Contrastive Self-Supervised Learning for Utility-Privacy Trade-off Navigation in Graph Neural Networks

Node-Level Vulnerability Analysis and DP Utility Recovery

Master Thesis (2026)
Author(s)

K. Tanahashi (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Contributor(s)

M. Khosla – Mentor (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Z. Erkin – Graduation committee member (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Faculty
Electrical Engineering, Mathematics and Computer Science
More Info
expand_more
Publication Year
2026
Language
English
Graduation Date
06-07-2026
Awarding Institution
Delft University of Technology
Programme
Computer Science
Faculty
Electrical Engineering, Mathematics and Computer Science
Downloads counter
43
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Graphs are everywhere in the real world. Although Graph Neural Networks (GNNs) have demonstrated strong performance across a wide range of graph-based tasks, their unique neighbourhood aggregation mechanism encodes sensitive feature, label, and topological information into model weights, making them vulnerable to Membership Inference Attacks (MIA). This poses challenges for organizations regarding the practical deployment of GNN models trained on their private data, as they have the obligation to protect the privacy of individuals in the dataset. While numerous privacy-preserving techniques, including differential privacy (DP) based approaches such as PrivGNN, have been proposed, they are subject to the inherent utility-privacy trade-off where achieving strong privacy often comes at the cost of reduction in model utility. In this work, we investigate Self-Supervised Learning (SSL) pretraining on a public graph, with a focus on contrastive pretraining via GRACE, as a utility-preserving privacy mitigation strategy with the potential to improve privacy without sacrificing generalizability. All experiments are performed under an inductive setting with disjoint graphs, where the model is evaluated on nodes never seen during training. We first show that SSL improves the utility-privacy trade-off in standard GNN training, with the backbone learning rate (BLR) acting as a tunable knob to navigate the trade-off. Subsequently, we perform a node-level vulnerability analysis, finding that structural isolation and intra-class feature dissimilarity act as predictors for nodes' privacy vulnerability, while neighbourhood class divergence exhibits more dataset-dependent results. We then show that employing lower BLR alone can disproportionately reduce the privacy vulnerability of the most exposed nodes, with SSL providing additional, uniform privacy benefit on top of it. Beyond standard GNN training, we integrate SSL into DP-based PrivGNN and show that it substantially recovers the utility lost to privacy mechanisms, providing significantly tighter formal privacy guarantees without hurting empirical privacy.

Files

Master_Thesis_Final.pdf
(pdf | 5.3 Mb)
License info not available