PriDyG:结合大语言模型与图神经网络的隐私保护动态图推理
PriDyG: Privacy-preserving Dynamic Graph Inference with LLM-GNN Collaboration
浏览论文内容
中文总结 AI 辅助
PriDyG是结合GNN结构学习与LLM语义推理的隐私保护动态图推理框架,可在边级差分隐私约束下,在节点分类等任务中降低累计隐私开销并保持良好效用。
中文摘要 AI 辅助
针对关系数据的图推理可能会暴露敏感边信息,在动态图中这一风险更为严重,因为模型的重复更新会导致隐私损失不断累积。我们提出了边级差分隐私动态图推理(EDG)问题,并设计了PriDyG这一隐私推理框架,该框架将基于图神经网络(GNN)的结构学习与基于大语言模型(LLM)的语义推理相结合。PriDyG引入了增量式私有多跳聚合机制,该机制会缓存新到达的边,且每条边仅被处理一次;通过并行组合,总隐私开销与单次静态发布的开销相当,与模型更新的数量或调度无关。与几何衰减预算分配方式相比,增量聚合可避免噪声呈指数级增长,同时保留精确的单跳信号和至少一半的两跳信息传递。PriDyG还通过仅基于节点文本的LLM预测来补充私有化的GNN输出,不会产生额外的边级隐私开销。在四个用于节点分类和链接预测的基准数据集上的实验表明,在相同隐私预算下,PriDyG的性能始终优于几何衰减基线,且其效用与逐更新重新训练的朴素方法相当,同时可将累计隐私开销降低多达三个数量级。
英文摘要
Graph inference over relational data can expose sensitive edge information, and this risk becomes more severe in dynamic graphs, where repeated model updates cause privacy loss to accumulate. We formulate Edge-level Differentially Private Dynamic Graph Inference (EDG) and propose PriDyG, a private inference framework that combines GNN-based structural learning with LLM-based semantic reasoning. PriDyG introduces incremental private multi-hop aggregation, which buffers newly arrived edges and processes each edge exactly once. By parallel composition, the total privacy cost equals that of a single static release, independent of the number or schedule of model updates. Compared with geometrically decaying budget allocation, incremental aggregation avoids exponentially increasing noise while preserving exact one-hop signals and at least half of two-hop information transfers. PriDyG further complements privatized GNN outputs with LLM predictions derived solely from node text, incurring no additional edge-level privacy cost. Experiments on four benchmarks for node classification and link prediction show that PriDyG consistently outperforms geometrically decaying baselines under the same privacy budget and matches the utility of naive per-update retraining while reducing cumulative privacy cost by up to three orders of magnitude.
发表机构
- Emory University(埃默里大学)
机构由 AI 辅助整理,请以论文原文为准。