Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/3460120.3484565acmconferencesArticle/Chapter ViewAbstractPublication PagesccsConference Proceedingsconference-collections

Locally Private Graph Neural Networks

Published: 13 November 2021 Publication History


Graph Neural Networks (GNNs) have demonstrated superior performance in learning node representations for various graph inference tasks. However, learning over graph data can raise privacy concerns when nodes represent people or human-related variables that involve sensitive or personal information. In this paper, we study the problem of node data privacy, where graph nodes (e.g., social network users) have potentially sensitive data that is kept private, but they could be beneficial for a central server for training a GNN over the graph. To address this problem, we propose a privacy-preserving, architecture-agnostic GNN learning framework with formal privacy guarantees based on Local Differential Privacy (LDP). Specifically, we develop a locally private mechanism to perturb and compress node features, which the server can efficiently collect to approximate the GNN's neighborhood aggregation step. Furthermore, to improve the accuracy of the estimation, we prepend to the GNN a denoising layer, called KProp, which is based on the multi-hop aggregation of node features. Finally, we propose a robust algorithm for learning with privatized noisy labels, where we again benefit from KProp's denoising capability to increase the accuracy of label inference for node classification. Extensive experiments conducted over real-world datasets demonstrate that our method can maintain a satisfying level of accuracy with low privacy loss.

Supplementary Material

MP4 File (CCS21-fp236.mp4)
Presentation video for the paper "Locally Private Graph Neural Networks". In this work, we propose a privacy-preserving GNN framework based on local differential privacy, when the graph topology is public but the node features/labels are private. Our contributions include building a new privacy mechanism, called the multi-bit mechanism, for high-dimensional feature perturbation. We also propose a simple graph convolution-based layer, called KProp, for improving the accuracy of our estimations. Finally, we design a novel learning algorithm, called Drop, for learning with privatized labels. Our experiments indicate that our method achieves a graceful accuracy-privacy trade-off.


2021. Stealing Links from Graph Neural Networks. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, Vancouver, B.C. https://www.usenix.org/conference/usenixsecurity21/presentation/he
Sami Abu-El-Haija, Bryan Perozzi, Amol Kapoor, Nazanin Alipourfard, Kristina Lerman, Hrayr Harutyunyan, Greg Ver Steeg, and Aram Galstyan. 2019. M ix H op: Higher-Order Graph Convolutional Architectures via Sparsified Neighborhood Mixing (Proceedings of Machine Learning Research, Vol. 97), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, Long Beach, California, USA, 21--29.
Jayadev Acharya, Ziteng Sun, and Huanyu Zhang. 2018. Communication efficient, sample optimal, linear time locally private discrete distribution estimation. arXiv preprint arXiv:1802.04705 (2018).
Jayadev Acharya, Ziteng Sun, and Huanyu Zhang. 2019. Hadamard response: Estimating distributions privately, efficiently, and with little communication. In The 22nd International Conference on Artificial Intelligence and Statistics. PMLR, 1120--1129.
Borja Balle and Yu-Xiang Wang. 2018. Improving the Gaussian Mechanism for Differential Privacy: Analytical Calibration and Optimal Denoising. In International Conference on Machine Learning. 394--403.
Raef Bassily, Kobbi Nissim, Uri Stemmer, and Abhradeep Thakurta. 2017. Practical locally private heavy hitters. arXiv preprint arXiv:1707.04982 (2017).
Raef Bassily and Adam Smith. 2015. Local, private, efficient protocols for succinct histograms. In Proceedings of the forty-seventh annual ACM symposium on Theory of computing. 127--135.
Mark Bun, Jelani Nelson, and Uri Stemmer. 2019. Heavy hitters and the structure of local privacy. ACM Transactions on Algorithms (TALG), Vol. 15, 4 (2019), 1--40.
Zhengdao Chen, Xiang Li, and Joan Bruna. 2017. Supervised community detection with line graph neural networks. arXiv preprint arXiv:1705.08415 (2017).
Graham Cormode, Tejas Kulkarni, and Divesh Srivastava. 2018. Marginal release under local differential privacy. In Proceedings of the 2018 International Conference on Management of Data. 131--146.
Bolin Ding, Janardhan Kulkarni, and Sergey Yekhanin. 2017. Collecting telemetry data privately. In Advances in Neural Information Processing Systems. 3571--3580.
John C Duchi, Michael I Jordan, and Martin J Wainwright. 2018. Minimax optimal procedures for locally private estimation. J. Amer. Statist. Assoc., Vol. 113, 521 (2018), 182--201.
Vasisht Duddu, Antoine Boutet, and Virat Shejwalkar. 2020. Quantifying Privacy Leakage in Graph Embedding. In Mobiquitous 2020--17th EAI International Conference on Mobile and Ubiquitous Systems: Computing, Networking and Services. 1--11.
David K Duvenaud, Dougal Maclaurin, Jorge Iparraguirre, Rafael Bombarell, Timothy Hirzel, Al á n Aspuru-Guzik, and Ryan P Adams. 2015. Convolutional networks on graphs for learning molecular fingerprints. In Advances in neural information processing systems. 2224--2232.
Cynthia Dwork, Aaron Roth, et al. 2014. The algorithmic foundations of differential privacy. Foundations and Trends ® in Theoretical Computer Science, Vol. 9, 3--4 (2014), 211--407.
Ú lfar Erlingsson, Vasyl Pihur, and Aleksandra Korolova. 2014. Rappor: Randomized aggregatable privacy-preserving ordinal response. In Proceedings of the 2014 ACM SIGSAC conference on computer and communications security. 1054--1067.
Marco Gaboardi and Ryan Rogers. 2018. Local private hypothesis testing: Chi-square tests. In International Conference on Machine Learning. PMLR, 1626--1635.
Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017a. Inductive representation learning on large graphs. In Advances in neural information processing systems. 1024--1034.
William L Hamilton, Rex Ying, and Jure Leskovec. 2017b. Representation learning on graphs: Methods and applications. arXiv preprint arXiv:1709.05584 (2017).
Madhav Jha and Sofya Raskhodnikova. 2013. Testing and reconstruction of Lipschitz functions with applications to data privacy. SIAM J. Comput., Vol. 42, 2 (2013), 700--731.
Meng Jiang, Taeho Jung, Ryan Karl, and Tong Zhao. 2020. Federated Dynamic GNN with Secure Aggregation. arXiv preprint arXiv:2009.07351 (2020).
Peter Kairouz, Keith Bonawitz, and Daniel Ramage. 2016. Discrete distribution estimation under local privacy. In International Conference on Machine Learning. PMLR, 2436--2444.
Peter Kairouz, H Brendan McMahan, Brendan Avent, Aurélien Bellet, Mehdi Bennis, Arjun Nitin Bhagoji, Keith Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al. 2019. Advances and open problems in federated learning. arXiv preprint arXiv:1912.04977 (2019).
Shiva Prasad Kasiviswanathan, Homin K Lee, Kobbi Nissim, Sofya Raskhodnikova, and Adam Smith. 2011. What can we learn privately? SIAM J. Comput., Vol. 40, 3 (2011), 793--826.
Diederik P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014).
Thomas N. Kipf and Max Welling. 2017. Semi-Supervised Classification with Graph Convolutional Networks. In International Conference on Learning Representations (ICLR) .
Günter Klambauer, Thomas Unterthiner, Andreas Mayr, and Sepp Hochreiter. 2017. Self-normalizing neural networks. In Advances in neural information processing systems. 971--980.
Johannes Klicpera, Stefan Wei ß enberger, and Stephan G ü nnemann. 2019. Diffusion improves graph learning. In Advances in Neural Information Processing Systems. 13354--13366.
Kaiyang Li, Guangchun Luo, Yang Ye, Wei Li, Shihao Ji, and Zhipeng Cai. 2020. Adversarial Privacy Preserving Graph Embedding against Inference Attack. arXiv preprint arXiv:2008.13072 (2020).
Qimai Li, Zhichao Han, and Xiao-Ming Wu. 2018. Deeper insights into graph convolutional networks for semi-supervised learning. arXiv preprint arXiv:1801.07606 (2018).
Yayong Li, Ling Chen, et al. 2021. Unified Robust Training for Graph NeuralNetworks against Label Noise. arXiv preprint arXiv:2103.03414 (2021).
Yujia Li, Daniel Tarlow, Marc Brockschmidt, and Richard Zemel. 2015. Gated graph sequence neural networks. arXiv preprint arXiv:1511.05493 (2015).
Peiyuan Liao, Han Zhao, Keyulu Xu, Tommi Jaakkola, Geoffrey Gordon, Stefanie Jegelka, and Ruslan Salakhutdinov. 2020. Graph Adversarial Networks: Protecting Information against Adversarial Attacks. arXiv preprint arXiv:2009.13504 (2020).
Miller McPherson, Lynn Smith-Lovin, and James M Cook. 2001. Birds of a feather: Homophily in social networks. Annual review of sociology, Vol. 27, 1 (2001), 415--444.
G. Mei, Z. Guo, S. Liu, and L. Pan. 2019. SGNN: A Graph Neural Network Based Federated Learning Approach by Hiding Structure. In 2019 IEEE International Conference on Big Data (Big Data). IEEE Computer Society, Los Alamitos, CA, USA, 2560--2568.
Christopher Morris, Martin Ritzert, Matthias Fey, William L Hamilton, Jan Eric Lenssen, Gaurav Rattan, and Martin Grohe. 2019. Weisfeiler and leman go neural: Higher-order graph neural networks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 33. 4602--4609.
Kobbi Nissim and Uri Stemmer. 2018. Clustering algorithms for the centralized and local models. In Algorithmic Learning Theory. PMLR, 619--653.
Hoang NT, Choong Jun Jin, and Tsuyoshi Murata. 2019. Learning graph neural networks with noisy labels. arXiv preprint arXiv:1905.01591 (2019).
Giorgio Patrini, Alessandro Rozza, Aditya Krishna Menon, Richard Nock, and Lizhen Qu. 2017. Making deep neural networks robust to label noise: A loss correction approach. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. 1944--1952.
Zhan Qin, Yin Yang, Ting Yu, Issa Khalil, Xiaokui Xiao, and Kui Ren. 2016. Heavy hitter estimation over set-valued data with local differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 192--203.
Sungmin Rhee, Seokjun Seo, and Sun Kim. 2017. Hybrid approach of relation network and localized graph convolutional filtering for breast cancer subtype classification. arXiv preprint arXiv:1711.05859 (2017).
Benedek Rozemberczki, Carl Allen, and Rik Sarkar. 2019. Multi-scale Attributed Node Embedding. arXiv preprint arXiv:1909.13021 (2019).
Benedek Rozemberczki and Rik Sarkar. 2020. Characteristic Functions on Graphs: Birds of a Feather, from Statistical Descriptors to Parametric Models. In Proceedings of the 29th ACM International Conference on Information and Knowledge Management (CIKM '20). ACM.
Franco Scarselli, Marco Gori, Ah Chung Tsoi, Markus Hagenbuchner, and Gabriele Monfardini. 2008. The graph neural network model. IEEE Transactions on Neural Networks, Vol. 20, 1 (2008), 61--80.
Hwanjun Song, Minseok Kim, Dongmin Park, and Jae-Gil Lee. 2020. Learning from noisy labels with deep neural networks: A survey. arXiv preprint arXiv:2007.08199 (2020).
Abhradeep Guha Thakurta, Andrew H Vyrros, Umesh S Vaishampayan, Gaurav Kapoor, Julien Freudiger, Vivek Rangarajan Sridhar, and Doug Davidson. 2017. Learning new words. US Patent 9,594,741.
Petar Veli v c kovi ć, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, and Yoshua Bengio. 2017. Graph attention networks. arXiv preprint arXiv:1710.10903 (2017).
Hongwei Wang and Jure Leskovec. 2020. Unifying graph convolutional neural networks and label propagation. arXiv preprint arXiv:2002.06755 (2020).
Ning Wang, Xiaokui Xiao, Yin Yang, Ta Duy Hoang, Hyejin Shin, Junbum Shin, and Ge Yu. 2018b. PrivTrie: Effective frequent term discovery under local differential privacy. In 2018 IEEE 34th International Conference on Data Engineering (ICDE). IEEE, 821--832.
Ning Wang, Xiaokui Xiao, Yin Yang, Jun Zhao, Siu Cheung Hui, Hyejin Shin, Junbum Shin, and Ge Yu. 2019 b. Collecting and analyzing multidimensional data with local differential privacy. In 2019 IEEE 35th International Conference on Data Engineering (ICDE). IEEE, 638--649.
Shaowei Wang, Liusheng Huang, Pengzhan Wang, Yiwen Nie, Hongli Xu, Wei Yang, Xiang-Yang Li, and Chunming Qiao. 2016a. Mutual information optimally local private discrete distribution estimation. arXiv preprint arXiv:1607.08025 (2016).
Tianhao Wang, Jeremiah Blocki, Ninghui Li, and Somesh Jha. 2017. Locally differentially private protocols for frequency estimation. In 26th $$USENIX$$ Security Symposium ($$USENIX$$ Security 17). 729--745.
Tianhao Wang, Ninghui Li, and Somesh Jha. 2018a. Locally differentially private frequent itemset mining. In 2018 IEEE Symposium on Security and Privacy (SP). IEEE, 127--143.
Tianhao Wang, Ninghui Li, and Somesh Jha. 2019 a. Locally differentially private heavy hitter identification. IEEE Transactions on Dependable and Secure Computing (2019).
Yue Wang, Xintao Wu, and Donghui Hu. 2016b. Using Randomized Response for Differential Privacy Preserving Data Collection. In EDBT/ICDT Workshops, Vol. 1558. 0090--6778.
Bang Wu, Xiangwen Yang, Shirui Pan, and Xingliang Yuan. 2020 b. Model Extraction Attacks on Graph Neural Networks: Taxonomy and Realization. arXiv preprint arXiv:2010.12751 (2020).
Zonghan Wu, Shirui Pan, Fengwen Chen, Guodong Long, Chengqi Zhang, and S Yu Philip. 2020 a. A comprehensive survey on graph neural networks. IEEE Transactions on Neural Networks and Learning Systems (2020).
Depeng Xu, Shuhan Yuan, Xintao Wu, and HaiNhat Phan. 2018c. DPNE: Differentially private network embedding. In Pacific-Asia Conference on Knowledge Discovery and Data Mining. Springer, 235--246.
Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2018a. How powerful are graph neural networks? arXiv preprint arXiv:1810.00826 (2018).
Keyulu Xu, Chengtao Li, Yonglong Tian, Tomohiro Sonobe, Ken-ichi Kawarabayashi, and Stefanie Jegelka. 2018b. Representation Learning on Graphs with Jumping Knowledge Networks. In Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 80), Jennifer Dy and Andreas Krause (Eds.). PMLR, Stockholmsmässan, Stockholm Sweden, 5453--5462.
Zhilin Yang, William W Cohen, and Ruslan Salakhutdinov. 2016. Revisiting semi-supervised learning with graph embeddings. arXiv preprint arXiv:1603.08861 (2016).
Min Ye and Alexander Barg. 2018. Optimal schemes for discrete distribution estimation under locally differential privacy. IEEE Transactions on Information Theory, Vol. 64, 8 (2018), 5662--5676.
Kun Yi and Jianxin Wu. 2019. Probabilistic end-to-end noise correction for learning with noisy labels. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 7017--7025.
Hongyi Zhang, Moustapha Cisse, Yann N Dauphin, and David Lopez-Paz. 2017. mixup: Beyond empirical risk minimization. arXiv preprint arXiv:1710.09412 (2017).
Muhan Zhang and Yixin Chen. 2018. Link prediction based on graph neural networks. In Advances in Neural Information Processing Systems. 5165--5175.
Sen Zhang and Weiwei Ni. 2019. Graph Embedding Matrix Sharing With Differential Privacy. IEEE Access, Vol. 7 (2019), 89390--89399.
Zhilu Zhang and Mert R Sabuncu. 2018. Generalized cross entropy loss for training deep neural networks with noisy labels. arXiv preprint arXiv:1805.07836 (2018).
Jun Zhou, Chaochao Chen, Longfei Zheng, Xiaolin Zheng, Bingzhe Wu, Ziqi Liu, and Li Wang. 2020. Privacy-Preserving Graph Neural Network for Node Classification. arXiv preprint arXiv:2005.11903 (2020).

Cited By

View all
  • (2025)A Privacy-Preserving Graph Neural Network for Network Intrusion DetectionIEEE Transactions on Dependable and Secure Computing10.1109/TDSC.2024.341785322:1(740-756)Online publication date: Jan-2025
  • (2024)Publishing number of walks and katz centrality under local differential privacyProceedings of the Fortieth Conference on Uncertainty in Artificial Intelligence10.5555/3702676.3702694(377-393)Online publication date: 15-Jul-2024
  • (2024)Delving into differentially private transformerProceedings of the 41st International Conference on Machine Learning10.5555/3692070.3692510(11049-11071)Online publication date: 21-Jul-2024
  • Show More Cited By



Information & Contributors


Published In

cover image ACM Conferences
CCS '21: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
November 2021
3558 pages
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].



Association for Computing Machinery

New York, NY, United States

Publication History

Published: 13 November 2021


Request permissions for this article.

Check for updates

Author Tags

  1. differential privacy
  2. graph neural networks
  3. node classification
  4. private learning


  • Research-article


CCS '21
CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security
November 15 - 19, 2021
Virtual Event, Republic of Korea

Acceptance Rates

Overall Acceptance Rate 1,261 of 6,999 submissions, 18%

Upcoming Conference

CCS '25


Other Metrics

Bibliometrics & Citations


Article Metrics

  • Downloads (Last 12 months)221
  • Downloads (Last 6 weeks)22
Reflects downloads up to 08 Feb 2025

Other Metrics


Cited By

View all
  • (2025)A Privacy-Preserving Graph Neural Network for Network Intrusion DetectionIEEE Transactions on Dependable and Secure Computing10.1109/TDSC.2024.341785322:1(740-756)Online publication date: Jan-2025
  • (2024)Publishing number of walks and katz centrality under local differential privacyProceedings of the Fortieth Conference on Uncertainty in Artificial Intelligence10.5555/3702676.3702694(377-393)Online publication date: 15-Jul-2024
  • (2024)Delving into differentially private transformerProceedings of the 41st International Conference on Machine Learning10.5555/3692070.3692510(11049-11071)Online publication date: 21-Jul-2024
  • (2024)Common Neighborhood Estimation over Bipartite Graphs under Local Differential PrivacyProceedings of the ACM on Management of Data10.1145/36988032:6(1-26)Online publication date: 20-Dec-2024
  • (2024)A Systematic Review of Contemporary Applications of Privacy-Aware Graph Neural Networks in Smart CitiesProceedings of the 19th International Conference on Availability, Reliability and Security10.1145/3664476.3669980(1-10)Online publication date: 30-Jul-2024
  • (2024)Towards Accurate and Stronger Local Differential Privacy for Federated Learning with Staircase Randomized ResponseProceedings of the Fourteenth ACM Conference on Data and Application Security and Privacy10.1145/3626232.3653279(307-318)Online publication date: 19-Jun-2024
  • (2024)Locally and Structurally Private Graph Neural NetworksDigital Threats: Research and Practice10.1145/36244855:1(1-23)Online publication date: 21-Mar-2024
  • (2024)LinkGuard: Link Locally Privacy-Preserving Graph Neural Networks with Integrated Denoising and Private LearningCompanion Proceedings of the ACM Web Conference 202410.1145/3589335.3651533(593-596)Online publication date: 13-May-2024
  • (2024)DPAR: Decoupled Graph Neural Networks with Node-Level Differential PrivacyProceedings of the ACM Web Conference 202410.1145/3589334.3645531(1170-1181)Online publication date: 13-May-2024
  • (2024)Local Differential Private Spatio- Temporal Dynamic Graph Learning for Wireless Social Networks2024 IEEE Wireless Communications and Networking Conference (WCNC)10.1109/WCNC57260.2024.10571169(1-6)Online publication date: 21-Apr-2024
  • Show More Cited By

View Options

Login options

View options


View or Download as a PDF file.



View online with eReader.







Share this Publication link

Share on social media