arXiv:2509.04785cs.LGcs.AI2025-09被引 3

提出三种高效删除敏感节点的图神经网络隐私保护方法。

Graph Unlearning: Efficient Node Removal in Graph Neural Networks

  • 基于类别标签替换与拓扑引导的邻居概率更新机制
  • 在三个基准数据集上实现高精度模型恢复与快速删除
  • 适合关注图模型隐私安全的研究者和应用开发者

随着对隐私攻击和敏感信息泄露的日益关注,研究人员积极探索高效移除敏感训练数据以降低图神经网络(GNN)模型的隐私风险。节点去学习(Node Unlearning)作为一种保护敏感节点隐私的有前景技术,可高效移除特定训练节点的信息。然而,现有方法或对GNN结构有约束,或未能有效利用图拓扑进行去学习,部分方法甚至破坏图结构,难以平衡性能与复杂度。为此,本文提出三种新型节点去学习方法:基于类别的标签替换、拓扑引导的邻居均值后验概率,以及类别一致的邻居节点过滤。其中,后两者充分利用图的拓扑特征,实现更高效的节点去学习。在三个基准数据集上的实验表明,所提方法在模型效用、去学习效用和效率方面均优于当前最优方法,能有效移除敏感训练节点,保护敏感节点隐私。研究结果有助于提升GNN模型的隐私安全性,并为该领域提供重要洞见。

原文摘要 · Abstract (English)

With increasing concerns about privacy attacks and potential sensitive information leakage, researchers have actively explored methods to efficiently remove sensitive training data and reduce privacy risks in graph neural network (GNN) models. Node unlearning has emerged as a promising technique for protecting the privacy of sensitive nodes by efficiently removing specific training node information from GNN models. However, existing node unlearning methods either impose restrictions on the GNN structure or do not effectively utilize the graph topology for node unlearning. Some methods even compromise the graph's topology, making it challenging to achieve a satisfactory performance-complexity trade-off. To address these issues and achieve efficient unlearning for training node removal in GNNs, we propose three novel node unlearning methods: Class-based Label Replacement, Topology-guided Neighbor Mean Posterior Probability, and Class-consistent Neighbor Node Filtering. Among these methods, Topology-guided Neighbor Mean Posterior Probability and Class-consistent Neighbor Node Filtering effectively leverage the topological features of the graph, resulting in more effective node unlearning. To validate the superiority of our proposed methods in node unlearning, we conducted experiments on three benchmark datasets. The evaluation criteria included model utility, unlearning utility, and unlearning efficiency. The experimental results demonstrate the utility and efficiency of the proposed methods and illustrate their superiority compared to state-of-the-art node unlearning methods. Overall, the proposed methods efficiently remove sensitive training nodes and protect the privacy information of sensitive nodes in GNNs. The findings contribute to enhancing the privacy and security of GNN models and provide valuable insights into the field of node unlearning.

图神经网络隐私保护去学习拓扑利用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。