When Do Differentially Private Inputs Protect Graph Shift Operators?

📅 2026-09-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the severe utility degradation caused by conventional differential privacy noise mechanisms in graph filtering. We propose a privacy-preserving framework that eliminates the need for additional noise injection by leveraging the inherent randomness of input signals to protect graph shift operators. Specifically, we establish an explicit characterization of privacy loss based on the zeros of graph filters and provide formal (ε,δ)-differential privacy guarantees under Gaussian inputs. Theoretically, we demonstrate that constraining the zero distribution to limit privacy leakage elevates the lower bound on adversarial reconstruction error. Empirically, by integrating likelihood ratio analysis with the Cramér-Rao bound, we validate the proposed method on synthetic financial networks, demonstrating its significant advantages in balancing the privacy-utility tradeoff.
📝 Abstract
We study the differential privacy (DP) of a graph shift operator (GSO) when an analyst observes the output of a graph filter. In particular, we study the setting in which the input signals to the graph filter are drawn from a differentially private distribution. Unlike approaches that perturb the GSO or the filter output, we use the randomness already present in the inputs to protect the GSO. This yields an equivalent level of privacy protection to that of the perturbation methods without adding noise, and thus a better privacy-utility trade-off. We provide an explicit characterization of the privacy loss and its certificate in terms of the zeros of the graph filter. In doing so, we show that the log-likelihood ratio between the releases of two adjacent topologies is governed by the distances from each zero to the graph frequencies of the two GSOs. Then, by uniformly bounding the log-likelihood ratio over the adjacent topologies, we obtain an explicit $(\varepsilon,δ)$-DP guarantee for Gaussian inputs. We further show, via a Cramér--Rao bound, that the zero placement that limits the privacy loss also raises the floor on the adversary's reconstruction error. Finally, empirical validation is performed on a synthetic network of financial exposures, where the largest position a pair can conceal and the accuracy with which it can be sized are collinear across pairs. Both are set by the graph-frequency content of the pair, and the full network becomes recoverable only as the certified budget grows.
Problem

Research questions and friction points this paper is trying to address.

Differential Privacy
Graph Shift Operator
Graph Filter
Privacy-Utility Trade-off
Topology Protection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Differential Privacy
Graph Shift Operator
Graph Filter Zeros
Privacy-Utility Trade-off
Cramér-Rao Bound