Plug and Play: Enabling Pluggable Attribute Unlearning in Recommender Systems
Xiaohua Feng, Yuyuan Li, Fengyuan Yu, Li Zhang, Chaochao Chen, Xiaolin Zheng
Abstract
With the escalating privacy concerns in recommender systems, attribute unlearning has drawn widespread attention as an effective approach against attribute inference attacks. This approach focuses on unlearning users' privacy attributes to reduce the performance of attackers while preserving the overall effectiveness of recommendation. Current research attempts to achieve attribute unlearning through adversarial training and distribution alignment in the statistic setting. However, these methods often struggle in dynamic real-world environments, particularly when considering scenarios where unlearning requests are frequently updated. In this paper, we first identify three main challenges of current methods in dynamic environments, i.e., irreversible operation, low efficiency, and unsatisfied recommendation preservation. To overcome these challenges, we propose a Pluggable Attribute Unlearning framework, PAU. Upon receiving an unlearning request, PAU plugs an additional erasure module into the original model to achieve unlearning. This module can perform a reverse operation if the request is later withdrawn. To enhance the efficiency of unlearning, we introduce rate distortion theory and reduce the attack performance by maximizing the encoded bits required for users' embedding within the same class of the unlearned attribute and minimizing those for different classes, which eliminates the need to calculate the centroid distribution for alignment. We further preserve recommendation performance by constraining the compactness of the user embedding space around a reasonable flood level. Extensive experiments conducted on four real-world datasets and three mainstream recommendation models demonstrate the effectiveness of our proposed framework.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5ff2e20d-f596-4ba5-bb8b-4e20a94442d5Cited by top-tier papers3
- LEGO: A Lightweight and Efficient Multiple-Attribute Unlearning Framework for Recommender SystemsFengyuan Yu, Yuyuan Li, Xiaohua Feng, Junjie Fang et al.ACM MM 2025 · 3 citations
- FedAU2: Attribute Unlearning for User-Level Federated Recommender Systems with Adaptive and Robust Adversarial TrainingYuyuan Li, Junjie Fang, Fengyuan Yu, Xichun Sheng et al.AAAI 2026 · 1 citation
- Sharpness-Aware Minimization for Generalized Embedding Learning in Federated RecommendationFengyuan Yu, Xiaohua Feng, Yuyuan Li, Changwang Zhang et al.WWW 2026
Builds on13
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang et al.NDSS 2019 · 1,141 citations
- Certified Data Removal from Machine Learning ModelsChuan Guo, Tom Goldstein, Awni Y. Hannun, Laurens van der MaatenICML 2020 · 633 citations
- Remember What You Want to Forget: Algorithms for Machine UnlearningAyush Sekhari, Jayadev Acharya, Gautam Kamath, Ananda Theertha SureshNeurIPS 2021 · 516 citations
Related papers
- Making Users Indistinguishable: Attribute-wise Unlearning in Recommender SystemsYuyuan Li, Chaochao Chen, Xiaolin Zheng, Yizhao Zhang et al.ACM MM 2023 · 26 citations
- Defending against Attribute Inference Attacks in Post-Training of Recommendation Systems via UnlearningWenhan Wu, Yili Gong, Jiawei Jiang, Chuang Hu et al.ICDE 2025 · 1 citation
- Aegis: Post-Training Attribute Unlearning in Federated Recommender Systems against Attribute Inference AttacksWenhan Wu, Jiawei Jiang, Chuang HuWWW 2025 · 4 citations
- DA2-Unlearn: Dual-Adaptive Forget-Repair-Based Recommendation UnlearningHaocheng Dou, Tao Lian, Xuemeng Song, Pengjie RenKDD 2026
- Debiasing Learning for Membership Inference Attacks Against Recommender SystemsZihan Wang, Na Huang, Fei Sun, Pengjie Ren et al.KDD 2022 · 22 citations
