As a decentralized machine learning technique, federated recommendation enables cross-platform or cross-device collaborative model training without compromising data privacy. Previous works have indicated that such a privacy-preserving learning framework is more easily affected by poisoning attacks from malicious users or data. However, many papers that demonstrate significant poisoning attack effectiveness often use simply vanilla federated recommendation as victim models without any protection mechanisms. In this paper, a security-aware federated recommendation system is implemented with a stochastic sampling strategy on the client side and robust estimation on the server side. Then, an improved poisoning attack algorithm is proposed to overcome these defense mechanisms and once again aim to enhance attack effectiveness. In the proposed algorithm, these malicious users primarily utilize intercepted gradients and intelligent sampling techniques to estimate approximate user embeddings, and then develop more threatening attack strategies based on this information. Our experiments, conducted on MovieLens datasets, focus on exposure-increasing attacks targeting items with varying levels of popularity. Regarding attacks that have been mitigated or even prevented by security-aware federated recommendation systems, the experimental results show that the proposed poisoning attack methods can further increase effectiveness by up to 86%.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Poisoning Attacks Against Security-Aware Federated Recommendation System

  • Chi Lee,
  • Szu-Hao Huang,
  • Chiao-Ting Chen

摘要

As a decentralized machine learning technique, federated recommendation enables cross-platform or cross-device collaborative model training without compromising data privacy. Previous works have indicated that such a privacy-preserving learning framework is more easily affected by poisoning attacks from malicious users or data. However, many papers that demonstrate significant poisoning attack effectiveness often use simply vanilla federated recommendation as victim models without any protection mechanisms. In this paper, a security-aware federated recommendation system is implemented with a stochastic sampling strategy on the client side and robust estimation on the server side. Then, an improved poisoning attack algorithm is proposed to overcome these defense mechanisms and once again aim to enhance attack effectiveness. In the proposed algorithm, these malicious users primarily utilize intercepted gradients and intelligent sampling techniques to estimate approximate user embeddings, and then develop more threatening attack strategies based on this information. Our experiments, conducted on MovieLens datasets, focus on exposure-increasing attacks targeting items with varying levels of popularity. Regarding attacks that have been mitigated or even prevented by security-aware federated recommendation systems, the experimental results show that the proposed poisoning attack methods can further increase effectiveness by up to 86%.