<p>Federated social recommender systems based on Graph Neural Network (GNN) enables efficient local training without sharing local private data. However, it has been proved to be vulnerable to security and privacy issues, namely data poisoning attacks and inference attacks. Existing efforts focused on enhancing the performance of the recommendations, without in-depth research on the privacy and security issues of Federated Recommender systems based on GNN (hereafter FRGNN). To this end, we propose a <Emphasis Type="Underline">Fe</Emphasis>derated <Emphasis Type="Underline">G</Emphasis>raph neural network for <Emphasis Type="Underline">S</Emphasis>ec<Emphasis Type="Underline">u</Emphasis>re and <Emphasis Type="Underline">P</Emphasis>rivat<Emphasis Type="Underline">e</Emphasis> recommendation (FeGSuPe) that can defend both the data poisoning attacks and the inference attacks, and improve the performance of recommendations. Specifically, FeGSuPe employs Diffie-Hellman for secure embedding transmission to protect user privacy, removes collaboration mechanism to reduce attack risks, and utilizes cosine similarity for the initial embedding to mitigate cold start. Furthermore, it employs mask cancellation for unbiased aggregation of model updates, thereby optimizing performance. Last, extensive experiments on three real-world datasets validate the superiority of FeGSuPe, achieving the highest test accuracy across all datasets, with the improvement of <InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(2.98\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mn>2.98</mn> <mo>%</mo> </mrow> </math></EquationSource> </InlineEquation> on Filmtrust, <InlineEquation ID="IEq2"> <EquationSource Format="TEX">\(14.79\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mn>14.79</mn> <mo>%</mo> </mrow> </math></EquationSource> </InlineEquation> on Ciao, <InlineEquation ID="IEq3"> <EquationSource Format="TEX">\(13.37\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mn>13.37</mn> <mo>%</mo> </mrow> </math></EquationSource> </InlineEquation> on Epinions, and achieving 2.4-11.6 times faster convergence, compared to three benchmarks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Secure and Private Recommendation based on Federated Graph Neural Network

  • Zhonglin Wang,
  • Jianming Wu,
  • Xiangcheng Zhu,
  • Ping Zhao

摘要

Federated social recommender systems based on Graph Neural Network (GNN) enables efficient local training without sharing local private data. However, it has been proved to be vulnerable to security and privacy issues, namely data poisoning attacks and inference attacks. Existing efforts focused on enhancing the performance of the recommendations, without in-depth research on the privacy and security issues of Federated Recommender systems based on GNN (hereafter FRGNN). To this end, we propose a Federated Graph neural network for Secure and Private recommendation (FeGSuPe) that can defend both the data poisoning attacks and the inference attacks, and improve the performance of recommendations. Specifically, FeGSuPe employs Diffie-Hellman for secure embedding transmission to protect user privacy, removes collaboration mechanism to reduce attack risks, and utilizes cosine similarity for the initial embedding to mitigate cold start. Furthermore, it employs mask cancellation for unbiased aggregation of model updates, thereby optimizing performance. Last, extensive experiments on three real-world datasets validate the superiority of FeGSuPe, achieving the highest test accuracy across all datasets, with the improvement of \(2.98\%\) 2.98 % on Filmtrust, \(14.79\%\) 14.79 % on Ciao, \(13.37\%\) 13.37 % on Epinions, and achieving 2.4-11.6 times faster convergence, compared to three benchmarks.