arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

EdgeRefine:基于边差分隐私下的杰卡德采样实现图的隐私-效用平衡

EdgeRefine: Privacy-Utility Balance for Graphs via Jaccard Sampling under Edge Differential Privacy

Wenxiu Ding, Muzhi Liu, Zheng Yan, Mingjun Wang, Yifan Zhao, Qiao Liu

arXiv 2607.08659首次发表:更新:

发表机构

State Key Laboratory of Integrated Services Networks,School of Cyber Engineering, Xidian University; (西安电子科技大学网络与信息安全学院; 综合业务网理论及关键技术国家重点实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对图神经网络在隐私敏感领域应用难题,提出EdgeRefine框架,利用杰卡德采样和隐私预算确定边比例并采样,在跨数据集和架构上提升隐私-效用平衡,实验表明其准确率高且抗隐私泄露能力强。

AI 中文摘要

图神经网络在从图结构数据学习方面取得了显著成功,但在隐私敏感领域的应用仍存在困难,因为图结构可能泄露敏感链接信息。为满足边级差分隐私,常用方法是对图邻接矩阵所有元素注入噪声,然而更强的隐私需求更多噪声,会降低效用。本文提出EdgeRefine,一种通过自适应边细化改善隐私-效用权衡的局部差分隐私框架。它首先用杰卡德相似度估计边存在概率并对边排序以去除噪声边,用隐私预算确定真假边比例,按概率排名分别采样,并通过单独采样率控制边总数。实验表明,EdgeRefine在跨数据集和GNN架构上,准确率与无噪声基线相当,且显著优于其他隐私保护方法。在隐私预算ε = 2.5时,在GAT下的ACM数据集上,EdgeRefine比最先进基线提高节点分类准确率17.8%,在GCN下的Cora数据集上提高19.7%。在图分类中,与无噪声基线相比,平均准确率下降约5%。在图重建攻击下,EdgeRefine在所有隐私预算下保持相对绝对误差水平高于1,在Cora上平均为1.962,在AMAP上平均为1.472,显示出强大的抗隐私泄露能力。

英文摘要

Graph Neural Networks (GNNs) have shown considerable success in learning from graph-structured data, but their use in privacy-sensitive areas remains difficult because graph structure can leak sensitive link information. To satisfy edge-level differential privacy, a common approach is to inject noise into all elements of the graph's adjacency matrix, thereby obfuscating the existence of any single edge. However, stronger privacy requires more noise, and excessive noise reduces utility, making the privacy-utility balance a major barrier to practical privacy-preserving graph learning. To address this issue, we propose EdgeRefine, a local differential privacy framework that improves this trade-off through adaptive edge refinement. EdgeRefine first estimates edge-existence probabilities using Jaccard similarity and ranks edges for noisy edge removal. To ensure the sparsity and reliability of the final graph, it uses the privacy budget $ε$ to determine the ratio of true to false edges, samples them separately based on this probability ranking, and controls the total number of edges with a separate sampling rate $k$. Extensive experiments show that EdgeRefine achieves accuracy comparable to the noise-free baseline and substantially outperforms other privacy-preserving methods across datasets and GNN architectures. Under privacy budget $ε= 2.5$, EdgeRefine improves node classification accuracy over state-of-the-art baselines by 17.8\% on ACM under GAT and 19.7\% on Cora under GCN. In graph classification, it achieves an average accuracy degradation of around 5\% compared to the noise-free baseline. Under graph reconstruction attacks, EdgeRefine maintains relative absolute error levels above 1 across all privacy budgets, averaging 1.962 on Cora and 1.472 on AMAP, indicating strong resilience against privacy leakage.

Comments21 pages, 6 figures; full version of the ACM CCS 2026 paper, including complete appendices and extended experimental results

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑