arXiv:2511.22872cs.IR2025-11AAAI被引 2

解决用户级联邦推荐中敏感属性泄露问题,提升隐私保护与推荐效果。

FedAU2: Attribute Unlearning for User-Level Federated Recommender Systems with Adaptive and Robust Adversarial Training

  • 自适应对抗训练缓解数据异构带来的训练不稳
  • 双随机变分自编码器防止梯度泄露,提升安全性
  • 在三个真实数据集上兼顾去属性化与推荐精度

联邦推荐系统(FedRecs)通过本地保留数据来保护用户隐私,但用户嵌入常包含敏感属性信息,易遭属性推断攻击。属性去学习成为应对该问题的可行方案。本文聚焦更具实际意义但更难的用户级联邦推荐场景。对抗训练是该场景下最可行的方法。我们识别出两大挑战:其一,用户数据异构导致训练不稳定;其二,梯度可能泄露属性信息。为此,提出FedAU2方法:针对第一挑战,设计自适应对抗训练策略,根据本地优化行为动态调整训练动态;针对第二挑战,引入双随机变分自编码器对对抗模型进行扰动,有效阻断基于梯度的信息泄露。在三个真实数据集上的大量实验表明,相比现有基线,所提方法在属性去学习效果和推荐性能上均表现更优。

原文摘要 · Abstract (English)

Federated Recommender Systems (FedRecs) leverage federated learning to protect user privacy by retaining data locally. However, user embeddings in FedRecs often encode sensitive attribute information, rendering them vulnerable to attribute inference attacks. Attribute unlearning has emerged as a promising approach to mitigate this issue. In this paper, we focus on user-level FedRecs, which is a more practical yet challenging setting compared to group-level FedRecs. Adversarial training emerges as the most feasible approach within this context. We identify two key challenges in implementing adversarial training-based attribute unlearning for user-level FedRecs: i) mitigating training instability caused by user data heterogeneity, and ii) preventing attribute information leakage through gradients. To address these challenges, we propose FedAU2, an attribute unlearning method for user-level FedRecs. For CH1, we propose an adaptive adversarial training strategy, where the training dynamics are adjusted in response to local optimization behavior. For CH2, we propose a dual-stochastic variational autoencoder to perturb the adversarial model, effectively preventing gradient-based information leakage. Extensive experiments on three real-world datasets demonstrate that our proposed FedAU2 achieves superior performance in unlearning effectiveness and recommendation performance compared to existing baselines.

联邦学习推荐系统隐私保护对抗训练

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。