arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

隐私归属何处:图上私有反事实解释的放置诊断与认证选择

Where Privacy Belongs: Placement Diagnosis and Certified Selection for Private Counterfactual Explanations on Graphs

Yuxiang Yao, Zijun Zhao

arXiv 2609.37667首次发表:更新:

发表机构

China Life Insurance Company Ltd.; Beijing Institute of Technology(中国人寿保险股份有限公司; 北京理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对图反事实解释的隐私泄露问题,提出PrivCFS方法,通过基于构造的认证和公共候选宇宙选择,实现纯ε-差分隐私,显著降低泄露风险,并具有可迁移性。

AI 中文摘要

图神经网络(GNNs)的反事实解释寻找翻转节点预测的最小干预——但计算该解释需要读取敏感图结构,而发布解释则会泄露该结构。现有的两种放置方式均告失败。在解释前对图进行私有化处理,会在恰好需要补救的边界节点上破坏目标,制造虚假翻转,即翻转私有化图但未翻转真实图。在干净图上解释并扰动已发布的解释则难以通过认证:对标准启发式方法的重新审计显示,其隐含的完全发布预算在Cora上为573至753,在CiteSeer上为256——超出其宣传预算数个数量级——且最坏情况下的单条目泄露的AUC达到1.0。我们提出PrivCFS,用基于构造的认证取代基于优化的认证:在固定的、与数据无关的候选宇宙上进行反事实选择——边干预来自公共先验图,特征干预来自公共模式——其无操作语义使相邻图具有相同的输出支持。通过指数机制发布的有效性门控、裁剪效用,其全局敏感度Δu≤1,为完整发布对象提供纯ε-差分隐私,并可跨查询组合——据我们所知,这是图上首个此类保证。隐私噪声是最廉价的阶段:在ε=8时,发布在补救人群上保留了其支持受限非私有最优值的94%至97%,在一般人群上保留了83%至95%;最优边推断审计平均AUC达到0.50,最差配对为0.59,而启发式方法的最差条目为1.0;并可迁移至15K节点图,有效率为0.96。主导成本是公共披露中可测量的单调代价,可在花费任何预算前从一张表中读出——将解释隐私从会计风险转变为可购买的决策。

英文摘要

Counterfactual explanations for graph neural networks (GNNs) find the minimal intervention that flips a node's prediction--but computing one requires reading sensitive graph structure, and releasing it discloses that structure. Both existing placements fail. Privatizing the graph before explaining corrupts the target on exactly the borderline nodes needing recourse, manufacturing spurious flips that flip the privatized graph but not the true one. Explaining on the clean graph and perturbing the released explanation resists certification: re-auditing the standard heuristic shows an implied full-release budget of 573--753 on Cora and 256 on CiteSeer--orders of magnitude beyond its advertised budget--with worst-case single-entry leakage at AUC 1.0. We propose PrivCFS, which replaces certification-by-optimization with certification-by-construction: counterfactual selection over a fixed, data-independent candidate universe--edge interventions from a public prior graph, feature interventions from a public schema--whose no-op semantics give neighboring graphs the same output support. A validity-gated, clipped utility of global sensitivity $Δu \le 1$ released through the exponential mechanism gives pure $\varepsilon$-DP for the complete released object, composable over queries--to our knowledge the first such guarantee on graphs. Privacy noise is the cheapest stage: at $\varepsilon$=8 the release retains 94--97% of its support-restricted non-private optimum on the recourse population and 83--95% on the general one; the optimal edge-inference audit attains AUC 0.50 on average and 0.59 worst-pair, versus the heuristic's worst entry 1.0; and transfers to a 15K-node graph at 0.96 valid rate. The dominant cost is a measurable, monotone price in public disclosure, readable off one table before any budget is spent--turning explanation privacy from an accounting risk into a purchasable decision.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑