Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its Countermeasures

被引:11
|
作者
Yuan, Wei [1 ]
Quoc Viet Hung Nguyen [2 ]
He, Tieke [3 ]
Chen, Liang [4 ]
Yin, Hongzhi [1 ]
机构
[1] Univ Queensland, Brisbane, Qld, Australia
[2] Griffith Univ, Gold Coast, Australia
[3] Nanjing Univ, Nanjing, Peoples R China
[4] Sun Yat Sen Univ, Guangzhou, Peoples R China
来源
PROCEEDINGS OF THE 46TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2023 | 2023年
基金
澳大利亚研究理事会;
关键词
Federated Recommender System; Poisoning Attack and Defense;
D O I
10.1145/3539618.3591722
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated Recommender Systems (FedRecs) are considered privacy-preserving techniques to collaboratively learn a recommendation model without sharing user data. Since all participants can directly influence the systems by uploading gradients, FedRecs are vulnerable to poisoning attacks of malicious clients. However, most existing poisoning attacks on FedRecs are either based on some prior knowledge or with less effectiveness. To reveal the real vulnerability of FedRecs, in this paper, we present a new poisoning attack method to manipulate target items' ranks and exposure rates effectively in the top-K recommendation without relying on any prior knowledge. Specifically, our attack manipulates target items' exposure rate by a group of synthetic malicious users who upload poisoned gradients considering target items' alternative products. We conduct extensive experiments with two widely used FedRecs (Fed-NCF and Fed-LightGCN) on two real-world recommendation datasets. The experimental results show that our attack can significantly improve the exposure rate of unpopular target items with extremely fewer malicious users and fewer global epochs than state-of-the-art attacks. In addition to disclosing the security hole, we design a novel countermeasure for poisoning attacks on FedRecs. Specifically, we propose a hierarchical gradient clipping with sparsified updating to defend against existing poisoning attacks. The empirical results demonstrate that the proposed defending mechanism improves the robustness of FedRecs.
引用
收藏
页码:1690 / 1699
页数:10
相关论文
共 50 条
  • [31] Extracting Core Users Based on Features of Users and Their Relationships in Recommender Systems
    Kuang, Li
    Cao, Gaofeng
    Chen, Liang
    INTERNATIONAL JOURNAL OF WEB SERVICES RESEARCH, 2017, 14 (02) : 1 - 23
  • [32] Poisoning Attacks to Graph-Based Recommender Systems
    Fang, Minghong
    Yang, Guolei
    Gong, Neil Zhenqiang
    Liu, Jia
    34TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2018), 2018, : 381 - 392
  • [33] User-controlled federated matrix factorization for recommender systems
    Vito Walter Anelli
    Yashar Deldjoo
    Tommaso Di Noia
    Antonio Ferrara
    Fedelucio Narducci
    Journal of Intelligent Information Systems, 2022, 58 : 287 - 309
  • [34] Federated matrix factorization for privacy-preserving recommender systems
    Du, Yongjie
    Zhou, Deyun
    Xie, Yu
    Shi, Jiao
    Gong, Maoguo
    APPLIED SOFT COMPUTING, 2021, 111
  • [35] DNS Cache Poisoning: A Review on its Technique and Countermeasures
    Dissanayake, I. M. M.
    2018 NATIONAL INFORMATION TECHNOLOGY CONFERENCE (NITC), 2018,
  • [36] Deep Leakage From Horizontal Federated Sequential Recommender Systems
    Guo, Kaifeng
    Xie, Kesheng
    Shi, Zian
    Gao, Rongjian
    IEEE ACCESS, 2024, 12 : 173037 - 173046
  • [37] User-controlled federated matrix factorization for recommender systems
    Anelli, Vito Walter
    Deldjoo, Yashar
    Di Noia, Tommaso
    Ferrara, Antonio
    Narducci, Fedelucio
    JOURNAL OF INTELLIGENT INFORMATION SYSTEMS, 2022, 58 (02) : 287 - 309
  • [38] Comparing Recommender Systems using Synthetic Data
    Slokom, Manel
    12TH ACM CONFERENCE ON RECOMMENDER SYSTEMS (RECSYS), 2018, : 548 - 552
  • [39] Authenticating Users of Recommender Systems Using Naive Bayes
    Wu, Zhengang
    Yu, Liangwen
    Sun, Huiping
    Guan, Zhi
    Chen, Zhong
    WEB INFORMATION SYSTEMS ENGINEERING - WISE 2013, PT I, 2013, 8180 : 199 - 208
  • [40] Propagating Users' Similarity towards improving Recommender Systems
    Satsiou, Anna
    Tassiulas, Leandros
    2014 IEEE/WIC/ACM INTERNATIONAL JOINT CONFERENCES ON WEB INTELLIGENCE (WI) AND INTELLIGENT AGENT TECHNOLOGIES (IAT), VOL 1, 2014, : 221 - 228