cs.LGNov 14, 2025

GraphToxin: Reconstructing Full Unlearned Graphs from Graph Unlearning

Authors: Ying Song, Balaji Palanisamy

Organizations: University of Pittsburgh Pittsburgh, PA, USA

Abstract

Graph unlearning (GU) has emerged as a promising solution to comply with "the right to be forgotten" regulations by enabling the removal of sensitive information upon request. However, this solution is not foolproof. The involvement of multiple parties creates new attack surfaces, and residual traces of deleted data can persist within the unlearned graph neural networks (GNNs). These vulnerabilities can be exploited by attackers to recover the supposedly erased samples, undermining the intended functionality of GU. In this work, we propose GraphToxin, the first full graph reconstruction attack against GU. We show that GraphToxin can recover not only a deleted individual's information and personal links but also sensitive content of their neighbors, thereby posing substantially more detrimental threats than prior membership inference attacks (MIAs). Specifically, we introduce a novel curvature matching module to provide fine-grained guidance for full unlearned graph recovery. We further extend GraphToxin to multiple-node removal under both white-box and black-box settings, showcasing its practical feasibility and potential to cause considerable harm. We highlight the necessity of worst-case analysis and propose a systematic evaluation framework to assess attack performance under both random and worst-case node removal scenarios. Our extensive experiments demonstrate the effectiveness and flexibility of GraphToxin. Notably, current defense mechanisms are largely ineffective against this attack. Additionally, our findings reveal that existing GU verification standards based on MIAs can be misleading: they achieve membership-level protection, while the full unlearned graph remains recoverable through GraphToxin.

Figures & tables

Appendix figures & tables8 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Beyond Homophily: Towards Generalized Graph Reconstruction Attack and Defense

    Jun 6, 2026Zhanke Zhou, Bo Han, Xuan Li +3Graph Neural NetworksText-Attributed Graph

  2. Graph Federated Unlearning for Privacy Preservation

    May 4, 2026Ruotong Ma, Wentao Yu, Qizhou Wang +2Federated Graph LearningFederated Learning

  3. MUGEN: Generating Unlearnable Graph Examples for Multiple Learning Tasks

    Sep 1, 2026Ziyan Liu, Chengshuai Zhao, Huan LiuUnlearnable ExamplesGraph Representation Learning