Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its Countermeasures
Wei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen, Hongzhi Yin
Abstract
Federated Recommender Systems (FedRecs) are considered privacy-preserving techniques to collaboratively learn a recommendation model without sharing user data. Since all participants can directly influence the systems by uploading gradients, FedRecs are vulnerable to poisoning attacks of malicious clients. However, most existing poisoning attacks on FedRecs are either based on some prior knowledge or with less effectiveness. To reveal the real vulnerability of FedRecs, in this paper, we present a new poisoning attack method to manipulate target items' ranks and exposure rates effectively in the top-K recommendation without relying on any prior knowledge. Specifically, our attack manipulates target items' exposure rate by a group of synthetic malicious users who upload poisoned gradients considering target items' alternative products. We conduct extensive experiments with two widely used FedRecs (Fed-NCF and Fed-LightGCN) on two real-world recommendation datasets. The experimental results show that our attack can significantly improve the exposure rate of unpopular target items with extremely fewer malicious users and fewer global epochs than state-of-the-art attacks. In addition to disclosing the security hole, we design a novel countermeasure for poisoning attacks on FedRecs. Specifically, we propose a hierarchical gradient clipping with sparsified updating to defend against existing poisoning attacks. The empirical results demonstrate that the proposed defending mechanism improves the robustness of FedRecs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 10077ecd-e793-41a6-904c-0b76bba9d437Cited by top-tier papers11
- Towards Personalized Privacy: User-Governed Data Contribution for Federated RecommendationLiang Qu, Wei Yuan, Ruiqi Zheng, Lizhen Cui et al.WWW 2024 · 44 citations
- HeteFedRec: Federated Recommender Systems with Model HeterogeneityWei Yuan, Liang Qu, Lizhen Cui, Yongxin Tong et al.ICDE 2024 · 35 citations
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 32 citations
- Towards Efficient Communication and Secure Federated Recommendation System via Low-rank TrainingNgoc-Hieu Nguyen, Tuan-Anh Nguyen, Tuan Nguyen, Vu Tien Hoang et al.WWW 2024 · 32 citations
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin et al.KDD 2024 · 16 citations
Builds on12
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- Are Graph Augmentations Necessary?: Simple Graph Contrastive Learning for RecommendationJunliang Yu, Hongzhi Yin, Xin Xia, Tong Chen et al.SIGIR 2022 · 658 citations
- FedFast: Going Beyond Average for Faster Training of Federated Recommender SystemsKhalil Muhammad, Qinqin Wang, Diarmuid O'Reilly-Morgan, Elias Z. Tragos et al.KDD 2020 · 215 citations
- FedRec++: Lossless Federated Recommendation with Explicit FeedbackFeng Liang, Weike Pan, Zhong MingAAAI 2021 · 152 citations
Related papers
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Preventing the Popular Item Embedding Based Attack in Federated RecommendationsJun Zhang, Huan Li, Dazhong Rong, Yan Zhao et al.ICDE 2024 · 7 citations
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen et al.ICDE 2022 · 76 citations
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu et al.CCS 2024 · 4 citations
- Spattack: Subgroup Poisoning Attacks on Federated Recommender SystemsBo Yan, Yurong Hao, Dingqi Liu, Huabin Sun et al.WWW 2026
