Preserving Node-level Privacy in Graph Neural Networks
Zihang Xiang, Tianhao Wang, Di Wang
Abstract
Differential privacy (DP) has seen immense applications in learning on tabular, image, and sequential data where instance-level privacy is concerned. In learning on graphs, contrastingly, works on node-level privacy are highly sparse. Challenges arise as existing DP protocols hardly apply to the message-passing mechanism in Graph Neural Networks (GNNs).In this study, we propose a solution that specifically addresses the issue of node-level privacy. Our protocol consists of two main components: 1) a sampling routine called Heter-Poisson, which employs a specialized node sampling strategy and a series of tailored operations to generate a batch of sub-graphs with desired properties, and 2) a randomization routine that utilizes symmetric multivariate Laplace (SML) noise instead of the commonly used Gaussian noise. Our privacy accounting shows this particular combination provides a non-trivial privacy guarantee. In addition, our protocol enables GNN learning with good performance, as demonstrated by experiments on five real-world datasets; compared with existing baselines, our method shows significant advantages, especially in the high privacy regime. Experimentally, we also 1) perform membership inference attacks against our protocol and 2) apply privacy audit techniques to confirm our protocol’s privacy integrity.In the sequel, we present a study on a seemingly appealing approach [33] (USENIX’23) that protects node-level privacy via differentially private node/instance embeddings. Unfortunately, such work has fundamental privacy flaws, which are identified through a thorough case study. More importantly, we prove an impossibility result of achieving both (strong) privacy and (acceptable) utility through private instance embedding. The implication is that such an approach has intrinsic utility barriers when enforcing differential privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d2fb1185-b522-4b21-af01-4ef5761cffa0Cited by top-tier papers16
- Unified Mechanism-Specific Amplification by Subsampling and Group Privacy AmplificationJan Schuchardt, Mihail Stoian, Arthur Kosmala, Stephan GünnemannNeurIPS 2024 · 8 citations
- Practical and Accurate Local Edge Differentially Private Graph AlgorithmsPranay Mundra, Charalampos Papamanthou, Julian Shun, Quanquan C. LiuVLDB 2025 · 3 citations
- PrivDPR: Synthetic Graph Publishing with Deep PageRank under Differential PrivacySen Zhang, Haibo Hu, Qingqing Ye, Jianliang XuKDD 2025 · 3 citations
- CoLA: A Choice Leakage Attack Framework to Expose Privacy Risks in Subset TrainingQi Li, Cheng-Long Wang, Yinzhi Cao, Di WangACL 2026 · 2 citations
- AdvSGM: Differentially Private Graph Learning via Adversarial Skip-Gram ModelSen Zhang, Qingqing Ye, Haibo Hu, Jianliang XuICDE 2025 · 2 citations
Builds on14
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Differentially Private Fine-tuning of Language ModelsDa Yu, Saurabh Naik, Arturs Backurs, Sivakanth Gopi et al.ICLR 2022 · 494 citations
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot et al.S&P 2021 · 288 citations
Related papers
- Devil's Hand: Data Poisoning Attacks to Locally Private Graph Learning ProtocolsLongzhu He, Chaozhuo Li, Peng Tang, Li Sun et al.KDD 2026
- GAP: Differentially Private Graph Neural Networks with Aggregation PerturbationSina Sajadmanesh, Ali Shahin Shamsabadi, Aurélien Bellet, Daniel Gatica-PerezUSENIX Security 2023
- Differentially Private Decoupled Graph Convolutions for Multigranular Topology ProtectionEli Chien, Wei-Ning Chen, Chao Pan, Pan Li et al.NeurIPS 2023 · 33 citations
- The Devil Within, The Cure Without: Securing Locally Private Graph Learning under PoisoningLongzhu He, Peng Tang, Li Sun, Sen SuWWW 2026
- Achieving Personalized Privacy-Preserving Graph Neural Network via Topology AwarenessDian Lei, Zijun Song, Yanli Yuan, Chunhai Li et al.WWW 2025 · 6 citations
