[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83407-en":3,"doc-seo-83407-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83407,7971461741311,"Ophelia","https://ap-avatar.wpscdn.com/avatar/74000253aff267980c6?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779345379180704826",8,"Research & Report","EdgeRefine Privacy-Utility Balance for Graphs via Jaccard Sampling under Edge Differential Privacy","Graph Neural Networks (GNNs) succeed on graph-structured data but struggle in privacy-sensitive settings because graph structure can reveal sensitive link information. To meet edge-level differential privacy, common methods add noise to the adjacency matrix, increasing privacy while degrading utility, creating a major privacy-utility trade-off barrier. EdgeRefine introduces a local differential privacy framework using Jaccard-based edge-existence probability estimation and adaptive edge refinement. It ranks edges for noisy removal, then separately samples true and false edges under the privacy budget to preserve sparsity and reliability. Extensive experiments show accuracy comparable to the noise-free baseline for node classification, stronger gains over prior privacy-preserving methods, and robust reconstruction error resilience across budgets, indicating strong resistance to privacy leakage.","EdgeRefine: Privacy-Utility Balance for Graphs via Jaccard Sampling under Edge Differential Privacy  \nWenxiu Ding∗ State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University Xi’an, Shaanxi, China  \nMingjun Wang  \nSchool of Cyber Engineering, Xidian University Xi’an, Shaanxi, China  \nMuzhi Liu  \nState Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University Xi’an, Shaanxi, China  \nYifan Zhao  \nSchool of Cyber Engineering, Xidian University Xi’an, Shaanxi, China  \nZheng Yan  \nState Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University Xi’an, Shaanxi, China  \nQiao Liu  \nSchool of Cyber Engineering, Xidian University Xi’an, Shaanxi, China  \narXiv :2607 .08659v 1 [ cs .LG] 9 Jul 2026  \nAbstract  \nGraph Neural Networks (GNNs) have shown considerable success in learning from graph-structured data. However, their application in privacy-sensitive areas remains difficult as the structural information of graphs is prone to leaking sensitive link information. To satisfy edge-level differential privacy, a common approach is to directly inject noise into all elements of the graph’s adjacency matrix, thereby obfuscating the existence of any single edge. While increased noise strengthens privacy protection, excessive noise reduces utility. Privacy-utility balance becomes a major barrier to practical privacy-preserving graph learning.  \nTo address this issue, we propose EdgeRefine, a new local differential privacy framework that rethinks the privacy-utility trade-off in graph learning through adaptive edge refinement. EdgeRefine first estimates edge-existence probabilities using Jaccard similarity and ranks edges accordingly for noisy edge removal. To ensure the sparsity and reliability of the final graph, we leverage the privacy budget 􀁮 to determine the ratio of true to false edges, sample them separately based on the previously obtained probability ranking, and then control the total number of edges with a separate sampling rate 􀀺 . We conducted extensive experiments to evaluate the effectiveness of EdgeRefine, which achieves accuracy comparable to the noise-free baseline and performs much better than other privacy-preserving methods on various datasets and GNN architectures. Under privacy budget 􀁮 = 2. 5, EdgeRefine achieves significant node classification accuracy improvements over state-of-the-art baselines: 17 .8% on ACM under GAT and 19 . 7% on Cora under GCN. In graph classification task, an average accuracy degradation of around 5% has also been achieved compared to noise-free baseline. Under graph reconstruction attacks, EdgeRefine maintains relative absolute error levels consistently above 1 across all privacy budgets (averaging 1.962 on Cora and 1.472 on AMAP), indicating strong resilience against privacy leakage.  \nCCS Concepts  \n• Security and privacy; • Computing methodologies → Machine learning; • Theory of computation → Graph algorithms analysis;  \n∗Correspondence [to wxding@xidian.edu.cn](to wxding@xidian.edu.cn)  \nKeywords  \nGraph Neural Networks, Differential Privacy  \n1 Introduction  \nGraph Neural Networks (GNNs) [7] are powerful methods for learning from graph-structured data [39]. They have shown great success in many areas, such as social network analysis [42], recommendation systems [8], and bioinformatics [33] . GNNs use messagepassing mechanisms. By iteratively aggregating information from neighboring nodes, GNNs capture complex patterns and learn representations directly from graph structures. This very capability, while driving their rapid adoption in privacy-sensitive domains like social networks, also introduces significant privacy risks [12] .  \nDifferential Privacy (DP) [9] enables the injection of noise into the original raw data, which provides a potential approach to graph data analysis with strong privacy enhancement. Common DP methods include the Laplace mechanism for continuous data [9","cbCaifwIZXTffxCb","https://ap.wps.com/l/cbCaifwIZXTffxCb","pdf",3415010,3,1,21,"English","en",105,"# Abstract\n# Introduction\n## Graph Neural Networks and Privacy Risks\n## Differential Privacy Mechanisms for Graph Learning\n## Limitations of Existing Privacy-Preserving Methods\n# Table 1 Comparison of Privacy-Preserving Graph Learning Methods","[{\"question\":\"What privacy problem does EdgeRefine target in graph learning?\",\"answer\":\"EdgeRefine targets link privacy risks where graph structure can leak sensitive edge information when applying graph neural networks. It aims to satisfy edge-level differential privacy while retaining learning utility.\"},{\"question\":\"How does EdgeRefine estimate which edges are more likely to exist?\",\"answer\":\"EdgeRefine estimates edge-existence probabilities using Jaccard similarity, ranks edges accordingly, and uses this ranking to guide noisy edge removal.\"},{\"question\":\"How does EdgeRefine balance privacy and utility when refining edges?\",\"answer\":\"EdgeRefine uses the privacy budget to determine the true-to-false edge ratio, samples true and false edges separately based on the probability ranking, and controls the overall number of edges with a separate sampling rate.\"}]",1784187356,53,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"edgerefine-privacy-utility-balance-for-graphs-via-jaccard-sampling-under-edge-differential-privacy","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/edgerefine-privacy-utility-balance-for-graphs-via-jaccard-sampling-under-edge-differential-privacy/83407/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What privacy problem does EdgeRefine target in graph learning?","Question",{"text":75,"@type":76},"EdgeRefine targets link privacy risks where graph structure can leak sensitive edge information when applying graph neural networks. It aims to satisfy edge-level differential privacy while retaining learning utility.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does EdgeRefine estimate which edges are more likely to exist?",{"text":80,"@type":76},"EdgeRefine estimates edge-existence probabilities using Jaccard similarity, ranks edges accordingly, and uses this ranking to guide noisy edge removal.",{"name":82,"@type":73,"acceptedAnswer":83},"How does EdgeRefine balance privacy and utility when refining edges?",{"text":84,"@type":76},"EdgeRefine uses the privacy budget to determine the true-to-false edge ratio, samples true and false edges separately based on the probability ranking, and controls the overall number of edges with a separate sampling rate.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]