针对联邦序列推荐的双视角攻击框架,提升攻击精准度。
DV-FSR: A Dual-View Target Attack Framework for Federated Sequential Recommendation
- 结合采样显式策略与对比学习隐式梯度策略协同攻击
- 在主流序列推荐模型上实现显著攻击效果
- 适合研究联邦推荐安全与防御机制的学者
联邦推荐(FedRec)通过去中心化训练保护用户隐私,但其架构易受对抗攻击。尽管已有大量关于联邦推荐中目标攻击的研究,但多数忽略了推荐模型的差异性鲁棒性。我们实证发现,现有目标攻击方法在联邦序列推荐(FSR)任务中效果有限。为此,本文聚焦于FSR中的目标攻击,提出一种新颖的双视角攻击框架DV-FSR。该方法创新性地融合基于采样的显式策略与基于对比学习的隐式梯度策略,实现协同攻击。此外,我们设计了一种专门针对FSR目标攻击的防御机制,用于评估所提攻击方法的可缓解性。大量实验验证了该方法在代表性序列模型上的有效性。
原文摘要 · Abstract (English)
Federated recommendation (FedRec) preserves user privacy by enabling decentralized training of personalized models, but this architecture is inherently vulnerable to adversarial attacks. Significant research has been conducted on targeted attacks in FedRec systems, motivated by commercial and social influence considerations. However, much of this work has largely overlooked the differential robustness of recommendation models. Moreover, our empirical findings indicate that existing targeted attack methods achieve only limited effectiveness in Federated Sequential Recommendation (FSR) tasks. Driven by these observations, we focus on investigating targeted attacks in FSR and propose a novel dualview attack framework, named DV-FSR. This attack method uniquely combines a sampling-based explicit strategy with a contrastive learning-based implicit gradient strategy to orchestrate a coordinated attack. Additionally, we introduce a specific defense mechanism tailored for targeted attacks in FSR, aiming to evaluate the mitigation effects of the attack method we proposed. Extensive experiments validate the effectiveness of our proposed approach on representative sequential models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。