Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its Countermeasures

被引:11
|
作者
Yuan, Wei [1 ]
Quoc Viet Hung Nguyen [2 ]
He, Tieke [3 ]
Chen, Liang [4 ]
Yin, Hongzhi [1 ]
机构
[1] Univ Queensland, Brisbane, Qld, Australia
[2] Griffith Univ, Gold Coast, Australia
[3] Nanjing Univ, Nanjing, Peoples R China
[4] Sun Yat Sen Univ, Guangzhou, Peoples R China
来源
PROCEEDINGS OF THE 46TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2023 | 2023年
基金
澳大利亚研究理事会;
关键词
Federated Recommender System; Poisoning Attack and Defense;
D O I
10.1145/3539618.3591722
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated Recommender Systems (FedRecs) are considered privacy-preserving techniques to collaboratively learn a recommendation model without sharing user data. Since all participants can directly influence the systems by uploading gradients, FedRecs are vulnerable to poisoning attacks of malicious clients. However, most existing poisoning attacks on FedRecs are either based on some prior knowledge or with less effectiveness. To reveal the real vulnerability of FedRecs, in this paper, we present a new poisoning attack method to manipulate target items' ranks and exposure rates effectively in the top-K recommendation without relying on any prior knowledge. Specifically, our attack manipulates target items' exposure rate by a group of synthetic malicious users who upload poisoned gradients considering target items' alternative products. We conduct extensive experiments with two widely used FedRecs (Fed-NCF and Fed-LightGCN) on two real-world recommendation datasets. The experimental results show that our attack can significantly improve the exposure rate of unpopular target items with extremely fewer malicious users and fewer global epochs than state-of-the-art attacks. In addition to disclosing the security hole, we design a novel countermeasure for poisoning attacks on FedRecs. Specifically, we propose a hierarchical gradient clipping with sparsified updating to defend against existing poisoning attacks. The empirical results demonstrate that the proposed defending mechanism improves the robustness of FedRecs.
引用
收藏
页码:1690 / 1699
页数:10
相关论文
共 50 条
  • [41] Heterogeneity in Customization of Recommender Systems By Users with Homogenous Preferences
    Solomon, Jacob
    34TH ANNUAL CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2016, 2016, : 4166 - 4170
  • [42] Modeling mutual feedback between users and recommender systems
    Zeng, An
    Yeung, Chi Ho
    Medo, Matus
    Zhang, Yi-Cheng
    JOURNAL OF STATISTICAL MECHANICS-THEORY AND EXPERIMENT, 2015,
  • [43] Recommender systems effect on the evolution of users' choices distribution
    Hazrati, Naieme
    Ricci, Francesco
    INFORMATION PROCESSING & MANAGEMENT, 2022, 59 (01)
  • [44] Connectedness of users-items networks and recommender systems
    Gharibshah, Joobin
    Jalili, Mahdi
    APPLIED MATHEMATICS AND COMPUTATION, 2014, 243 : 578 - 584
  • [45] Learning Multiple Similarities of Users and Items in Recommender Systems
    Chen, Huiyuan
    Li, Jing
    2017 17TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2017, : 811 - 816
  • [46] A Model For Improving Recommender Systems Based On The Similarity Of Users
    Abdolvand, Neda
    Rahimi, Zahra
    Harandi, Saeedeh Rajaee
    PROCEEDINGS OF 2019 15TH IRAN INTERNATIONAL INDUSTRIAL ENGINEERING CONFERENCE (IIIEC), 2019, : 121 - 126
  • [47] Empowering Users through Privacy Management Recommender Systems
    Rasmussen, Curtis
    Dara, Rozita
    2014 IEEE CANADA INTERNATIONAL HUMANITARIAN TECHNOLOGY CONFERENCE (IHTC), 2014,
  • [48] Inferring Private Demographics of New Users in Recommender Systems
    Sun, Mingxuan
    Li, Changbin
    Zha, Hongyuan
    PROCEEDINGS OF THE 20TH ACM INTERNATIONAL CONFERENCE ON MODELLING, ANALYSIS AND SIMULATION OF WIRELESS AND MOBILE SYSTEMS (MSWIM'17), 2017, : 237 - 244
  • [49] Choice models and recommender systems effects on users' choices
    Hazrati, Naieme
    Ricci, Francesco
    USER MODELING AND USER-ADAPTED INTERACTION, 2024, 34 (01) : 109 - 145
  • [50] Collaborating with Users in Proximity for Decentralized Mobile Recommender Systems
    Beierle, Felix
    Eichinger, Tobias
    2019 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI 2019), 2019, : 1192 - 1197