction attacks. Model extraction attacks and defenses have been explored extensively in other non-graph settings. While detecting or preventing model extraction appears to be difficult, deterring them via effective ownership verification techniques offer a potential defense. In non-graph settings, fingerprinting models, or the data used to build them, have shown to be a promising approach toward ownership verification.We present GrOVe, a state-of-the-art GNN model fingerprinting scheme that, given a target model and a suspect model, can reliably determine if the suspect model was trained independently of the target model or if it is a surrogate of the target model obtained via model extraction. We show that GrOVe can distinguish between surrogate and independent models even when the independent model uses the same training dataset and architecture as the original target model.Using six benchmark datasets and three model architectures, we show that GrOVe consistently achieves low falsepositive and false-negative rates. We demonstrate that GrOVe is robust against known fingerprint evasion techniques while remaining computationally efficient.

Original languageEnglish
Title of host publicationProceedings - 45th IEEE Symposium on Security and Privacy, SP 2024
PublisherIEEE
Pages2460-2477
Number of pages18
ISBN (Electronic)9798350331301
DOIs
Publication statusPublished - 2024
MoE publication typeA4 Conference publication
EventIEEE Symposium on Security and Privacy - San Francisco, United States
Duration: 20 May 202423 May 2024
Conference number: 45

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
ISSN (Print)1081-6011

Conference

ConferenceIEEE Symposium on Security and Privacy
Abbreviated titleSP
Country/TerritoryUnited States
CitySan Francisco
Period20/05/202423/05/2024

Keywords

  • Graph Neural Networks
  • Model Extraction
  • Ownership Verification

Fingerprint

Dive into the research topics of 'GrOVe: Ownership Verification of Graph Neural Networks using Embeddings'. Together they form a unique fingerprint.

Cite this