Reference Recommendation Based Membership Inference Attack Against Hybrid-Based Recommender Systems
Xiaoxiao Chi, Xuyun Zhang, Yan Wang, Hongsheng Hu, Wanchun Dou
Abstract
Recommender systems have been widely deployed across various domains such as e-commerce and social media, and intelligently suggest items like products and potential friends to users based on their preferences and interaction history, which are often privacy-sensitive. Recent studies have revealed that recommender systems are prone to membership inference attacks (MIAs), where an attacker aims to infer whether or not a user’s data has been used for training a target recommender system. However, existing MIAs fail to exploit the unique characteristic of recommender systems, and therefore are only applicable to mixed recommender systems consisting of two recommendation algorithms. This leaves a gap in investigating MIAs against hybrid-based recommender systems where the same algorithm utilizing user-item historical interactions and attributes of users and items serves and produces personalised recommendations. To investigate how the personalisation in hybrid-based recommender systems influences MIA, we propose a novel metric-based MIA. Specifically, we leverage the characteristic of personalisation to obtain reference recommendation for any target users. Then, a relative membership metric is proposed to exploit a target user’s historical interactions, target recommendation, and reference recommendation to infer the membership of the target user’s data. Finally, we theoretically and empirically demonstrate the efficacy of the proposed metric-based MIA on hybrid-based recommender systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0ce0540f-e63e-4bd1-834d-62e472795e38Builds on11
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 628 citations
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 354 citations
Related papers
- Debiasing Learning for Membership Inference Attacks Against Recommender SystemsZihan Wang, Na Huang, Fei Sun, Pengjie Ren et al.KDD 2022 · 22 citations
- Membership Inference Attacks Against Recommender SystemsMinxing Zhang, Zhaochun Ren, Zihan Wang, Pengjie Ren et al.CCS 2021 · 62 citations
- Membership Inference Attacks Against Sequential Recommender SystemsZhihao Zhu, Chenwang Wu, Rui Fan, Defu Lian et al.WWW 2023 · 25 citations
- Membership Inference Attack Against Large Language Model-Based Recommendation Systems: A New Distillation-Based ParadigmCuihong Li, Xiaowen Huang, Chuanhuan Yin, Jitao SangAAAI 2026
- Social Relation-Level Privacy Risks and Preservation in Social Recommender SystemsXuhao Zhao, Zhongrui Zhang, Yanmin Zhu, Zhaobo Wang et al.SIGIR 2025 · 2 citations
