提出双视角攻击框架,提升联邦序列推荐中的精准操控效果。
DARTS: A Dual-View Attack Framework for Targeted Manipulation in Federated Sequential Recommendation
- 结合采样显式策略与对比学习隐式梯度策略协同攻击
- 在主流序列模型上实现显著更高的目标操纵成功率
- 适合研究联邦学习安全、推荐系统攻防的学者与工程师
联邦推荐(FedRec)通过去中心化训练保护用户隐私,但其架构易受对抗攻击。尽管已有针对联邦推荐的定向攻击研究,但多数忽视了推荐模型的差异性鲁棒性。我们实证发现,现有方法在联邦序列推荐(FSR)任务中效果有限。为此,本文聚焦于FSR中的定向攻击,提出新型双视角攻击框架DV-FSR,该方法融合基于采样的显式策略与基于对比学习的隐式梯度策略,实现协同攻击。同时,设计专用防御机制以评估所提攻击的有效性。大量实验验证了该方法在代表性序列模型上的优越性能。代码已公开。
原文摘要 · Abstract (English)
Federated recommendation (FedRec) preserves user privacy by enabling decentralized training of personalized models, but this architecture is inherently vulnerable to adversarial attacks. Significant research has been conducted on targeted attacks in FedRec systems, motivated by commercial and social influence considerations. However, much of this work has largely overlooked the differential robustness of recommendation models. Moreover, our empirical findings indicate that existing targeted attack methods achieve only limited effectiveness in Federated Sequential Recommendation(FSR) tasks. Driven by these observations, we focus on investigating targeted attacks in FSR and propose a novel dualview attack framework, named DV-FSR. This attack method uniquely combines a sampling-based explicit strategy with a contrastive learning-based implicit gradient strategy to orchestrate a coordinated attack. Additionally, we introduce a specific defense mechanism tailored for targeted attacks in FSR, aiming to evaluate the mitigation effects of the attack method we proposed. Extensive experiments validate the effectiveness of our proposed approach on representative sequential models. Our codes are publicly available.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。