#machine learning
May 2026
Can Subgraph Explanations Be Weaponized to Steal Graph Neural Networks?
This work presents the first model extraction attack specifically designed for graph classification under strict black-box constraints, which uses model explanation outputs to guide Monte Carlo edge sensitivity estimation toward decision boundaries, with Hoeffding concentration guarantees on estimation accuracy.
Ojas Nimase, Jia-Te Li, Yuelei Zhao et al.
· arXiv.org · 0 citations