提出无需先验知识的攻击方法,可隐蔽提升目标商品曝光率。
Preventing the Popular Item Embedding Based Attack in Federated Recommendations
- 通过训练中嵌入变化挖掘热门商品,实现无模型依赖攻击
- 使目标商品曝光率提升40%以上,且防御手段难以拦截
- 适合研究推荐系统安全或设计对抗防御的研究者
隐私担忧推动了联邦推荐系统(FRS)的发展,可在分布式客户端上构建个性化模型。然而,FRS易受投毒攻击,恶意用户通过操纵梯度故意推广目标商品。现有攻击依赖特定模型和先验知识,限制了实际应用。本文提出一种无需模型和先验知识的攻击方法——PIECK(基于热门商品嵌入的攻击),其核心是利用训练过程中嵌入变化挖掘热门商品。基于此,PIECK发展出两种方案:PIECKIPE通过增强目标商品嵌入与挖掘出的热门商品对齐以提升曝光;PIECKUEA进一步引入用户嵌入近似模块,逼近私有用户嵌入以增强攻击鲁棒性。评估发现现有防御方法对PIECK无效,因有毒梯度必然压倒冷门商品。为此,我们提出新型防御,在用户训练中引入两项正则化项,约束商品曝光增强和用户嵌入近似,同时保持推荐性能。在两个基础模型、三个真实数据集、四种顶级攻击和六种通用防御方法上验证,证明PIECK及其防御均有效。
原文摘要 · Abstract (English)
Privacy concerns have led to the rise of federated recommender systems (FRS), which can create personalized models across distributed clients. However, FRS is vulnerable to poisoning attacks, where malicious users manipulate gradients to promote their target items intentionally. Existing attacks against FRS have limitations, as they depend on specific models and prior knowledge, restricting their real-world applicability. In our exploration of practical FRS vulnerabilities, we devise a model-agnostic and prior-knowledge-free attack, named PIECK (Popular Item Embedding based Attack). The core module of PIECK is popular item mining, which leverages embedding changes during FRS training to effectively identify the popular items. Built upon the core module, PIECK branches into two diverse solutions: The PIECKIPE solution employs an item popularity enhancement module, which aligns the embeddings of targeted items with the mined popular items to increase item exposure. The PIECKUEA further enhances the robustness of the attack by using a user embedding approximation module, which approximates private user embeddings using mined popular items. Upon identifying PIECK, we evaluate existing federated defense methods and find them ineffective against PIECK, as poisonous gradients inevitably overwhelm the cold target items. We then propose a novel defense method by introducing two regularization terms during user training, which constrain item popularity enhancement and user embedding approximation while preserving FRS performance. We evaluate PIECK and its defense across two base models, three real datasets, four top-tier attacks, and six general defense methods, affirming the efficacy of both PIECK and its defense.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。