USENIX Security2026Top-tier venue
CTA: Clip-then-Aggregate, a Differentially Private Learning Algorithm for Graph Data
Jianxin Wei
Abstract
Graph learning has become a fundamental tool for modeling relational data in applications such as social networks and recommender systems, yet it often involves individuals' private features or interactions. Differential privacy (DP) provides a rigorous framework for protecting sensitive data, but its application to graph learning is challenging due to complex inter-node dependencies induced by message aggregation. Despite this broad influence, the per-neighbor impact of a node is typically small. Nevertheless, most existing private graph learning methods are built upon the DP-SGD framework, whose reliance on global gradient clipping prevents the precise capture of these influences and overestimates the true gradient sensitivity.
To address these challenges, we propose CTA, a differentially private graph learning algorithm that enables end-to-end training while perturbing only model gradients with tightly characterized sensitivity. CTA adopts a clip-then-aggregate design in both the forward and backward passes of model training. In the forward pass, CTA clips node embeddings before aggregation. Crucially, in the backward pass, instead of clipping each gradient as a whole, CTA separately clips and bounds two gradient components and then aggregates them to form the final model gradients. This design allows CTA to capture fine-grained gradient variations induced by graph aggregation and derive tighter gradient sensitivity bounds. Extensive experiments on real-world datasets demonstrate that CTA consistently outperforms existing private graph learning methods across a wide range of settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on14
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Simple Spectral Graph ConvolutionHao Zhu, Piotr KoniuszICLR 2021 · 352 citations
- Combining Label Propagation and Simple Models out-performs Graph Neural NetworksQian Huang, Horace He, Abhay Singh, Ser-Nam Lim et al.ICLR 2021 · 322 citations
- Stealing Links from Graph Neural NetworksXinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong et al.USENIX Security 2021 · 226 citations
Related papers
- SaGD: A Node-Level Differentially Private Graph Learning Framework with Sensitivity-Aware Gradient DescentJianxin Wei, Ergute Bao, Xiaokui Xiao, Ting YuWWW 2026
- GAP: Differentially Private Graph Neural Networks with Aggregation PerturbationSina Sajadmanesh, Ali Shahin Shamsabadi, Aurélien Bellet, Daniel Gatica-PerezUSENIX Security 2023
- Differentially Private Graph Learning via Sensitivity-Bounded Personalized PageRankAlessandro Epasto, Vahab Mirrokni, Bryan Perozzi, Anton Tsitsulin et al.NeurIPS 2022 · 27 citations
- Locally Private Graph Neural NetworksSina Sajadmanesh, Daniel Gatica-PerezCCS 2021 · 124 citations
- Differentially Private Relational Learning with Entity-level Privacy GuaranteesYinan Huang, Haoteng Yin, Eli Chien, Rongzhe Wei et al.NeurIPS 2025
