Defending against Attribute Inference Attacks in Post-Training of Recommendation Systems via Unlearning
Wenhan Wu, Yili Gong, Jiawei Jiang, Chuang Hu, Xiaobo Zhou, Dazhao Cheng
Abstract
Attribute Inference Attacks (AIAs) pose a significant threat to recommendation systems (RS) by enabling adversaries to use threat models to infer sensitive user attributes like gender or race from user embeddings, resulting in privacy breaches such as unauthorized profiling and discriminatory policies against specific groups. Existing attribute protection methods are primarily applied during training, suffering from significant limitations, such as architectural inflexibility, dependence on interaction data, and potential catastrophic degradation in recommendation performance. To overcome these challenges, we propose AttrCloak, an efficient and effective post-training attribute unlearning (AU) framework that removes sensitive information from user embeddings without altering RS training architectures. AttrCloak employs dual-objective optimization with parameter self-sharing to minimize mutual information between user embeddings and sensitive attributes while preserving recommendation quality. Furthermore, it accommodates data-free scenarios by leveraging regularization loss when interaction data is unavailable. Comprehensive evaluations on four real-world datasets demonstrate AttrCloak's good performance in privacy protection and recommendation performance.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 641e2103-22f9-411a-bcaa-be338f714e19Related papers
- Making Users Indistinguishable: Attribute-wise Unlearning in Recommender SystemsYuyuan Li, Chaochao Chen, Xiaolin Zheng, Yizhao Zhang et al.ACM MM 2023 · 26 citations
- Aegis: Post-Training Attribute Unlearning in Federated Recommender Systems against Attribute Inference AttacksWenhan Wu, Jiawei Jiang, Chuang HuWWW 2025 · 4 citations
- Plug and Play: Enabling Pluggable Attribute Unlearning in Recommender SystemsXiaohua Feng, Yuyuan Li, Fengyuan Yu, Li Zhang et al.WWW 2025 · 5 citations
- FedAU2: Attribute Unlearning for User-Level Federated Recommender Systems with Adaptive and Robust Adversarial TrainingYuyuan Li, Junjie Fang, Fengyuan Yu, Xichun Sheng et al.AAAI 2026 · 1 citation
- LEGO: A Lightweight and Efficient Multiple-Attribute Unlearning Framework for Recommender SystemsFengyuan Yu, Yuyuan Li, Xiaohua Feng, Junjie Fang et al.ACM MM 2025 · 3 citations
