Link inference attack on privacy-preserving knowledge graphs

Bouguerra, Emna; Harrouche, Ibtissam; Alborch, Ferran; Önen, Melek
PSD 2026, Privacy in Statistical Databases Conference, 30 September-2 October 2026, Cádiz, Spain

Knowledge Graphs (KGs) are widely used to store and share structured information across sensitive domains such as healthcare, finance, and social networks. A common privacy practice is to delete sensitive relations before publishing the graph, under the assumption that removing edges is sufficient to prevent their recovery. In this paper, we challenge this assumption and show that even when a relation is fully or partially hidden, its existence leaves structural traces in the public graph that can be exploited to recover it with high accuracy. To this end, we propose a link inference attack that operates on the topology of the public graph, and evaluate it under two privacy scenarios that differ in how the adversary exploits the knowledge available to him. In the first setting where the adversary exploits all topological information, the attack achieves near-perfect discrimination (AP = 0.949, ROC-AUC = 0.999), while in the more realistic one where the adversary makes use of some semantic information, it recovers up to 74% of hidden edges. Building on these results, we further conduct a structural analysis to identify which topological properties of the graph drive the attack success, revealing that privacy risk is not uniform across entities and that certain structural patterns make specific relations significantly more vulnerable to inference than others.


Type:
Conference
City:
Cádiz
Date:
2026-09-30
Department:
Digital Security
Eurecom Ref:
8920
Copyright:
© Springer. Personal use of this material is permitted. The definitive version of this paper was published in PSD 2026, Privacy in Statistical Databases Conference, 30 September-2 October 2026, Cádiz, Spain and is available at :

PERMALINK : https://www.eurecom.fr/publication/8920