Heterogeneous Randomized Response for Differential Privacy in Graph Neural Networks

Heterogeneous Randomized Response for Differential Privacy in Graph Neural Networks
复制标题

DOI:
10.1109/bigdata55660.2022.10020501
复制
发表时间:
2022-11
期刊:
2022 IEEE International Conference on Big Data (Big Data)
影响因子:
--
通讯作者:
Khang Tran;Phung Lai;Nhathai Phan;Issa M. Khalil;Yao Ma;Abdallah Khreishah;M. Thai;Xintao Wu
Khang Tran;Phung Lai;Nhathai Phan;Issa M. Khalil;Yao Ma;Abdallah Khreishah;M. Thai;Xintao Wu
中科院分区:
其他
文献类型:
--
作者:
Khang Tran;Phung Lai;Nhathai Phan;Issa M. Khalil;Yao Ma;Abdallah Khreishah;M. Thai;Xintao Wu

文献摘要

相似文献

图神经网络(GNN)容易受到隐私推理攻击(皮亚斯),因为它们能够从图数据中的节点之间的特征和边学习联合表示。为了防止GNN中的隐私泄漏,我们提出了一种新的异构随机响应(HeteroRR)机制,以保护节点的特征和边缘在差分隐私(DP)保证下免受皮亚斯的攻击,而不会在训练GNN时产生不必要的数据和模型效用成本。我们的想法是平衡的重要性和敏感性的节点的特征和边缘在重新分配的隐私预算,因为一些功能和边缘比其他更敏感或重要的模型效用。因此,我们在节点的特征和边缘两个级别上获得了明显更好的随机化概率和更严格的误差界限,从而使我们能够保持高数据效用来训练GNN。使用基准数据集进行的广泛理论和实证分析表明,在对节点特征和边缘进行严格隐私保护的情况下,HeteroRR在模型效用方面显着优于各种基线。这使我们能够有效地保护DP保持GNN中的皮亚斯。
Graph neural networks (GNNs) are susceptible to privacy inference attacks (PIAS) given their ability to learn joint representation from features and edges among nodes in graph data. To prevent privacy leakages in GNNs, we propose a novel heterogeneous randomized response (HeteroRR) mechanism to protect nodes’ features and edges against PIAS under differential privacy (DP) guarantees, without an undue cost of data and model utility in training GNNs. Our idea is to balance the importance and sensitivity of nodes’ features and edges in redistributing the privacy budgets since some features and edges are more sensitive or important to the model utility than others. As a result, we derive significantly better randomization probabilities and tighter error bounds at both levels of nodes’ features and edges departing from existing approaches, thus enabling us to maintain high data utility for training GNNs. An extensive theoretical and empirical analysis using benchmark datasets shows that HeteroRR significantly outperforms various baselines in terms of model utility under rigorous privacy protection for both nodes’ features and edges. That enables us to defend PIAs in DP-preserving GNNs effectively.