跳到正文
arXiv:cs.LG· Longzhu He, Zelang Wen, Chaozhuo Li, Sen Su·· 4 小时前AI 评分43

LLM 增强图神经网络隐私风险审计研究

Auditing Privacy Risks in LLM-Enhanced Graph Neural Networks

AI 导读

研究者通过五阶段统一框架系统审计了 LLM 增强 GNN 的隐私风险,覆盖 10 个文本属性图数据集、6 种隐私攻击、42 种 LLM 增强 GNN 配置及 3 个较新语言模型骨干。实验显示,LLM 增强 GNN 虽提升效用,但在所评估攻击下隐私脆弱性始终高于浅层文本表示基线,其嵌入空间中链路、标签与成员关系信号更易被推理攻击利用。研究还评估了代表性防御措施的效果。

正文

View PDF HTML (experimental)

Abstract:Large language models (LLMs) have recently advanced graph neural networks (GNNs) by enriching node representations with semantic information, giving rise to LLM-enhanced GNNs that achieve substantial performance gains. However, how such semantic enhancement affects privacy risks remains largely underexplored. To bridge this gap, we systematically audit the privacy risks of LLM-enhanced GNNs through a unified framework consisting of five stages: (1) dataset preparation, (2) victim model training, (3) privacy attack, (4) risk assessment, and (5) defense analysis. Specifically, our evaluation spans ten text-attributed graph datasets across diverse domains, six privacy attacks, 42 LLM-enhanced GNN configurations, and three more recent language-model backbones. Extensive experiments show that, despite their utility improvements, LLM-enhanced GNNs consistently exhibit greater empirical privacy vulnerability than shallow text representation baselines under the evaluated attacks across diverse models and datasets. Further analysis shows that LLM-enhanced representations exhibit more distinguishable link-, label-, and membership-related signals in the embedding space, making them more exploitable by inference attacks. Finally, we evaluate representative defenses and examine their effectiveness in mitigating these privacy risks. Overall, this work provides a systematic audit of privacy risks in LLM-enhanced GNNs and offers insights for developing more secure and trustworthy graph learning systems.
Subjects: Machine Learning (cs.LG); Cryptography and Security (cs.CR)
Cite as: arXiv:2608.25727 [cs.LG]
  (or arXiv:2608.25727v2 [cs.LG] for this version)
  https://doi.org/10.48550/arXiv.2608.25727

arXiv-issued DOI via DataCite

Submission history

From: Longzhu He [view email]
[v1] Wed, 26 Aug 2026 12:42:21 UTC (1,196 KB)
[v2] Wed, 7 Oct 2026 13:53:09 UTC (1,092 KB)

来源:arXiv:cs.LG · arxiv.org