FedAU2: Attribute Unlearning for User-Level Federated Recommender Systems with Adaptive and Robust Adversarial Training
Yuyuan Li, Junjie Fang, Fengyuan Yu, Xichun Sheng, Tianyu Du, Xuyang Teng, Shaowei Jiang, Linbo Jiang, Jianan Lin, Chaochao Chen
Abstract
Federated Recommender Systems (FedRecs) leverage federated learning to protect user privacy by retaining data locally. However, user embeddings in FedRecs often encode sensitive attribute information, rendering them vulnerable to attribute inference attacks. Attribute unlearning has emerged as a promising approach to mitigate this issue. In this paper, we focus on user-level FedRecs, which is a more practical yet challenging setting compared to group-level FedRecs. Adversarial training emerges as the most feasible approach within this context. We identify two key challenges in implementing adversarial training-based attribute unlearning for user-level FedRecs: i) mitigating training instability caused by user data heterogeneity, and ii) preventing attribute information leakage through gradients. To address these challenges, we propose FedAU2, an attribute unlearning method for user-level FedRecs. For CH1, we propose an adaptive adversarial training strategy, where the training dynamics are adjusted in response to local optimization behavior. For CH2, we propose a dual-stochastic variational autoencoder to perturb the adversarial model, effectively preventing gradient-based information leakage. Extensive experiments on three real-world datasets demonstrate that our proposed FedAU2 achieves superior performance in unlearning effectiveness and recommendation performance compared to existing baselines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 101d02fc-444c-414d-9661-64fa67d36e17Builds on23
- Understanding and Improving Fast Adversarial TrainingMaksym Andriushchenko, Nicolas FlammarionNeurIPS 2020 · 366 citations
- InstaHide: Instance-hiding Schemes for Private Distributed LearningYangsibo Huang, Zhao Song, Kai Li, Sanjeev AroraICML 2020 · 178 citations
- ENCODER: Entity Mining and Modification Relation Binding for Composed Image RetrievalZixu Li, Zhiwei Chen, Haokun Wen, Zhiheng Fu et al.AAAI 2025 · 59 citations
- Personalized Behavior-Aware Transformer for Multi-Behavior Sequential RecommendationJiajie Su, Chaochao Chen, Zibin Lin, Xi Li et al.ACM MM 2023 · 47 citations
- Towards Personalized Privacy: User-Governed Data Contribution for Federated RecommendationLiang Qu, Wei Yuan, Ruiqi Zheng, Lizhen Cui et al.WWW 2024 · 44 citations
Related papers
- Aegis: Post-Training Attribute Unlearning in Federated Recommender Systems against Attribute Inference AttacksWenhan Wu, Jiawei Jiang, Chuang HuWWW 2025 · 4 citations
- Plug and Play: Enabling Pluggable Attribute Unlearning in Recommender SystemsXiaohua Feng, Yuyuan Li, Fengyuan Yu, Li Zhang et al.WWW 2025 · 5 citations
- Making Users Indistinguishable: Attribute-wise Unlearning in Recommender SystemsYuyuan Li, Chaochao Chen, Xiaolin Zheng, Yizhao Zhang et al.ACM MM 2023 · 26 citations
- Interaction-level Membership Inference Attack Against Federated Recommender SystemsWei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui et al.WWW 2023 · 101 citations
- Defending against Attribute Inference Attacks in Post-Training of Recommendation Systems via UnlearningWenhan Wu, Yili Gong, Jiawei Jiang, Chuang Hu et al.ICDE 2025 · 1 citation
