Pith. sign in

REVIEW 2 cited by

Degree-Preserving Randomized Response for Graph Neural Networks under Local Differential Privacy

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2202.10209 v6 pith:W4NLO6OB submitted 2022-02-21 cs.CR cs.LG

classification cs.CRcs.LG
keywords graphprivacydprruseralgorithmedgesaccuracydatasets
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Differentially private GNNs (Graph Neural Networks) have been recently studied to provide high accuracy in various tasks on graph data while strongly protecting user privacy. In particular, a recent study proposes an algorithm to protect each user's feature vector in an attributed graph, which includes feature vectors along with node IDs and edges, with LDP (Local Differential Privacy), a strong privacy notion without a trusted third party. However, this algorithm does not protect edges (friendships) in a social graph, hence cannot protect user privacy in unattributed graphs, which include only node IDs and edges. How to provide strong privacy with high accuracy in unattributed graphs remains open. In this paper, we propose a novel LDP algorithm called the DPRR (Degree-Preserving Randomized Response) to provide LDP for edges in GNNs. Our DPRR preserves each user's degree hence a graph structure while providing edge LDP. Technically, our DPRR uses Warner's RR (Randomized Response) and strategic edge sampling, where each user's sampling probability is automatically tuned using the Laplacian mechanism to preserve the degree information under edge LDP. We also propose a privacy budget allocation method to make the noise in both Warner's RR and the Laplacian mechanism small. We focus on graph classification as a task of GNNs and evaluate the DPRR using three social graph datasets. Our experimental results show that the DPRR significantly outperforms three baselines and provides accuracy close to a non-private algorithm in all datasets with a reasonable privacy budget, e.g., epsilon=1. Finally, we introduce data poisoning attacks to our DPRR and a defense against the attacks. We evaluate them using the three social graph datasets and discuss the experimental results.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Practical and Accurate Local Edge Differentially Private Graph Algorithms

    cs.DS 2025-06 reject novelty 6.0 of 10

    New LEDP k-core and triangle-counting algorithms replace edge-count error bounds with degree- and degeneracy-based bounds, and are evaluated in a distributed simulation with reported accuracy improvements.

  2. EdgeRefine: Privacy-Utility Balance for Graphs via Jaccard Sampling under Edge Differential Privacy

    cs.LG 2026-07 reject novelty 5.0 of 10

    EdgeRefine denoises randomized-response graphs by ranking edges with Jaccard similarity and sampling a fixed quota from observed and non-observed edges, reporting near-noise-free GNN accuracy under edge differential privacy.

Pith tools