Local Differential Privacy in Graph Neural Networks: a Reconstruction Approach

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Bhaila, Karuna, Huang, Wen, Wu, Yongkai, Wu, Xintao
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916347702673408
author Bhaila, Karuna
Huang, Wen
Wu, Yongkai
Wu, Xintao
author_facet Bhaila, Karuna
Huang, Wen
Wu, Yongkai
Wu, Xintao
contents Graph Neural Networks have achieved tremendous success in modeling complex graph data in a variety of applications. However, there are limited studies investigating privacy protection in GNNs. In this work, we propose a learning framework that can provide node privacy at the user level, while incurring low utility loss. We focus on a decentralized notion of Differential Privacy, namely Local Differential Privacy, and apply randomization mechanisms to perturb both feature and label data at the node level before the data is collected by a central server for model training. Specifically, we investigate the application of randomization mechanisms in high-dimensional feature settings and propose an LDP protocol with strict privacy guarantees. Based on frequency estimation in statistical analysis of randomized data, we develop reconstruction methods to approximate features and labels from perturbed data. We also formulate this learning framework to utilize frequency estimates of graph clusters to supervise the training procedure at a sub-graph level. Extensive experiments on real-world and semi-synthetic datasets demonstrate the validity of our proposed model.
format Preprint
id arxiv_https___arxiv_org_abs_2309_08569
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Local Differential Privacy in Graph Neural Networks: a Reconstruction Approach
Bhaila, Karuna
Huang, Wen
Wu, Yongkai
Wu, Xintao
Machine Learning
Cryptography and Security
Graph Neural Networks have achieved tremendous success in modeling complex graph data in a variety of applications. However, there are limited studies investigating privacy protection in GNNs. In this work, we propose a learning framework that can provide node privacy at the user level, while incurring low utility loss. We focus on a decentralized notion of Differential Privacy, namely Local Differential Privacy, and apply randomization mechanisms to perturb both feature and label data at the node level before the data is collected by a central server for model training. Specifically, we investigate the application of randomization mechanisms in high-dimensional feature settings and propose an LDP protocol with strict privacy guarantees. Based on frequency estimation in statistical analysis of randomized data, we develop reconstruction methods to approximate features and labels from perturbed data. We also formulate this learning framework to utilize frequency estimates of graph clusters to supervise the training procedure at a sub-graph level. Extensive experiments on real-world and semi-synthetic datasets demonstrate the validity of our proposed model.
title Local Differential Privacy in Graph Neural Networks: a Reconstruction Approach
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2309.08569