提出防御数据投毒的隐私保护图学习协议,兼顾安全与效果。
Trust-But-Verify: Poisoning-Resilient Locally Private Graph Learning Protocols

- 用户本地扰动数据,服务器通过双向验证识别恶意节点。
- 在四个真实数据集上提升学习效用,对抗多种攻击方式。
- 适合注重隐私与安全的分布式图学习场景使用。
基于局部差分隐私(LDP)的分布式图学习协议可有效保护隐私并保障学习性能。然而,其开放参与特性使其易受数据投毒攻击:攻击者注入恶意节点干扰邻域聚合,降低下游任务性能。现有防御手段尚不充分。本文提出VERITAS协议,采用“信任但验证”范式,在用户端联合扰动节点特征与图结构,服务端利用双边认证不对称性识别并剔除恶意节点。协议包含四个协同阶段:(1) 本地数据扰动,(2) 基于认证的恶意节点剔除,(3) 双重去噪恢复效用,(4) 鲁棒私有图学习。在四个真实世界基准数据集上,针对多种LDP机制与GNN架构的实验表明,VERITAS能有效抵御投毒攻击,并在严格隐私保护下显著提升学习性能。
原文摘要 · Abstract (English)
Built upon local differential privacy (LDP), locally private graph learning protocols have emerged as an important paradigm for decentralized graph learning, balancing privacy protection and learning utility. Under such protocols, each user locally perturbs their node features and adjacency information before transmission, ensuring formal privacy guarantees without original data leaving the device. However, the inherently open participation nature renders these protocols critically vulnerable to data poisoning attacks, where adversaries inject carefully crafted malicious nodes to corrupt neighborhood aggregation and degrade downstream utility. Despite the severity of this threat, effective defenses in this setting remain largely unexplored. In this paper, we propose VERITAS, a poisoning-resilient locally private graph learning protocol built on a trust-but-verify paradigm. By introducing a verification list encoding graded peer trust levels, VERITAS jointly privatizes node features and graph structure on the user side, while exploiting bilateral attestation asymmetry on the server side to identify and prune malicious nodes. Concretely, VERITAS comprises four synergistic stages: (1) local data perturbation, (2) attestation-driven malicious node pruning, (3) utility restoration via dual denoising, and (4) robust private graph learning. Extensive experiments on four real-world benchmark datasets across multiple LDP mechanisms and GNN architectures demonstrate that VERITAS effectively defends against data poisoning attacks and significantly improves downstream graph learning utility under rigorous privacy guarantees.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。