[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120050-en":3,"doc-seo-120050-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120050,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Privacy-Preserving Graph Machine Learning - dissertation","Real-world data can be modeled as graphs, where entities and their dependencies are captured explicitly, enabling applications across many domains. Graph neural networks (GNNs) have become central for tasks such as node classification and link prediction, yet privacy weaknesses increasingly matter in sensitive settings including healthcare, finance, and recommender systems. The thesis analyzes multiple privacy attacks and defenses for GNNs, focusing on membership inference, private model release using differential privacy, and privacy risks from releasing model explanations and reconstructing sensitive graph structures. It further studies leakage from latent representations, using related attacks as privacy auditors for graph and tabular data.","PRIVACY-PRESERVING GRAPH MACHINE LEARNING  \nVon der Fakultät für Elektrotechnik und Informatik der Gottfried Wilhelm Leibniz Universität Hannover zur Erlangung des akademischen Grades  \nDOKTOR DER NATURWISSENSCHAFTEN  \nDr. rer. nat.  \ngenehmigte Dissertation  \nvon Herrn  \nM.Sc., M.Phil. Iyiola Emmanuel OLATUNJI  \ngeboren am 07.09.1992  \nin Ibadan, Nigeria  \nHannover, Deutschland, 2024  \nReferent: Prof. Dr. techn. Wolfgang Nejdl Korreferentin: Asst. Prof. Megha Khosla  \nVorsitz: Prof. Dr. Sascha Fahl  \nTag der Promotion: 12.07.2024  \nDECLARATION OF AUTHORSHIP  \nI, Iyiola Emmanuel Olatunji, declare that this thesis, titled “Privacypreserving graph machine learning” and the work presented in it are my own. I confirm that:  \n• This work was done wholly or mainly while in candidature for a research degree at this university.  \n• Where any part of this thesis has previously been submitted for a degree or any other qualification at this university or any other institution, this has been clearly stated.  \n• Where I have consulted the published work of others, this is always clearly attributed.  \n• Where I have quoted from the work of others, the source is always given. With the exception of such quotations, this thesis is entirely my own work.  \n• I have acknowledged all main sources of help.  \n• Where the thesis is based on work done by myself jointly with others, I have made clear exactly what was done by others and what I have contributed myself.  \nABSTRACT  \nMost real-world data can be represented as graphs, capturing intricate relationships and dependencies among entities. This unique characteristics of graphs makes them applicable in various domains. A special family of machine learning models called graph neural networks (GNNs) are specially designed to handle graph data. In recent years, the widespread adoption of GNNs has revolutionized various analytical tasks involving graph data, such as node classification and link prediction.  \nHowever, concerns regarding the privacy vulnerabilities of these models have emerged, particularly in sensitive domains like healthcare, finance and recommender systems. This thesis explores the privacy implications of GNNs through a multi-faceted analysis encompassing several attacks, defense strategies and privacy-preserving frameworks.  \nThe first investigation focuses on the susceptibility of GNNs to membership inference attacks. We propose several attacks and defenses to effectively mitigate these attacks while minimizing the impact on model performance. Our findings reveal that structural information rather than overfitting is the primary contributor to information leakage.  \nSubsequently, we propose a novel privacy-preserving framework, PrivGnn, leveraging knowledge distillation and two noise mechanisms, random subsampling, and noisy labeling to privately release GNN models while providing rigorous privacy guarantees. The theoretical analysis within the Rényi differential privacy framework is accompanied by empirical validation against baseline methods. We also show that our privately released GNN model is robust to membership inference attacks.  \nFurthermore, since model explanations have become a desirable outcome of modern machine learning models, we explore the privacy risks involved in releasing model explanations from GNNs. Specifically, we study the interplay between privacy and interpretability in GNNs through graph reconstruction attacks. We demonstrate how model explanations can facilitate the reconstruction of sensitive graph structures. Various attack strategies are evaluated based on auxiliary information available to adversaries, with a proposed defense employing randomized response mechanisms to mitigate privacy leakage.  \nLastly, we develop attacks to systematically study the information leakage from latent representation in graph and tabular input data domains. We reveal the susceptibility of latent space representation learning to privacy attacks that reconstruct original ","cbCaibN9snCRNWkO","https://ap.wps.com/l/cbCaibN9snCRNWkO","pdf",4100514,1,180,"English","en",105,"# Abstract\n## Privacy threats to GNNs\n## Membership inference attacks and mitigations\n## PrivGnn: private GNN model release\n## Privacy risks from model explanations\n## Attacks on latent representations and privacy auditing","[{\"question\":\"What privacy problems does the thesis address for graph neural networks?\",\"answer\":\"It examines privacy vulnerabilities of GNNs, including membership inference, risks from releasing model explanations, and leakage from latent representations in graph and tabular settings.\"},{\"question\":\"How does the thesis mitigate membership inference attacks on GNNs?\",\"answer\":\"It proposes several attacks and defenses, showing that structural information—not overfitting—is the main driver of information leakage, and mitigations aim to reduce leakage while preserving model performance.\"},{\"question\":\"What is PrivGnn and how does it ensure privacy when releasing GNN models?\",\"answer\":\"PrivGnn is a privacy-preserving framework that uses knowledge distillation plus random subsampling and noisy labeling, supported by theoretical privacy analysis in the Rényi differential privacy framework and empirical validation.\"}]","Privacy-Preserving Graph Machine Learning - dissertation | PDF",1785727887,454,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"privacy-preserving-graph-machine-learning-dissertation","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/privacy-preserving-graph-machine-learning-dissertation/120050/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What privacy problems does the thesis address for graph neural networks?","Question",{"text":75,"@type":76},"It examines privacy vulnerabilities of GNNs, including membership inference, risks from releasing model explanations, and leakage from latent representations in graph and tabular settings.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the thesis mitigate membership inference attacks on GNNs?",{"text":80,"@type":76},"It proposes several attacks and defenses, showing that structural information—not overfitting—is the main driver of information leakage, and mitigations aim to reduce leakage while preserving model performance.",{"name":82,"@type":73,"acceptedAnswer":83},"What is PrivGnn and how does it ensure privacy when releasing GNN models?",{"text":84,"@type":76},"PrivGnn is a privacy-preserving framework that uses knowledge distillation plus random subsampling and noisy labeling, supported by theoretical privacy analysis in the Rényi differential privacy framework and empirical validation.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]