























Abstract:Federated Graph Neural Networks (FedGNNs) facilitate collaborative learning across multiple clients with graph-structured data while preserving user privacy. However, emerging research indicates that within this setting, shared model updates, particularly gradients, can unintentionally leak sensitive information of local users. Numerous privacy inference attacks have been explored in traditional federated learning and extended to graph settings, but the problem of label distribution inference in FedGNNs remains largely underexplored. In this work, we introduce Fed-Listing (Federated Label Distribution Inference in GNNs), a novel gradient-based attack designed to infer the private label statistics of target clients in FedGNNs without access to raw data or node features. Fed-Listing only leverages the final-layer gradients exchanged during training to uncover statistical patterns that reveal class proportions in a stealthy manner. Extensive experiments on four benchmark datasets and three GNN architectures show that Fed-Listing significantly outperforms existing baselines, including random guessing and Decaf, even under challenging non-i.i.d. scenarios. Moreover, existing defense mechanisms can barely reduce the attack performance of Fed-Listing, unless the model's utility is severely degraded. The code implementation and Supplementary materials are available here: this https URL.
| Comments: | 9 pages, 3 figures, and 4 tables |
| Subjects: | Machine Learning (cs.LG) |
| Cite as: | arXiv:2602.00407 [cs.LG] |
| (or arXiv:2602.00407v2 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2602.00407 arXiv-issued DOI via DataCite |
From: Suprim Nakarmi [view email]
[v1]
Fri, 30 Jan 2026 23:51:49 UTC (8,431 KB)
[v2]
Wed, 6 May 2026 23:56:25 UTC (1,699 KB)
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。