Bang Wu 0004

dblp:220/9034-4 · DBLP profile ↗
← Back
14ranked-venue papers
6as first author
14since 2021 · last 2026
0009-0001-0204-7246ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Imprint of the Forgotten: Stealthy Membership Inference in Unlearned Graph Neural Networks
abstract
Graphs effectively model interactions in real-world applications such as social and trade networks, where Graph Neural Networks (GNNs) excel at tasks such as link prediction to enhance user experiences. Despite these benefits, users raise privacy concerns as user data can be exploited to improve GNN performance without consent. Accordingly, various graph unlearning methods have been developed. Prior work shows that comparing models before and after unlearning enables attackers to launch former membership inference attacks (FMIA) on unlearned data. However, the imprint of unlearned data left in the unlearned model itself remains underexplored, and existing membership inference methods mainly exploit overfitting, making them ineffective for identifying unlearned data. To address this, we conducted theoretical analysis and proposed an attack framework targeting unlearned GNNs by learning the distribution patterns of unlearned data to distinguish them from normal test data. Extensive experiments on four real-world datasets and GNN architectures confirm our framework's effectiveness and reveal significant vulnerabilities in current graph unlearning methods.
He Zhang 0012, Bang Wu 0004, Xiaoning Liu 0002, Karin Verspoor, Xun Yi
AAAI2
2025 Unsupervised Backdoor Detection and Mitigation for Spiking Neural Networks
abstract
Spiking Neural Networks (SNNs) have attracted significant attention from the research community due to their high energy efficiency compared to Artificial Neural Networks (ANNs). However, rare studies on the security of SNNs were conducted, especially in backdoor attacks. Existing defense methods for ANN backdoor attacks either perform poorly or can be easily bypassed in SNN scenarios due to SNNs’ event-driven and temporal dependency characteristics, posing significant research challenges. In this paper, we identify the blockers to existing backdoor defenses for defending against attacks in SNNs and propose an unsupervised post-training backdoor detection method named Temporal Membrane Potential Backdoor Detection (TMPBD) to address those blockers in SNNs with neuromorphic data. Specifically, TMPBD employs the maximum margin statistic of temporal membrane potential in the last spiking layer of the SNNs to detect attack target labels without knowledge of the attack or access to any data. Moreover, we also design a practical and robust mitigation mechanism named Neural Dendrites Suppression Backdoor Mitigation (NDSBM). NDSBM dually clamps the neural dendrites, i.e., the weights connecting the first two convolution layers in each convolution block to limit the backdoor effect, while preserving the benign model behaviors learned from the temporal membrane potential obtained from a small, clean, unlabeled dataset in the same domain. To evaluate the performance, we conduct a comprehensive evaluation with multiple backdoor attack techniques, including the SOTA input-aware dynamic trigger attack dedicated to SNNs with clean models on three neuromorphic benchmark datasets. The results demonstrated that TMPBD achieves 100% prediction accuracy in detecting dynamic trigger attacks and associating attack target labels in all benchmark datasets. NDSBM lowered the attack success rate (ASR) from 100% caused by the dynamic trigger attack down to 8.44% with only mitigation or 2.81% when combined with detection for an end-to-end pipeline without performance degradation in clean accuracy.
Bang Wu 0004, Xiaoyu Xia 0001, Xiaoning Liu 0002, Xun Yi, Xiuzhen Zhang 0001
RAID2
2025 Dynamic Graph Unlearning: A General and Efficient Post-Processing Method via Gradient Transformation
abstract
Dynamic graph neural networks (DGNNs) have emerged and been widely deployed in various web applications (e.g., Reddit) to serve users (e.g., personalized content delivery) due to their remarkable ability to learn from complex and dynamic user interaction data. Despite benefiting from high-quality services, users have raised privacy concerns, such as misuse of personal data (e.g., dynamic user-user/item interaction) for model training, requiring DGNNs to "forget" their data to meet AI governance laws (e.g., the "right to be forgotten" in GDPR). However, current static graph unlearning studies cannot unlearn dynamic graph elements and exhibit limitations such as the model-specific design or reliance on pre-processing, which disenable their practicability in dynamic graph unlearning. To this end, we study the dynamic graph unlearning for the first time and propose an effective, efficient, general, and post-processing method to implement DGNN unlearning. Specifically, we first formulate dynamic graph unlearning in the context of continuous-time dynamic graphs, and then propose a method called Gradient Transformation that directly maps the unlearning request to the desired parameter update. Comprehensive evaluations on six real-world datasets and state-of-the-art DGNN backbones demonstrate its effectiveness (e.g., limited drop or obvious improvement in utility) and efficiency (e.g., 7.23× speed-up) advantages. Additionally, our method has the potential to handle future unlearning requests with significant performance gains (e.g., 32.59× speed-up).
He Zhang 0012, Bang Wu 0004, Xiangwen Yang, Xingliang Yuan, Xiaoning Liu 0002, Xun Yi
WWW2
2024 GraphGuard: Detecting and Counteracting Training Data Misuse in Graph Neural Networks
Bang Wu 0004, He Zhang 0012, Xiangwen Yang, Shuo Wang 0012, Minhui Xue 0001, Shirui Pan, Xingliang Yuan
NDSS1
2024 Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity Verification
abstract
The deployment of Graph Neural Networks (GNNs) within Machine Learning as a Service (MLaaS) has opened up new attack surfaces and an escalation in security concerns regarding model-centric attacks. These attacks can directly manipulate the GNN model parameters during serving, causing incorrect predictions and posing substantial threats to essential GNN applications. Traditional integrity verification methods falter in this context due to the limitations imposed by MLaaS and the distinct characteristics of GNN models.In this research, we introduce a groundbreaking approach to protect GNN models in MLaaS from model-centric attacks. Our approach includes a comprehensive verification schema for GNN’s integrity, taking into account both transductive and inductive GNNs, and accommodating varying pre-deployment knowledge of the models. We propose a query-based verification technique, fortified with innovative node fingerprint generation algorithms. To deal with advanced attackers who know our mechanisms in advance, we introduce randomized fingerprint nodes within our design. The experimental evaluation demonstrates that our method can detect five representative adversarial model-centric attacks, displaying 2 to 4 times greater efficiency compared to baselines.
Bang Wu 0004, Xingliang Yuan, Shuo Wang 0012, Qi Li 0002, Minhui Xue 0001, Shirui Pan
SP1
2024 Trustworthy Graph Neural Networks: Aspects, Methods, and Trends
abstract
Graph neural networks (GNNs) have emerged as a series of competent graph learning methods for diverse real-world scenarios, ranging from daily applications such as recommendation systems and question answering to cutting-edge technologies such as drug discovery in life sciences and n-body simulation in astrophysics. However, task performance is not the only requirement for GNNs. Performance-oriented GNNs have exhibited potential adverse effects, such as vulnerability to adversarial attacks, unexplainable discrimination against disadvantaged groups, or excessive resource consumption in edge computing environments. To avoid these unintentional harms, it is necessary to build competent GNNs characterized by trustworthiness. To this end, we propose a comprehensive roadmap to build trustworthy GNNs from the view of the various computing technologies involved. In this survey, we introduce basic concepts and comprehensively summarize existing efforts for trustworthy GNNs from six aspects, including robustness, explainability, privacy, fairness, accountability, and environmental well-being. In addition, we highlight the intricate cross-aspect relations between the above six aspects of trustworthy GNNs. Finally, we present a thorough overview of trending directions for facilitating the research and industrialization of trustworthy GNNs.
He Zhang 0012, Bang Wu 0004, Xingliang Yuan, Shirui Pan, Hanghang Tong, Jian Pei 0001
Proc. IEEE2
2024 DeFiGuard: A Price Manipulation Detection Service in DeFi Using Graph Neural Networks
abstract
The prosperity of Decentralized Finance (DeFi) unveils underlying risks, with reported losses surpassing 3.2 billion USD between 2018 and 2022 due to vulnerabilities in Decentralized Applications (DApps). One significant threat is the Price Manipulation Attack (PMA) that alters asset prices during transaction execution. As a result, PMA accounts for over 50 million USD in losses. To address the urgent need for efficient PMA detection, this article introduces a novel detection service,DeFiGuard, using Graph Neural Networks (GNNs). In this article, we propose cash flow graphs with four distinct features, which capture the trading behaviors from transactions. Moreover,DeFiGuardintegrates transaction parsing, graph construction, model training, and PMA detection. Evaluations on the collected transactions demonstrate thatDeFiGuardwith GNN models outperforms the baseline MLP model and classical classification models in Accuracy, TPR, FPR, and AUC-ROC. The results of ablation studies suggest that the combination of the four proposed node features enhancesDeFiGuard’s efficacy. Moreover,DeFiGuardclassifies transactions within 0.892 to 5.317 seconds, which provides sufficient time for the victims (DApps and users) to take action to rescue their vulnerable funds. In conclusion, this research offers a significant step towards safeguarding the DeFi landscape from PMAs using GNNs.
Dabao Wang, Bang Wu 0004, Xingliang Yuan, Lei Wu 0012, Yajin Zhou, Helei Cui
IEEE Trans. Serv. Comput.2
2023 Demystifying Uneven Vulnerability of Link Stealing Attacks against Graph Neural Networks
abstract
While graph neural networks (GNNs) dominate the state-of-the-art for exploring graphs in real-world applications, they have been shown to be vulnerable to a growing number of privacy attacks. For instance, link stealing is a well-known membership inference attack (MIA) on edges that infers the presence of an edge in a GNN’s training graph. Recent studies on independent and identically distributed data (e.g., images) have empirically demonstrated that individuals from different groups suffer from different levels of privacy risks to MIAs, i.e., uneven vulnerability. However, theoretical evidence of such uneven vulnerability is missing. In this paper, we first present theoretical evidence of the uneven vulnerability of GNNs to link stealing attacks, which lays the foundation for demystifying such uneven risks among different groups of edges. We further demonstrate a group-based attack paradigm to expose the practical privacy harm to GNN users derived from the uneven vulnerability of edges. Finally, we empirically validate the existence of obvious uneven vulnerability on nine real-world datasets (e.g., about 25% AUC difference between different groups in the Credit graph). Compared with existing methods, the outperformance of our group-based attack paradigm confirms that customising different strategies for different groups results in more effective privacy attacks.
He Zhang 0012, Bang Wu 0004, Shuo Wang 0012, Xiangwen Yang, Minhui Xue 0001, Shirui Pan, Xingliang Yuan
ICML2
2023 Defeating Misclassification Attacks Against Transfer Learning
abstract
Transfer learning is prevalent as a technique to efficiently generate new models (Student models) based on the knowledge transferred from a pre-trained model (Teacher model). However, Teacher models are often publicly available for sharing and reuse, which inevitably introduces vulnerability to trigger severe attacks against transfer learning systems. In this article, we take a first step towards mitigating one of the most advanced misclassification attacks in transfer learning. We design a distilleddifferentiatorvia activation-based network pruning to enervate the attack transferability while retaining accuracy. We adopt an ensemble structure from variant differentiators to improve the defence robustness. To avoid the bloated ensemble size during inference, we propose a two-phase defence, in which inference from the Student model is first performed to narrow down the candidate differentiators to be assembled, and later only a small, fixed number of them can be chosen to validate clean or reject adversarial inputs effectively. Our comprehensive evaluations on both large and small image recognition tasks confirm that the Student models with our defence of only 5 differentiators are immune to over 90% of the adversarial inputs with an accuracy loss of less than 10%. Our comparison also demonstrates that our design outperforms prior problematic defences.
Bang Wu 0004, Shuo Wang 0012, Xingliang Yuan, Cong Wang 0001, Carsten Rudolph, Xiangwen Yang
IEEE Trans. Dependable Secur. Comput.1
2022 Model Extraction Attacks on Graph Neural Networks: Taxonomy and Realisation
abstract
Machine learning models are shown to face a severe threat from Model Extraction Attacks, where a well-trained private model owned by a service provider can be stolen by an attacker pretending as a client. Unfortunately, prior works focus on the models trained over the Euclidean space, e.g., images and texts, while how to extract a GNN model that contains a graph structure and node features is yet to be explored. In this paper, for the first time, we comprehensively investigate and develop model extraction attacks against GNN models. We first systematically formalise the threat modelling in the context of GNN model extraction and classify the adversarial threats into seven categories by considering different background knowledge of the attacker, e.g., attributes and/or neighbour connections of the nodes obtained by the attacker. Then we present detailed methods which utilise the accessible knowledge in each threat to implement the attacks. By evaluating over three real-world datasets, our attacks are shown to extract duplicated models effectively, i.e., 84% - 89% of the inputs in the target domain have the same output predictions as the victim model.
Bang Wu 0004, Xiangwen Yang, Shirui Pan, Xingliang Yuan
AsiaCCS1
2022 Leia: A Lightweight Cryptographic Neural Network Inference System at the Edge
abstract
The advances in machine learning have revealed its great potential for emerging mobile applications such as face recognition and voice assistant. Models trained via a Neural Network (NN) can offer accurate and efficient inference services for mobile users. Unfortunately, the current deployment of such service encounters privacy concerns. Directly offloading the model to the mobile device violates model privacy of the model owner, while feeding user input to the service compromises user privacy. To address this issue, we propose Leia, a lightweight cryptographic NN inference system at the edge. Leia is designed from two mobile-friendly perspectives. First, it leverages the paradigm of edge computing wherein the inference procedure keeps the model closer to the mobile user to foster low latency service. Specifically, Leia’s architecture consists of two non-colluding edge services to obliviously perform NN inference on the encoded user data and model. Second, Leia’s realization makes the judicious use of potentially constrained computational and communication resources in edge devices. We adapt the Binarized Neural Network (BNN), a trending flavor of NN with low inference overhead, and purely choose the lightweight secret sharing techniques to realize secure blocks of BNN. We implement Leia and deploy it on Raspberry Pi. Empirical evaluations on benchmark and medical datasets via various models demonstrate the practicality of Leia.
Xiaoning Liu 0002, Bang Wu 0004, Xingliang Yuan, Xun Yi
IEEE Trans. Inf. Forensics Secur.2
2021 Towards Extracting Graph Neural Network Models via Prediction Queries (Student Abstract)
abstract
Graph data has been widely used to represent data from various domain, e.g., social networks, recommendation system. With great power, the GNN models, usually as valuable properties of their owners, also become attractive targets of the adversary who covets to steal them. While existing works show that simple deep neural networks can be reproduced by so-called Model Extraction Attacks, how to extract a GNN model has not been explored. In this paper, we exploit the threat of model extraction attacks against GNN models. Unlike ordinary attacks which obtain model information via only the input-output query pairs, we utilize both the node queries and the graph structure to extract the GNNs. Furthermore, we consider the stealthiness of the attack and propose to generate legitimate queries so the extraction can be applied discreetly. We implement our attack by leveraging the responses of these queries, as well as other accessible knowledge, e.g., neighbor connectives of the queried nodes. By evaluating over three real-world datasets, our attack is shown to effectively produce a surrogate model with more than 80% equivalent predictions as the target model.
Bang Wu 0004, Shirui Pan, Xingliang Yuan
AAAI1
2021 Projective Ranking: A Transferable Evasion Attack Method on Graph Neural Networks
abstract
Graph Neural Networks (GNNs) have emerged as a series of effective learning methods for graph-related tasks. However, GNNs are shown vulnerable to adversarial attacks, where attackers can fool GNNs into making wrong predictions on adversarial samples with well-designed perturbations. Specifically, we observe that the current evasion attacks suffer from two limitations: (1) the attack strategy based on the reinforcement learning method might not be transferable when the attack budget changes; (2) the greedy mechanism in the vanilla gradient-based method ignores the long-term benefits of each perturbation operation. In this paper, we propose a new attack method named projective ranking to overcome the above limitations. Our idea is to learn a powerful attack strategy considering the long-term benefits of perturbations, then adjust it as little as possible to generate adversarial samples under different budgets. We further employ mutual information to measure the long-term benefits of each perturbation and rank them accordingly, so the learned attack strategy has better attack performance. Our method dramatically reduces the adaptation cost of learning a new attack strategy by projecting the attack strategy when the attack budget changes. Our preliminary evaluation results in synthesized and real-world datasets demonstrate that our method owns powerful attack performance and effective transferability.
He Zhang 0012, Bang Wu 0004, Xiangwen Yang, Chuan Zhou 0001, Shuo Wang 0012, Xingliang Yuan, Shirui Pan
CIKM2
2021 Adapting Membership Inference Attacks to GNN for Graph Classification: Approaches and Implications
abstract
In light of the wide application of Graph Neural Networks (GNNs), Membership Inference Attack (MIA) against GNNs raises severe privacy concerns, where training data can be leaked from trained GNN models. However, prior studies focus on inferring the membership of only the components in a graph, e.g., an individual node or edge. In this paper, we take the first step in MIA against GNNs for graph-level classification. Our objective is to infer whether a graph sample has been used for training a GNN model. We present and implement two types of attacks, i.e., training-based attacks and threshold-based attacks from different adversarial capabilities. We perform comprehensive experiments to evaluate our attacks in seven real-world datasets using five representative GNN models. Both our attacks are shown effective and can achieve high performance, i.e., reaching over 0.7 attack F1 scores in most cases1. Our findings also confirm that, unlike the node-level classifier, MIAs on graph-level classification tasks are more co-related with the overfitting level of GNNs rather than the statistic property of their training graphs.
Bang Wu 0004, Xiangwen Yang, Shirui Pan, Xingliang Yuan
ICDM1