cs.CRFeb 6, 2026

Taipan: A Query-free Transfer-based Multiple Sensitive Attribute Inference Attack Solely from Auxiliary Graphs

Authors: Ying Song, Balaji Palanisamy

Organizations: University of Pittsburgh Pittsburgh, PA, USA

Abstract

Graph-structured data underpin a wide spectrum of modern applications, yet their multiple sensitive attributes are not isolated but deeply coupled with graph topology. This coupling facilitates intersectional privacy leakage through attribute inference attacks (AIAs). Existing AIAs predominantly assume adversaries with two capabilities: (I) access to either auxiliary data sampled from the same distribution as the target or partial training records, and (II) the ability to repeatedly query the victim model. In reality, however, these assumptions are often impractical due to stringent data protection regulations, prohibitive query budgets, and heightened detection risks. Moreover, as prior attacks are designed to infer a single sensitive attribute at a time, they fail to simultaneously recover multiple attributes and thus underestimate overall privacy risks arising from cross-attribute dependencies. More critically, they obscure a systemic blind spot: \textbf{auxiliary graphs alone are sufficient to expose multiple sensitive attributes in the target graph.} This threat persists even under distribution shifts, enabling stealthy offline attacks without any model interactions. To investigate this unexplored vulnerability, we introduce \textbf{Taipan, the first query-free framework for multiple sensitive attribute inference attacks on graphs (G-MSAIAs).} Taipan incorporates \emph{Hierarchical Attack Knowledge Routing} to capture intricate inter-attribute correlations, and \emph{Prompt-guided Attack Prototype Refinement} to mitigate distribution shifts between auxiliary and target graphs. Extensive experiments on diverse real-world graph datasets demonstrate that Taipan consistently achieves strong attack performance across same-, similar-, and out-of-distribution settings, and remains effective under partial label coverage or even rigorous privacy guarantees.

Figures & tables

Explore similar work

Sep 14, 2026cs.CL

GraphProfiler: Source-Linked Sensitive Attribute Inference via Personal Knowledge Graphs

Sensitive attributes such as age, income, and occupation can be inferred from user-generated content by aggregating indirect cues across many ordinary posts. LLM-based profilers can perform this aggregation automatically and with high accuracy, which makes large-scale personal attribute inference a major privacy threat. Existing LLM-based profilers, however, offer limited insight into which specific posts, concepts, and relationships made an inference possible, which is key to targeted privacy mitigation, i.e., redacting or rewriting only the few posts that actually leak an attribute, rather than perturbing entire histories. We introduce GraphProfiler, an auditable LLM-based profiler that represents each user's post history as a source-linked personal knowledge graph where nodes and edges trace back to the originating post and resolves attribute predictions to cited graph records and source texts. GraphProfiler reaches 86.7% attack success rate on the eight-attribute SynthPAI benchmark, within two points of strong text-only baselines, and 84.6% on PANDORA, while citing supporting evidence for over 98% of predictions. Our controlled ablation experiments provide evidence that the cited posts contribute to attack success, as removing them reduces the attack success rate substantially more than removing an equal number of random posts.
May 19, 2026cs.CR

Inferring Sensitive Attributes from Knowledge Graph Embeddings: Attack and Defense Strategies

Knowledge Graphs (KGs) are a powerful representation of linked data, offering flexibility, semantic richness, and support for knowledge enrichment and reasoning. They help data owners organize and exploit heterogeneous data to provide insightful services (e.g., recommendations), yet real-world KGs are often incomplete, hiding true facts or missing valuable insights. Knowledge graph embedding techniques are commonly used to infer valuable missing information. However, reasoning over KGs can inadvertently expose sensitive user information, even when such data is not explicitly stored. In this work, we investigate the privacy risks associated with KGE-based reasoning, focusing on attribute inference attacks where adversaries attempt to deduce sensitive user attributes from seemingly non-sensitive outputs. We propose and evaluate a framework that mitigates these privacy risks by applying post processing sanitization techniques to KGE outputs. Preliminary results demonstrate the effectiveness of these attacks on the outputs of KGE models, and explore the trade-off between recommendation quality and privacy protection when applying randomization based approaches, highlighting the need to experiment with more advanced techniques in future work to address this issue.
Nov 14, 2025cs.LG

GraphToxin: Reconstructing Full Unlearned Graphs from Graph Unlearning

Graph unlearning (GU) has emerged as a promising solution to comply with "the right to be forgotten" regulations by enabling the removal of sensitive information upon request. However, this solution is not foolproof. The involvement of multiple parties creates new attack surfaces, and residual traces of deleted data can persist within the unlearned graph neural networks (GNNs). These vulnerabilities can be exploited by attackers to recover the supposedly erased samples, undermining the intended functionality of GU. In this work, we propose GraphToxin, the first full graph reconstruction attack against GU. We show that GraphToxin can recover not only a deleted individual's information and personal links but also sensitive content of their neighbors, thereby posing substantially more detrimental threats than prior membership inference attacks (MIAs). Specifically, we introduce a novel curvature matching module to provide fine-grained guidance for full unlearned graph recovery. We further extend GraphToxin to multiple-node removal under both white-box and black-box settings, showcasing its practical feasibility and potential to cause considerable harm. We highlight the necessity of worst-case analysis and propose a systematic evaluation framework to assess attack performance under both random and worst-case node removal scenarios. Our extensive experiments demonstrate the effectiveness and flexibility of GraphToxin. Notably, current defense mechanisms are largely ineffective against this attack. Additionally, our findings reveal that existing GU verification standards based on MIAs can be misleading: they achieve membership-level protection, while the full unlearned graph remains recoverable through GraphToxin.