通过个性化扰动提升推荐系统鲁棒性与精度
Understanding and Improving Adversarial Collaborative Filtering for Robust Recommendation
- 基于用户嵌入尺度设计个性化扰动,增强对抗训练效果
- 理论证明对抗协同过滤可降低推荐误差,无论数据是否被污染
- 适合关注推荐系统安全与性能优化的研究者与工程师
对抗协同过滤(ACF)通过在用户和物品嵌入上施加对抗扰动进行对抗训练,被广泛认为是提升协同过滤推荐系统对投毒攻击鲁棒性的有效方法。此外,大量实证研究显示,ACF相比传统协同过滤还能提升推荐性能。然而,目前对ACF在性能与鲁棒性方面有效性背后的理论理解仍不清晰。本文首次从理论上证明,在相同训练轮次下,ACF在干净数据和被污染数据场景中均能实现比传统协同过滤更低的推荐误差。进一步,通过建立优化过程中推荐误差下降的理论边界,发现根据用户嵌入尺度分配个性化的扰动幅度可进一步提升ACF效果。基于此,我们提出个性化幅度对抗协同过滤(PamaCF)。大量实验表明,PamaCF不仅能有效防御多种投毒攻击,还显著提升了推荐性能。
原文摘要 · Abstract (English)
Adversarial Collaborative Filtering (ACF), which typically applies adversarial perturbations at user and item embeddings through adversarial training, is widely recognized as an effective strategy for enhancing the robustness of Collaborative Filtering (CF) recommender systems against poisoning attacks. Besides, numerous studies have empirically shown that ACF can also improve recommendation performance compared to traditional CF. Despite these empirical successes, the theoretical understanding of ACF's effectiveness in terms of both performance and robustness remains unclear. To bridge this gap, in this paper, we first theoretically show that ACF can achieve a lower recommendation error compared to traditional CF with the same training epochs in both clean and poisoned data contexts. Furthermore, by establishing bounds for reductions in recommendation error during ACF's optimization process, we find that applying personalized magnitudes of perturbation for different users based on their embedding scales can further improve ACF's effectiveness. Building on these theoretical understandings, we propose Personalized Magnitude Adversarial Collaborative Filtering (PamaCF). Extensive experiments demonstrate that PamaCF effectively defends against various types of poisoning attacks while significantly enhancing recommendation performance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。