cs.CRFeb 6, 2026

Taipan: A Query-free Transfer-based Multiple Sensitive Attribute Inference Attack Solely from Auxiliary Graphs

Authors: Ying Song, Balaji Palanisamy

Organizations: University of Pittsburgh Pittsburgh, PA, USA

Abstract

Graph-structured data underpin a wide spectrum of modern applications, yet their multiple sensitive attributes are not isolated but deeply coupled with graph topology. This coupling facilitates intersectional privacy leakage through attribute inference attacks (AIAs). Existing AIAs predominantly assume adversaries with two capabilities: (I) access to either auxiliary data sampled from the same distribution as the target or partial training records, and (II) the ability to repeatedly query the victim model. In reality, however, these assumptions are often impractical due to stringent data protection regulations, prohibitive query budgets, and heightened detection risks. Moreover, as prior attacks are designed to infer a single sensitive attribute at a time, they fail to simultaneously recover multiple attributes and thus underestimate overall privacy risks arising from cross-attribute dependencies. More critically, they obscure a systemic blind spot: \textbf{auxiliary graphs alone are sufficient to expose multiple sensitive attributes in the target graph.} This threat persists even under distribution shifts, enabling stealthy offline attacks without any model interactions. To investigate this unexplored vulnerability, we introduce \textbf{Taipan, the first query-free framework for multiple sensitive attribute inference attacks on graphs (G-MSAIAs).} Taipan incorporates \emph{Hierarchical Attack Knowledge Routing} to capture intricate inter-attribute correlations, and \emph{Prompt-guided Attack Prototype Refinement} to mitigate distribution shifts between auxiliary and target graphs. Extensive experiments on diverse real-world graph datasets demonstrate that Taipan consistently achieves strong attack performance across same-, similar-, and out-of-distribution settings, and remains effective under partial label coverage or even rigorous privacy guarantees.

Figures & tables

Explore similar work

CardsList
  1. GraphProfiler: Source-Linked Sensitive Attribute Inference via Personal Knowledge Graphs

    Sep 14, 2026Ahmed Sohair Khan, Estrid He, Chenglong Ma +2Membership Inference AttacksProfiling

  2. GraphToxin: Reconstructing Full Unlearned Graphs from Graph Unlearning

    Nov 14, 2025Ying Song, Balaji PalanisamyMembership Inference AttacksUnlearnable Examples