2607004629
  • Open Access
  • Review

Differentially Private Graph Learning: A Survey

  • Longzhu He 1,   
  • Li Sun 1, *,   
  • Ming Li 2,   
  • Yang Cao 3,   
  • Sen Su 1, 4, *,   
  • Masatoshi Yoshikawa 5,   
  • Jia Wu 6,   
  • Pietro Liò 7,   
  • Philip S. Yu 8

Received: 31 May 2026 | Revised: 08 Jul 2026 | Accepted: 14 Jul 2026 | Published: 30 Jul 2026

Abstract

Graph learning has been widely applied across diverse domains, including social networks, recommendation systems, and bioinformatics. However, real-world graph data often contains highly sensitive information, raising serious privacy concerns. Differential Privacy (DP) has emerged as a rigorous mathematical framework to protect sensitive information in graph learning while providing formal privacy guarantees. This survey presents the first comprehensive and systematic review of Differentially Private Graph Learning (DPGL). We organize existing DPGL methods into four categories based on the granularity of privacy protection, namely node-level, edge-level, graph-level, and local differential privacy. Within each category, we further analyze learning paradigms, perturbation mechanisms, and their respective strengths and limitations, and identify key technical challenges in the field. Furthermore, we identify future research directions critical for advancing DPGL toward practical deployment in real-world applications. This survey aims to provide a unified reference for researchers and practitioners while inspiring future innovations in privacy-preserving graph learning.

References 

  • 1.

    Zhu, X.; Tan, V.Y.; Xiao, X. Blink: Link local differential privacy in graph neural networks via Bayesian estimation. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS), Copenhagen, Denmark, 26–30 November 2023; pp. 2651–2664. https://doi.org/10.1145/3576915.3623165.

  • 2.

    Su, X.; Xue, S.; Liu, F.; et al. A comprehensive survey on community detection with deep learning. IEEE Trans. Neural Netw. Learn. Syst. 2024, 35, 4682–4702. https://doi.org/10.1109/TNNLS.2021.3137396.

  • 3.

    Hu, W.; Fang, H. Towards differential privacy in sequential recommendation: A noisy graph neural network approach. ACM Trans. Knowl. Discov. Data 2024, 18, 1–21. https://doi.org/10.1145/3643821.

  • 4.

    Ma, X.; Wu, J.; Xue, S.; et al. A Comprehensive Survey on Graph Anomaly Detection with Deep Learning. IEEE Trans. Knowl. Data Eng. 2023, 35, 12012–12038. https://doi.org/10.1109/TKDE.2021.3118815.

  • 5.

    Mueller, T.T.; Paetzold, J.C.; Prabhakar, C.; et al. Differentially private graph neural networks for whole-graph classification. IEEE Trans. Pattern Anal. Mach. Intell. 2023, 45, 7308–7318. https://doi.org/10.1109/TPAMI.2022.3228315.

  • 6.

    Kipf, T.N.; Welling, M. Semi-supervised classification with graph convolutional networks. In Proceedings of the International Conference on Learning Representations (ICLR), Toulon, France, 24–26 April 2017; pp. 1–14. https://openreview.net/forum?id=SJU4ayYgl.

  • 7.

    Wu, F.; Long, Y.; Zhang, C.; et al. Linkteller: Recovering private edges from graph neural networks via influence analysis. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA, 22–26 May 2022; pp. 2005–2024. https://doi.org/10.1109/SP46214.2022.9833806.

  • 8.

    Wang, X.; Wang, W.H. Group property inference attacks against graph neural networks. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS), Los Angeles, CA, USA, 7–11 November 2022; pp. 2871–2884. https://doi.org/10.1145/3548606.3560662.

  • 9.

    Meng, L.; Bai, Y.; Chen, Y.; et al. Devil in disguise: Breaching graph neural networks privacy through infiltration. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS), Copenhagen, Denmark, 26–30 November 2023; pp. 1153–1167. https://doi.org/10.1145/3576915.3623173.

  • 10.

    Dwork, C. Differential privacy: A survey of results. In Proceedings of the International Conference on Theory and Applications of Models of Computation (TAMC), Xi’an, China, 25–29 April 2008; pp. 1–19. https://doi.org/10.1007/978-3- 540-79228-4 1.

  • 11.

    Abadi, M.; Chu, A.; Goodfellow, I.; et al. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS), Vienna, Austria, 24–28 October 2016; pp. 308–318. https://doi.org/10.1145/2976749.2978318.

  • 12.

    Xiong, X.; Liu, S.; Li, D.; et al. A comprehensive survey on local differential privacy. Secur. Commun. Netw. 2020, 2020, 8829523. https://doi.org/10.3390/s20247030.

  • 13.

    Kasiviswanathan, S.P.; Lee, H.K.; Nissim, K.; et al. What can we learn privately? Siam J. Comput. 2011, 40, 793–826. https://doi.org/10.1137/090756090.

  • 14.

    Xiang, Z.; Wang, T.; Wang, D. Preserving node-level privacy in graph neural networks. In Proceedings of the 2024 IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA, 20–23 May 2024; pp. 4714–4732. https://doi.org/10.1109/SP54263.2024.00270.

  • 15.

    Kolluri, A.; Baluta, T.; Hooi, B.; et al. LPGNet: Link private graph networks for node classification. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security (CCS), Los Angeles, CA, USA, 7–11 November 2022; pp. 1813–1827. https://doi.org/10.1145/3548606.3560705.

  • 16.

    Li, Y.; Purcell, M.; Rakotoarivelo, T.; et al. Private graph data release: A survey. Acm Comput. Surv. 2023, 55, 1–39. https://doi.org/10.1145/3569085.

  • 17.

    Fu, D.; Bao, W.; Maciejewski, R.; et al. Privacy-preserving graph machine learning from data to computation: A survey. ACM SIGKDD Explor. Newsl. 2023, 25, 54–72. https://doi.org/10.1145/3606274.3606280.

  • 18.

    Zhang, H.; Wu, B.; Yuan, X.; et al. Trustworthy graph neural networks: Aspects, methods, and trends. Proc. IEEE 2024, 112, 97–139. https://doi.org/10.1109/JPROC.2024.3369017.

  • 19.

    Sajadmanesh, S.; Gatica-Perez, D. Locally private graph neural networks. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS), Virtual, 15–19 November 2021; pp. 2130–2145. https://doi.org/10.1145/3460120.3484565.

  • 20.

    Daigavane, A.; Madan, G.; Sinha, A.; et al. Node-level differentially private graph neural networks. In Proceedings of the ICLR 2022 Workshop on PAIR2Struct: Privacy, Accountability, Interpretability, Robustness, Reasoning on Structured Data (PAIR2Struct), Virtual, 2 April 2022; pp. 1–11. https://openreview.net/forum?id=BCfgOLx3gb9.

  • 21.

    Lin, W.; Li, B.; Wang, C. Towards private learning on decentralized graphs with local differential privacy. IEEE Trans. Inf. Forensics Secur. 2022, 17, 2936–2946. https://doi.org/10.1109/TIFS.2022.3198283.

  • 22.

    Jin, H.; Chen, X. Gromov-wasserstein discrepancy with local differential privacy for distributed structural graphs. In Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence (IJCAI), Vienna, Austria, 23–29 July 2022; pp. 2115–2121. https://doi.org/10.24963/ijcai.2022/294.

  • 23.

    Olatunji, I.E.; Funke, T.; Khosla, M. Releasing graph neural networks with differential privacy guarantees. Trans. Mach. Learn. Res. 2023, 2023, 1–29. https://openreview.net/forum?id=wk8oXR0kFA.

  • 24.

    Sajadmanesh, S.; Shamsabadi, A.S.; Bellet, A.; et al. GAP: Differentially private graph neural networks with aggregation perturbation. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security), 2023, Anaheim, CA, USA, 9–11 August 2023; pp. 3223–3240. https://www.usenix.org/conference/usenixsecurity23/presentation/sajadmanesh.

  • 25.

    Pei, X.; Deng, X.; Tian, S.; et al. Privacy-enhanced graph neural network for decentralized local graphs. IEEE Trans. Inf. Forensics Secur. 2024, 19, 1614–1629. https://doi.org/10.1109/TIFS.2023.3329971.

  • 26.

    Wang, X.; Gu, T.; Bao, X.; et al. Individual fairness for local private graph neural network. Knowl. Based Syst. 2023, 268, 110490. https://doi.org/10.1016/j.knosys.2023.110490.

  • 27.

    Chien, E.; Chen, W.N.; Pan, C.; et al. Differentially private decoupled graph convolutions for multigranular topology protection. Adv. Neural Inf. Process. Syst. 2023, 36, 45381–45401. https://openreview.net/forum?id=dd3KNayGFz.

  • 28.

    Sajadmanesh, S.; Gatica-Perez, D. Progap: Progressive graph neural networks with differential privacy guarantees. In Proceedings of the 17th ACM International Conference on Web Search and Data Mining (WSDM), Merida, Mexico, 4–8 March 2024; pp. 596–605. https://doi.org/10.1145/3616855.3635761.

  • 29.

    Tang, T.; Niu, Y.; Avestimehr, S.; et al. Edge private graph neural networks with singular value perturbation. Proc. Priv. Enhancing Technol. 2024, 3, 391–406. https://doi.org/10.56553/popets-2024-0084.

  • 30.

    Zhang, Q.; Lee, H.k.; Ma, J.; et al. DPAR: Decoupled graph neural networks with node-level differential privacy. In Proceedings of the ACM Web Conference 2024 (WWW), Singapore, 13–17 May 2024; pp. 1170–1181. https://doi.org/10.1145/3589334.3645531.

  • 31.

    Qi, Y.; Lin, X.; Liu, Z.; et al. LinkGuard: Link locally privacy-preserving graph neural networks with integrated denoising and private learning. In Proceedings of the Companion Proceedings of the ACM Web Conference 2024 (WWW), Singapore, 13–17 May 2024; pp. 593–596. https://doi.org/10.1145/3589335.3651533

  • 32.

    Ran, X.; Ye, Q.; Hu, H.; et al. Differentially private graph neural networks for link prediction. In Proceedings of the 2024 IEEE 40th International Conference on Data Engineering (ICDE), Utrecht, The Netherlands, 13–16 May 2024; pp. 1632–1644. https://doi.org/10.1109/ICDE60146.2024.00133

  • 33.

    Zhang, G.; Cheng, X.; Pan, J.; et al. Locally differentially private graph learning on decentralized social graph. Knowl. Based Syst. 2024, 304, 112488. https://doi.org/10.1016/j.knosys.2024.112488.

  • 34.

    Hidano, S.; Murakami, T. Degree-preserving randomized response for graph neural networks under local differential privacy. Trans. Data Priv. 2024, 17, 89–121. http://www.tdp.cat/issues21/abs.a521a23.php.

  • 35.

    Bhaila, K.; Huang, W.; Wu, Y.; et al. Local differential privacy in graph neural networks: a reconstruction approach. In Proceedings of the 2024 SIAM International Conference on Data Mining (SDM), Houston, TX, USA, 18–20 April 2024; pp. 1–9. https://doi.org/10.1137/1.9781611978032.1.

  • 36.

    Li, Z.; Li, R.H.; Liao, M.; et al. Privacy-preserving graph embedding based on local differential privacy. In Proceedings of the 33rd ACM International Conference on Information and Knowledge Management (CIKM), Boise, ID, USA, 21–25 October 2024; pp. 1316–1325. https://doi.org/10.1145/3627673.3679759.

  • 37.

    Joshi, R.B.; Indri, P.; Mishra, S. GraphPrivatizer: Improved structural differential privacy for graph neural networks. Trans. Mach. Learn. Res. 2024, 2024, 1–30. https://openreview.net/forum?id=lcPtUhoGYc

  • 38.

    Lei, D.; Song, Z.; Yuan, Y.; et al. Achieving personalized privacy-preserving graph neural network via topology awareness. In Proceedings of the ACM on Web Conference 2025 (WWW), Sydney, NSW, Australia, 28 April–2 May 2025; pp. 3552–3560. https://doi.org/10.1145/3696410.3714555.

  • 39.

    Hou, R.; Ye, Q.; Ran, X.; et al. PrivIM: Differentially private graph neural networks for influence maximization. In Proceedings of the 2025 IEEE 41st International Conference on Data Engineering (ICDE), Hong Kong, China, 19–23 May 2025; pp. 3467–3479. https://doi.org/10.1109/ICDE65448.2025.00259.

  • 40.

    Zhang, S.; Ye, Q.; Hu, H. Structure-preference enabled graph embedding generation under differential privacy. In Proceedings of the 2025 IEEE 41st International Conference on Data Engineering (ICDE), Hong Kong, China, 19–23 May 2025; pp. 1334–1347. https://doi.org/10.1109/ICDE65448.2025.00104.

  • 41.

    Zhang, S.; Ye, Q.; Hu, H.; et al. AdvSGM: Differentially private graph learning via adversarial skip-gram model. In Proceedings of the 2025 IEEE 41st International Conference on Data Engineering (ICDE), Hong Kong, China, 19–23 May 2025; pp. 3494–3507. https://doi.org/10.1109/ICDE65448.2025.00261.

  • 42.

    Wei, J.; Zhu, Y.; Xiao, X.; et al. GCON: Differentially private graph convolutional network via objective perturbation. In Proceedings of the 2025 IEEE 41st International Conference on Data Engineering (ICDE), Hong Kong, China, 19–23 May 2025, pp. 2507–2520. https://doi.org/10.1109/ICDE65448.2025.00189.

  • 43.

    Li, Y.; Song, X.; Gong, K.; et al. Differentially private graph neural networks for graph classification and its adaptive optimization. Expert Syst. Appl. 2025, 263, 125798. https://doi.org/10.1016/j.eswa.2024.125798.

  • 44.

    Li, Y.; Song, X.; Liu, S.; et al. A semi-supervised privacy-preserving graph classification framework enhanced by graph contrastive learning. Expert Syst. Appl. 2026, 299, 130149. https://doi.org/10.1016/j.eswa.2025.130149.

  • 45.

    Guo, Z.; Liu, Y.; Ao, X.; et al. GRASP: Differentially private graph reconstruction defense with structured perturbation. In Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 2 (SIGKDD), Toronto, ON, Canada, 3–7 August 2025; pp. 767–777. https://doi.org/10.1145/3711896.3736992.

  • 46.

    Fu, J.; Hong, Y.; Chen, Z.; et al. Safeguarding graph neural networks against topology inference attacks. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS), Taipei, Taiwan, 13–17 October 2025; pp. 2144–2158. https://doi.org/10.1145/3719027.3765173.

  • 47.

    Yang, C.; Zhu, T.; Liu, Y.; et al. Differentially private adaptive noise for graph neural network in online social networks. Comput. Netw. 2025, 273, 111757. https://doi.org/10.1016/j.comnet.2025.111757.

  • 48.

    Xie, Y.; Ding, J.; Xue, P.; et al. Leveraging homophily under local differential privacy for effective graph neural networks. In Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases (ECML- PKDD), Porto, Portugal, 15–19 September 2025; pp. 380–396. https://doi.org/10.1007/978-3-032-06096-9 22.

  • 49.

    He, L.; Li, C.; Tang, P.; et al. Going deeper into locally differentially private graph neural networks. Forty-second International Conference on Machine Learning (ICML), Vancouver, BC, Canada, 13–19 July 2025; pp. 22548–22565. https://proceedings.mlr.press/v267/he25k.html.

  • 50.

    Bai, Y.; Xiao, L.; Zhao, H.; et al. DPRO-GNN: Bridging differential privacy and advanced optimization for privacy- preserving graph learning. Inf. Sci. 2026, 723, 122695. https://doi.org/10.1016/j.ins.2025.122695.

  • 51.

    Ke, H.; Zhang, S.; Ye, Q.; et al. Adversarial signed graph learning with differential privacy. In Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 1 (SIGKDD), Jeju, Republic of Korea, 9–13 August 2026; pp. 532–543. https://doi.org/10.1145/3770854.3780282.

  • 52.

    He, L.; Li, C.; Tang, P.; et al. Devil’s Hand: Data poisoning attacks to locally private graph learning protocols. In Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V. 1 (SIGKDD), Jeju, Republic of Korea, 9–13 August 2026; pp. 395–406. https://doi.org/10.1145/3770854.3780158.

  • 53.

    He, L.; Tang, P.; Sun, L.; et al. The Devil Within, The Cure Without: Securing Locally Private Graph Learning under Poisoning. In Proceedings of the ACM Web Conference 2026 (WWW), Dubai, United Arab Emirates, 29 June–3 July 2026; pp. 4493–4504. https://doi.org/10.1145/3774904.3792102.

  • 54.

    Zheng, Y.; Li, C.; Li, Z.; et al. Convergent privacy framework for multi-layer GNNs through contractive message passing. In Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 23–27 February 2026. https://doi.org/10.14722/ndss.2026.240255.

  • 55.

    He, L.; Tang, P.; Zhang, Y.; et al. Mitigating privacy risks in Retrieval-Augmented Generation via locally private entity perturbation. Inf. Process. Manag. 2025, 62, 104150. https://doi.org/10.1016/j.ipm.2025.104150.

  • 56.

    Wu, Z.; Pan, S.; Chen, F.; et al. A comprehensive survey on graph neural networks. IEEE Trans. Neural Netw. Learn. Syst. 2021, 32, 4–24. https://doi.org/10.1109/TNNLS.2020.2978386.

  • 57.

    He, L.; Wei, Z. Towards structure-aware data augmentation for high-degree graph neural networks. Inf. Process. Manag. 2026, 63, 104343. https://doi.org/10.1016/j.ipm.2025.104343.

  • 58.

    Papernot, N.; Abadi, M.; Erlingsson, .; et al. Semi-supervised knowledge transfer for deep learning from private training data. In Proceedings of the International Conference on Learning Representations (ICLR), Toulon, France, 24–26 April 2017. https://openreview.net/forum?id=HkwoSDPgg.

  • 59.

    Ding, B.; Kulkarni, J.; Yekhanin, S. Collecting telemetry data privately. Adv. Neural Inf. Process. Syst. 2017, 30, 3571–3580. https://doi.org/10.48550/arXiv.1712.01524.

  • 60.

    Kairouz, P.; Bonawitz, K.; Ramage, D. Discrete distribution estimation under local privacy. In Proceedings of the International Conference on Machine Learning (ICML), New York, NY, USA, 19–24 June 2016; pp. 2436–2444. https://proceedings.mlr.press/v48/kairouz16.html.

  • 61.

    Wang, N.; Xiao, X.; Yang, Y.; et al. Collecting and analyzing multidimensional data with local differential privacy. In Proceedings of the 2019 IEEE 35th International Conference on Data Engineering (ICDE), Macao, China, 8–11 April 2019; pp. 638–649. https://doi.org/10.1109/ICDE.2019.00063.

  • 62.

    Li, Z.; Wang, T.; Lopuha-Zwakenberg, M.; et al. Estimating numerical distributions under local differential privacy. In Proceedings of the 2020 ACM SIGMOD International Conference on Management of Data (SIGMOD), Virtual, 14–19 June 2020; pp. 621–635. https://doi.org/10.1145/3318464.3389700.

  • 63.

    Liu, J.; Yang, C.; Lu, Z.; et al. Graph foundation models: Concepts, opportunities and challenges. IEEE Trans. Pattern Anal. Mach. Intell. 2025, 47, 5023–5044. https://doi.org/10.1109/TPAMI.2025.3548729.

  • 64.

    Sun, J.; Xu, C.; Tang, L.; et al. Think-on-graph: Deep and responsible reasoning of large language model on knowledge graph. International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024; Volume 2024, pp. 3868–3898. https://openreview.net/forum?id=nnVO1PvbTv.

  • 65.

    Xu, Y.; He, S.; Chen, J.; et al. Generate-on-graph: Treat LLM as both agent and KG for incomplete knowledge graph question answering. In Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing (EMNLP), Miami, FL, USA, 12–16 November 2024; pp. 18410–18430. https://doi.org/10.18653/v1/2024.emnlp-main.1023.

  • 66.

    Edge, D.; Trinh, H.; Cheng, N.; et al. From local to global: A graph rag approach to query-focused summarization. arXiv 2024, arXiv:2404.16130. https://doi.org/10.48550/arXiv.2404.16130.

  • 67.

    Guo, Z.; Xia, L.; Yu, Y.; et al. LightRAG: Simple and fast retrieval-augmented generation. In Proceedings of the Findings of the Association for Computational Linguistics: EMNLP (EMNLP Findings), Suzhou, China, 4–9 November 2025; pp. 10746–10761. https://doi.org/10.18653/v1/2025.findings-emnlp.568.

  • 68.

    Chan, C.M.; Chen, W.; Su, Y.; et al. Chateval: Towards better llm-based evaluators through multi-agent debate. In Proceedings of the International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024. https://openreview.net/forum?id=FQepisCUWu.

  • 69.

    Yang, Y.; Chai, H.; Shao, S.; et al. Agentnet: Decentralized evolutionary coordination for llm-based multi-agent systems. Adv. Neural Inf. Process. Syst. 2025, 38, 107309–107336. https://openreview.net/forum?id=tXqLxHlb8Z.

  • 70.

    Zhang, G.; Yue, Y.; Li, Z.; et al. Cut the crap: An economical communication pipeline for llm-based multi-agent systems. In Proceedings of the International Conference on Learning Representations (ICLR), Singapore, 24–28 April 2025. https://openreview.net/forum?id=LkzuPorQ5L.

  • 71.

    He, L.; He, L.; He, D.; et al. Conflict-resilient multi-agent reasoning via signed graph modeling. arXiv 2026, arXiv:2605.19418. https://doi.org/10.48550/arXiv.2605.19418.

  • 72.

    Wang, L.; Ma, C.; Feng, X.; et al. A survey on large language model based autonomous agents. Front. Comput. Sci. 2024, 18, 186345. https://doi.org/10.1007/s11704-024-40231-1.

  • 73.

    Li, B.; Qi, P.; Liu, B.; et al. Trustworthy AI: From principles to practices. ACM Comput. Surv. 2023, 55, 177. https://doi.org/10.1145/3555803.

Share this article:
How to Cite
He, L.; Sun, L.; Li, M.; Cao, Y.; Su, S.; Yoshikawa, M.; Wu, J.; Liò, P.; Yu, P. S. Differentially Private Graph Learning: A Survey. Transactions on Graph Intelligence and Network Applications 2026.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.