Poisoning Federated Recommender Systems with Fake Users
Ming Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang Gong
Abstract
Federated recommendation is a prominent use case within federated learning, yet it remains susceptible to various attacks, from user to server-side vulnerabilities. Poisoning attacks are particularly notable among user-side attacks, as participants upload malicious model updates to deceive the global model, often intending to promote or demote specific targeted items. This study investigates strategies for executing promotion attacks in federated recommender systems. Current poisoning attacks on federated recommender systems often rely on additional information, such as the local training data of genuine users or item popularity. However, such information is challenging for the potential attacker to obtain. Thus, there is a need to develop an attack that requires no extra information apart from item embeddings obtained from the server. In this paper, we introduce a novel fake user based poisoning attack named PoisonFRS to promote the attacker-chosen targeted item in federated recommender systems without requiring knowledge about user-item rating data, user attributes, or the aggregation rule used by the server. Extensive experiments on multiple real-world datasets demonstrate that PoisonFRS can effectively promote the attacker-chosen targeted item to a large portion of genuine users and outperform current benchmarks that rely on additional information about the system. We further observe that the model updates from both genuine and fake users are indistinguishable within the latent space. CCS CONCEPTS • Security and privacy → Systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5ac84892-68ab-4a8d-8fd9-33304174c2b0Cited by top-tier papers2
- FedREDefense: Defending against Model Poisoning Attacks for Federated Learning using Model Update Reconstruction ErrorYueqi Xie, Minghong Fang, Neil Zhenqiang GongICML 2024 · 32 citations
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun et al.NDSS 2025
Builds on16
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 293 citations
- Learning from History for Byzantine Robust OptimizationSai Praneeth Karimireddy, Lie He, Martin JaggiICML 2021 · 247 citations
- FedFast: Going Beyond Average for Faster Training of Federated Recommender SystemsKhalil Muhammad, Qinqin Wang, Diarmuid O'Reilly-Morgan, Elias Z. Tragos et al.KDD 2020 · 215 citations
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 126 citations
Related papers
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen et al.ICDE 2022 · 76 citations
- Preventing the Popular Item Embedding Based Attack in Federated RecommendationsJun Zhang, Huan Li, Dazhong Rong, Yan Zhao et al.ICDE 2024 · 7 citations
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen et al.SIGIR 2023 · 46 citations
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu et al.CCS 2024 · 4 citations
- Spattack: Subgroup Poisoning Attacks on Federated Recommender SystemsBo Yan, Yurong Hao, Dingqi Liu, Huabin Sun et al.WWW 2026
