Trust-But-Verify: Poisoning-Resilient Locally Private Graph Learning Protocols

📅 2026-09-07
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出VERITAS协议,通过本地数据扰动与验证机制解决基于本地差分隐私的图学习中数据投毒攻击问题。
📝 Abstract
Built upon local differential privacy (LDP), locally private graph learning protocols have emerged as an important paradigm for decentralized graph learning, balancing privacy protection and learning utility. Under such protocols, each user locally perturbs their node features and adjacency information before transmission, ensuring formal privacy guarantees without original data leaving the device. However, the inherently open participation nature renders these protocols critically vulnerable to data poisoning attacks, where adversaries inject carefully crafted malicious nodes to corrupt neighborhood aggregation and degrade downstream utility. Despite the severity of this threat, effective defenses in this setting remain largely unexplored. In this paper, we propose VERITAS, a poisoning-resilient locally private graph learning protocol built on a trust-but-verify paradigm. By introducing a verification list encoding graded peer trust levels, VERITAS jointly privatizes node features and graph structure on the user side, while exploiting bilateral attestation asymmetry on the server side to identify and prune malicious nodes. Concretely, VERITAS comprises four synergistic stages: (1) local data perturbation, (2) attestation-driven malicious node pruning, (3) utility restoration via dual denoising, and (4) robust private graph learning. Extensive experiments on four real-world benchmark datasets across multiple LDP mechanisms and GNN architectures demonstrate that VERITAS effectively defends against data poisoning attacks and significantly improves downstream graph learning utility under rigorous privacy guarantees.
Problem

Research questions and friction points this paper is trying to address.

data poisoning attacks
locally private graph learning
local differential privacy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Poisoning-Resilient
Trust-but-Verify
Local Differential Privacy
Bilateral Attestation
Dual Denoising
🔎 Similar Papers
L
Longzhu He
Beijing University of Posts and Telecommunications
L
Li Sun
Beijing University of Posts and Telecommunications
Hao Peng
Hao Peng
Beihang University, Professor
Social Event DetectionAnomaly DetectionReinforcement Learning
R
Ruijie Wang
Beihang University
Raymond Chi-Wing Wong
Raymond Chi-Wing Wong
The Hong Kong University of Science and Technology
databasesdata mining
S
Sen Su
Beijing University of Posts and Telecommunications