
Jiaxing Zhou, Di Wu · Discover Artificial Intelligence 2026 · 2026
DOI: 10.1007/s44163-026-02198-9
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Scan-to-order systems route user data through merchants, payment gateways, cloud services, and third-party analytics providers in a single transaction flow. This multi-entity architecture makes privacy leakage difficult to trace: a sensitive record may travel five or six hops before reaching an unauthorised party, and the intermediate steps look identical to legitimate business traffic. Existing rule-based provenance tools and static graph models break down at this scale because they treat every data flow as equally important and cannot attribute causal responsibility to specific edges or nodes. We address this gap with DS-GNN, a sensitivity-aware graph neural network that encodes privacy risk directly into the message-passing computation of a dynamic heterogeneous interaction graph. Instead of post-hoc reweighting, DS-GNN learns to amplify high-sensitivity data paths during aggregation and suppress low-risk noise, which preserves discriminative signals across long propagation chains. A counterfactual inference module then answers “what changes if we remove this edge?” and quantifies each component’s causal contribution to the predicted leakage risk. To support reproducible evaluation, we release SynOrder-Leak, a synthetic dataset with 50 dynamic graph snapshots, controlled leakage events, and per-edge sensitivity labels drawn from three regulatory categories. Experiments show that DS-GNN reaches 0.72 Precision@10 and 0.61 MRR, outperforming the best baseline by 8 and 8 percentage points respectively, with the margin widening further on paths exceeding five hops.
No comments yet — start the discussion below.