Mitigating Privacy Risks in Graph Condensation from a Hyperbolic Geometry Perspective
Yuecen Wei, Liu Yang, Beining Yang, Qingyun Sun, Hao Peng, Tianyu Wo, Chunming Hu, Xingcheng Fu
Abstract
Graph condensation reduces large graphs into smaller synthetic ones for efficient training and potential privacy protection. While existing studies demonstrate graph condensation's resilience against membership inference attacks (MIAs), key questions remain unanswered: Can the common MIAs' accuracy truly represent the privacy-preserving capabilities of graph condensation? Does it remain robust against more powerful adversaries? And what are the underlying reasons for its performance? This paper investigates the privacy risks of gradient-matching-based condensation via tailored MIAs. We reveal that existing methods often face a trade-off between performance and generalization, where increasing node diversity can unintentionally amplify privacy leakage. Moreover, existing methods either homogenize nodes of the same class to maximize task-specific performance at the cost of generalization or enhance node diversity by efficiently incorporating additional information to improve model generalization, but such diversity inevitably expands the attack reasoning due to increased data disparity. To better balance performance and privacy, we propose a novel graph condensation framework (HDGC) that investigates privacy issues in graph condensation from a hyperbolic geometric perspective. Specifically, we first leverage hyperbolic geometric properties to constrain gradient-matching directions ( HGGM ), thereby obtaining latent hierarchical semantic guidance when learning the synthetic graph's topology. This mechanism measures node importance in hyperbolic space to enhance model generalization. Subsequently, we introduce hyperbolic adaptive differentially private noise during gradient matching ( HADP ). This perturbation intelligently adjusts noise influence based on local gradient importance and global geometric radius, ensuring diversity among same-class nodes while preserving differential privacy. Finally, relying on the post-processing principle of differential privacy, we incorporate distributionally robust optimization to mitigate excessive utility degradation caused by noise injection without compromising privacy guarantees. Experiments and analyses demonstrate that HDGC effectively captures geometric space characteristics, achieves superior performance, and provides a great foundation for defending inference attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8c62ccd8-92bd-46fd-9c01-b752fcb84e8bRelated papers
- Federated Graph Condensation with Information Bottleneck PrinciplesBo Yan, Sihao He, Cheng Yang, Shang Liu et al.AAAI 2025 · 11 citations
- Robust Graph Condensation via Classification Complexity MitigationJiayi Luo, Qingyun Sun, Beining Yang, Haonan Yuan et al.NeurIPS 2025
- Poincaré Differential Privacy for Hierarchy-Aware Graph EmbeddingYuecen Wei, Haonan Yuan, Xingcheng Fu, Qingyun Sun et al.AAAI 2024 · 15 citations
- Privacy for Free: How does Dataset Condensation Help Privacy?Tian Dong, Bo Zhao, Lingjuan LyuICML 2022 · 154 citations
- DP-GenG: Differentially Private Dataset Distillation Guided by DP-Generated DataShuo Shi, Jinghuai Zhang, Shijie Jiang, Chunyi Zhou et al.AAAI 2026
