The research paper, Empirical Auditing of Edge-Private Graph Generators, has been accepted as a poster at the NeurIPS 2026 Workshop on Bridging Optimal Transport, Learning and Structured Data: Toward Geometric Distributional Learning.
The paper is a joint piece of work by Stratis Limnios, Anum Fatima, James Adams, Lukasz Szpruch, Carsten Maple, Gesine Reinert and Andrew Elliott.
What the paper explores
Synthetic networks aim to preserve useful patterns while protecting sensitive relationships. The paper asks a specific question: can an auditor distinguish between synthetic outputs generated from two networks that differ by just one connection?
The authors compare three ways of detecting privacy leakage: checking for the connection directly, analysing the surrounding network structure, and using graph neural networks to learn more complex patterns. Across two generators and two networks, the privacy leakage detected depends on both the generator and the network. Learned attacks can reveal information that simpler structural checks miss.
These findings require careful interpretation. Differential privacy bounds information disclosure; it does not promise zero leakage. Detecting leakage therefore does not automatically demonstrate a breach of the stated guarantee. Equally, an audit that finds no breach cannot certify privacy.
For Plenitude, the connection to AI assurance is practical. Organisations need to understand the scope of a system’s guarantees, whether its implementation meets the relevant assumptions, and what testing reveals about its behaviour.
Why this matters
In financial crime applications, this means asking what evidence supports the use of a system in its intended setting, what exposure remains, and who owns the decision to accept or mitigate that risk. Research of this kind informs that approach by making both the evidence and its limitations explicit.