GRASP: Differentially Private Graph Reconstruction Defense with Structured Perturbation
Zhiyu Guo, Yang Liu, Xiang Ao, Qing He
Abstract
In this paper, we reveal that existing Differentially Private Graph Neural Networks (DP-GNNs) are not effective against Graph Reconstruction Attack (GRA). We further attribute the ineffectiveness of existing DP-GNNs against GRA to their unstructured perturbation mechanism, which only induces unidirectional shift in the embedding similarity distribution. Specifically, this perturbation mechanism tends to decrease the embedding similarity of all node pairs without significantly disrupting the relative ranking, thus allowing GRA to still reconstruct the original graph structure by leveraging the relative ranking of similarities. To address this, we propose a novel Differentially Private Graph Neural Network based on Structured Perturbation (GRASP). Specifically, we observe that independent noise tends to decrease the embedding similarity, while identical noise tends to increase it. By integrating these two types of noise using a Bernoulli technique, we introduce a simple yet effective structured perturbation mechanism, which promotes bidirectional shift in the embedding similarity distribution, thereby effectively disrupting the relative ranking and defending against GRA. Extensive experiments on eight benchmark datasets demonstrate that GRASP effectively defends against GRA. Furthermore, GRASP achieves a superior privacy-utility trade-off compared to existing graph structure protection methods. The implementation of GRASP is available at https://github.com/ZhiyuZone/GRASP/.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 291bf0ec-6e35-4341-8b2f-e331c3a1bf87Cited by top-tier papers2
- STRAP: Spatio-Temporal Pattern Retrieval for Out-of-Distribution GeneralizationHaoyu Zhang, Wentao Zhang, Hao Miao, Xinke Jiang et al.NeurIPS 2025 · 12 citations
- A2GBD: Attack-Agnostic Graph Backdoor DefenseChenxu Du, Yang Liu, Xingtong Yu, Zhuoer Xu et al.WWW 2026
Builds on20
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Pick and Choose: A GNN-based Imbalanced Learning Approach for Fraud DetectionYang Liu, Xiang Ao, Zidi Qin, Jianfeng Chi et al.WWW 2021 · 527 citations
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
- LINKTELLER: Recovering Private Edges from Graph Neural Networks via Influence AnalysisFan Wu, Yunhui Long, Ce Zhang, Bo LiS&P 2022 · 125 citations
Related papers
- GAP: Differentially Private Graph Neural Networks with Aggregation PerturbationSina Sajadmanesh, Ali Shahin Shamsabadi, Aurélien Bellet, Daniel Gatica-PerezUSENIX Security 2023
- Safeguarding Graph Neural Networks against Topology Inference AttacksJie Fu, Yuan Hong, Zhili Chen, Wendy Hui WangCCS 2025
- On Strengthening and Defending Graph Reconstruction Attack with Markov Chain ApproximationZhanke Zhou, Chenyu Zhou, Xuan Li, Jiangchao Yao et al.ICML 2023 · 25 citations
- On provable privacy vulnerabilities of graph representationsRuofan Wu, Guanhua Fang, Mingyang Zhang, Qiying Pan et al.NeurIPS 2024 · 3 citations
- GRID: Protecting Training Graph from Link Stealing Attacks on GNN ModelsJiadong Lou, Xu Yuan, Rui Zhang, Xingliang Yuan et al.S&P 2025
