信任但验证:抗投毒的本地私有图学习协议
Trust-But-Verify: Poisoning-Resilient Locally Private Graph Learning Protocols
浏览论文内容
中文总结 AI 辅助
针对本地私有图学习易受数据投毒攻击的问题,提出基于信任但验证范式的VERITAS协议,通过验证列表和双边证明修剪恶意节点,实验证明其有效提升鲁棒性。
中文摘要 AI 辅助
基于本地差分隐私(LDP),本地私有图学习协议已成为去中心化图学习的重要范式,在隐私保护和学习效用之间取得平衡。在此类协议下,每个用户在传输前本地扰动其节点特征和邻接信息,确保在不离开设备的情况下提供正式的隐私保证。然而,本质上开放参与的特性使这些协议极易受到数据投毒攻击,攻击者注入精心设计的恶意节点以破坏邻域聚合并降低下游效用。尽管此威胁严重,但该设置下的有效防御仍 largely 未被探索。本文中,我们提出 VERITAS,一种基于信任但验证范式的抗投毒本地私有图学习协议。通过引入编码分级对等信任级别的验证列表,VERITAS 在用户侧联合私有化节点特征和图结构,同时在服务器侧利用双边证明不对称性来识别和修剪恶意节点。具体而言,VERITAS 包含四个协同阶段:(1)本地数据扰动,(2)证明驱动的恶意节点修剪,(3)通过双重去噪恢复效用,以及(4)鲁棒私有图学习。在四个真实世界基准数据集上跨多种 LDP 机制和 GNN 架构的大量实验表明,VERITAS 有效防御数据投毒攻击,并在严格隐私保证下显著提高下游图学习效用。
英文摘要
Built upon local differential privacy (LDP), locally private graph learning protocols have emerged as an important paradigm for decentralized graph learning, balancing privacy protection and learning utility. Under such protocols, each user locally perturbs their node features and adjacency information before transmission, ensuring formal privacy guarantees without original data leaving the device. However, the inherently open participation nature renders these protocols critically vulnerable to data poisoning attacks, where adversaries inject carefully crafted malicious nodes to corrupt neighborhood aggregation and degrade downstream utility. Despite the severity of this threat, effective defenses in this setting remain largely unexplored. In this paper, we propose VERITAS, a poisoning-resilient locally private graph learning protocol built on a trust-but-verify paradigm. By introducing a verification list encoding graded peer trust levels, VERITAS jointly privatizes node features and graph structure on the user side, while exploiting bilateral attestation asymmetry on the server side to identify and prune malicious nodes. Concretely, VERITAS comprises four synergistic stages: (1) local data perturbation, (2) attestation-driven malicious node pruning, (3) utility restoration via dual denoising, and (4) robust private graph learning. Extensive experiments on four real-world benchmark datasets across multiple LDP mechanisms and GNN architectures demonstrate that VERITAS effectively defends against data poisoning attacks and significantly improves downstream graph learning utility under rigorous privacy guarantees.
发表机构
- Beijing University of Posts and Telecommunications(北京邮电大学)
- Beihang University(北京航空航天大学)
- The Hong Kong University of Science and Technology(香港科技大学)
- Chongqing University of Posts and Telecommunications(重庆邮电大学)
机构由 AI 辅助整理,请以论文原文为准。