为推荐系统设计隐私风险评分,帮用户识别敏感行为数据。
RecPS: Privacy Risk Scoring for Recommender Systems
- 基于成员推断攻击构建交互级与用户级隐私评分
- 在多个主流数据集上验证了评分对隐私泄露的准确预测能力
- 适合关注数据隐私的模型开发者和需合规部署的平台
推荐系统已成为众多网络应用的核心组件,其核心是基于高度敏感的用户-项目交互数据训练的推荐模型。尽管学术界积极研究隐私保护技术,但实际模型开发仍依赖有限的隐私防护措施,如受控访问。用户应有权选择不共享高度敏感的交互数据,但目前尚无方法帮助用户判断哪些交互更敏感。因此,量化推荐系统训练数据的隐私风险是实现隐私感知的模型开发与部署的关键步骤。本文提出一种基于成员推断攻击(MIA)的隐私评分方法 RecPS,可实现交互级与用户级的隐私风险评估。交互级评分基于差分隐私原理构建,并进一步扩展至用户级。关键组件 RecLiRA 是一个高质量的交互级成员推断方法。我们在多个知名基准数据集和推荐模型上进行了广泛实验,证明了 RecPS 在风险评估和模型遗忘能力方面的独特优势。
原文摘要 · Abstract (English)
Recommender systems (RecSys) have become an essential component of many web applications. The core of the system is a recommendation model trained on highly sensitive user-item interaction data. While privacy-enhancing techniques are actively studied in the research community, the real-world model development still depends on minimal privacy protection, e.g., via controlled access. Users of such systems should have the right to choose \emph{not} to share highly sensitive interactions. However, there is no method allowing the user to know which interactions are more sensitive than others. Thus, quantifying the privacy risk of RecSys training data is a critical step to enabling privacy-aware RecSys model development and deployment. We propose a membership-inference attack (MIA)- based privacy scoring method, RecPS, to measure privacy risks at both the interaction and user levels. The RecPS interaction-level score definition is motivated and derived from differential privacy, which is then extended to the user-level scoring method. A critical component is the interaction-level MIA method RecLiRA, which gives high-quality membership estimation. We have conducted extensive experiments on well-known benchmark datasets and RecSys models to show the unique features and benefits of RecPS scoring in risk assessment and RecSys model unlearning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。