Interaction-level Membership Inference Attack Against Federated Recommender Systems
Wei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui, Tieke He, Hongzhi Yin
Abstract
The marriage of federated learning and recommender system (Fe-dRec) has been widely used to address the growing data privacy concerns in personalized recommendation services. In FedRecs, users' attribute information and behavior data (i.e., user-item interaction data) are kept locally on their personal devices, therefore, it is considered a fairly secure approach to protect user privacy. As a result, the privacy issue of FedRecs is rarely explored. Unfortunately, several recent studies reveal that FedRecs are vulnerable to user attribute inference attacks, highlighting the privacy concerns of FedRecs. In this paper, we further investigate the privacy problem of user behavior data (i.e., user-item interactions) in FedRecs. Specifically, we perform the first systematic study on interactionlevel membership inference attacks on FedRecs. An interactionlevel membership inference attacker is first designed, and then the classical privacy protection mechanism, Local Differential Privacy (LDP), is adopted to defend against the membership inference attack. Unfortunately, the empirical analysis shows that LDP is not effective against such new attacks unless the recommendation performance is largely compromised. To mitigate the interactionlevel membership attack threats, we design a simple yet effective defense method to significantly reduce the attacker's inference accuracy without losing recommendation performance. Extensive experiments are conducted with two widely used FedRecs (Fed-NCF and Fed-LightGCN) on three real-world recommendation datasets (MovieLens-100K, Steam-200K, and Amazon Cell Phone), and the experimental results show the effectiveness of our solutions. CCS CONCEPTS • Information systems → Recommender systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5a49de76-5270-4c85-91b0-2361f098a517Cited by top-tier papers6
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen et al.SIGIR 2023 · 46 citations
- HeteFedRec: Federated Recommender Systems with Model HeterogeneityWei Yuan, Liang Qu, Lizhen Cui, Yongxin Tong et al.ICDE 2024 · 35 citations
- Hide Your Model: A Parameter Transmission-free Federated Recommender SystemWei Yuan, Chaoqun Yang, Liang Qu, Quoc Viet Hung Nguyen et al.ICDE 2024 · 15 citations
- Poisoning Decentralized Collaborative Recommender System and Its CountermeasuresRuiqi Zheng, Liang Qu, Tong Chen, Kai Zheng et al.SIGIR 2024 · 10 citations
- Detecting Data Contamination in LLMs via In-Context LearningMichal Zawalski, Meriem Boubdir, Klaudia Balazy, Besmira Nushi et al.ICLR 2026 · 8 citations
Builds on10
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant RepresentationsKaran Ganju, Qi Wang, Wei Yang, Carl A. Gunter et al.CCS 2018 · 574 citations
- FedFast: Going Beyond Average for Faster Training of Federated Recommender SystemsKhalil Muhammad, Qinqin Wang, Diarmuid O'Reilly-Morgan, Elias Z. Tragos et al.KDD 2020 · 215 citations
Related papers
- Membership Inference Attacks Against Recommender SystemsMinxing Zhang, Zhaochun Ren, Zihan Wang, Pengjie Ren et al.CCS 2021 · 62 citations
- FedAU2: Attribute Unlearning for User-Level Federated Recommender Systems with Adaptive and Robust Adversarial TrainingYuyuan Li, Junjie Fang, Fengyuan Yu, Xichun Sheng et al.AAAI 2026 · 1 citation
- Theoretically Unmasking Inference Attacks Against LDP-Protected Clients in Federated Vision ModelsQuan Minh Nguyen, Minh N. Vu, Truc Nguyen, My T. ThaiICML 2025
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen et al.ICDE 2022 · 76 citations
- Local and Central Differential Privacy for Robustness and Privacy in Federated LearningMohammad Naseri, Jamie Hayes, Emiliano De CristofaroNDSS 2022
