跳到主要导航 跳到搜索 跳到主要内容

Mitigating Privacy Risks in Graph Condensation from a Hyperbolic Geometry Perspective

  • Beihang University
  • Guangxi Normal University
  • University of Edinburgh

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Graph condensation reduces large graphs into smaller synthetic ones for efficient training and potential privacy protection. While existing studies demonstrate graph condensation's resilience against membership inference attacks (MIAs), key questions remain unanswered: Can the common MIAs' accuracy truly represent the privacy-preserving capabilities of graph condensation? Does it remain robust against more powerful adversaries? And what are the underlying reasons for its performance? This paper investigates the privacy risks of gradient-matching-based condensation via tailored MIAs. We reveal that existing methods often face a trade-off between performance and generalization, where increasing node diversity can unintentionally amplify privacy leakage. Moreover, existing methods either homogenize nodes of the same class to maximize task-specific performance at the cost of generalization or enhance node diversity by efficiently incorporating additional information to improve model generalization, but such diversity inevitably expands the attack reasoning due to increased data disparity. To better balance performance and privacy, we propose a novel graph condensation framework (HDGC) that investigates privacy issues in graph condensation from a hyperbolic geometric perspective. Specifically, we first leverage hyperbolic geometric properties to constrain gradient-matching directions (HGGM), thereby obtaining latent hierarchical semantic guidance when learning the synthetic graph's topology. This mechanism measures node importance in hyperbolic space to enhance model generalization. Subsequently, we introduce hyperbolic adaptive differentially private noise during gradient matching (HADP). This perturbation intelligently adjusts noise influence based on local gradient importance and global geometric radius, ensuring diversity among same-class nodes while preserving differential privacy. Finally, relying on the post-processing principle of differential privacy, we incorporate distributionally robust optimization to mitigate excessive utility degradation caused by noise injection without compromising privacy guarantees. Experiments and analyses demonstrate that HDGC effectively captures geometric space characteristics, achieves superior performance, and provides a great foundation for defending inference attacks.

源语言英语
主期刊名KDD 2026 - Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1
出版商Association for Computing Machinery
1554-1565
页数12
ISBN(电子版)9798400722585
DOI
出版状态已出版 - 20 4月 2026
活动32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1, KDD 2026 - Jeju Island, 韩国
期限: 9 8月 202613 8月 2026

出版系列

姓名Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining
1-A
ISSN(印刷版)2154-817X

会议

会议32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1, KDD 2026
国家/地区韩国
Jeju Island
时期9/08/2613/08/26

学术指纹

探究 'Mitigating Privacy Risks in Graph Condensation from a Hyperbolic Geometry Perspective' 的科研主题。它们共同构成独一无二的学术指纹。

引用此