English

Adversarial Attacks on Locally Private Graph Neural Networks

Machine Learning 2026-03-24 v1 Cryptography and Security

Abstract

Graph neural network (GNN) is a powerful tool for analyzing graph-structured data. However, their vulnerability to adversarial attacks raises serious concerns, especially when dealing with sensitive information. Local Differential Privacy (LDP) offers a privacy-preserving framework for training GNNs, but its impact on adversarial robustness remains underexplored. This paper investigates adversarial attacks on LDP-protected GNNs. We explore how the privacy guarantees of LDP can be leveraged or hindered by adversarial perturbations. The effectiveness of existing attack methods on LDP-protected GNNs are analyzed and potential challenges in crafting adversarial examples under LDP constraints are discussed. Additionally, we suggest directions for defending LDP-protected GNNs against adversarial attacks. This work investigates the interplay between privacy and security in graph learning, highlighting the need for robust and privacy-preserving GNN architectures.

Keywords

Cite

@article{arxiv.2603.20746,
  title  = {Adversarial Attacks on Locally Private Graph Neural Networks},
  author = {Matta Varun and Ajay Kumar Dhakar and Yuan Hong and Shamik Sural},
  journal= {arXiv preprint arXiv:2603.20746},
  year   = {2026}
}
R2 v1 2026-07-01T11:31:16.842Z