arXiv:2507.06258cs.CRcs.AI2025-07中稿 · WWW 2026被引 2

针对联邦推荐系统设计精准攻击,仅用0.1%恶意用户就能定向操纵特定群体推荐结果。

Spattack: Subgroup Poisoning Attacks on Federated Recommender Systems

  • 通过近似与促进双阶段策略,精准识别并影响目标用户子群
  • 在真实数据集上实现对目标子群强攻击效果,对非目标用户影响极小
  • 适合研究隐私安全与对抗攻击的学者,尤其关注群体公平性

联邦推荐系统(FedRec)在保护用户隐私的同时提供个性化推荐,但近期研究揭示其易受投毒攻击:恶意客户端注入伪造梯度以推广目标商品。现有攻击多针对全体用户,隐蔽性差且易被检测。现实中攻击者更可能针对特定子群(如向老年人推广保健品)以提升效果并隐藏行踪。为此,我们提出Spattack,首个专为联邦场景下用户子群定制的投毒攻击方法。该方法采用近似-促进范式:先近似目标与非目标子群的用户嵌入,再将目标商品推向目标子群。实验表明,即使仅有0.1%的用户为恶意,Spattack仍能在三个真实数据集上实现对目标子群的强攻击效果,对非目标用户影响微弱。此外,该方法具备良好推荐性能,并对主流防御策略表现出强鲁棒性。

原文摘要 · Abstract (English)

Federated recommender systems (FedRec) have emerged as a promising approach to provide personalized recommendations while protecting user privacy. However, recent studies have shown their vulnerability to poisoning attacks, where malicious clients inject crafted gradients to promote target items to benign users. Existing attacks typically target the full user group, which compromises stealth and increases detection risk. In contrast, real-world adversaries may prefer to target specific user subgroups, such as promoting health supplements to older individuals, to maximize effectiveness while preserving stealth. Motivated by this gap, we introduce Spattack, the first poisoning attack designed to manipulate recommendations for specific user subgroups in federated settings. Spattack adopts an approximate-and-promote paradigm, which approximates user embeddings of target and non-target subgroups and then promotes target items to the target subgroup. We further reveal a trade-off between strong attack performance on the target subgroup and limited impact on the non-target subgroup. To achieve a better trade-off, we propose enhanced approximation and promotion strategies. For approximation, we push embeddings of different subgroups apart via contrastive learning and augment the target subgroup's relevant item set through clustering. For promotion, we align embeddings of target items and relevant items to strengthen their semantic connections, together with an adaptive weighting strategy to balance effects across subgroups. Experiments on three real-world datasets demonstrate that Spattack achieves strong attack performance on the target subgroup with minimal impact on non-target users, even when only 0.1% of users are malicious. Moreover, Spattack maintains competitive recommendation performance and shows strong resilience against mainstream defenses.

联邦学习推荐系统投毒攻击子群攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。