Poisoning Decentralized Collaborative Recommender System and Its Countermeasures
Ruiqi Zheng, Liang Qu, Tong Chen, Kai Zheng, Yuhui Shi, Hongzhi Yin
Abstract
To make room for privacy and efficiency, the deployment of many recommender systems is experiencing a shift from central servers to personal devices, where the federated recommender systems (FedRecs) and decentralized collaborative recommender systems (DecRecs) are arguably the two most representative paradigms. While both leverage knowledge (e.g., gradients) sharing to facilitate learning local models, FedRecs rely on a central server to coordinate the optimization process, yet in DecRecs, the knowledge sharing directly happens between clients. On the flip side, knowledge sharing also opens a backdoor for model poisoning attacks, where adversaries disguise themselves as benign clients and disseminate polluted knowledge to achieve malicious goals like promoting an item's exposure rate. Although research on such poisoning attacks provides valuable insights into finding security loopholes and corresponding countermeasures, existing attacks mostly focus on FedRecs, and are either inapplicable or ineffective for DecRecs. Compared with FedRecs where the tampered information can be universally distributed to all clients once uploaded to the cloud, each adversary in DecRecs can only communicate with neighbor clients of a small size, confining its impact to a limited range.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7bfc79c3-2e5b-4290-9b16-c328e28acf98Cited by top-tier papers3
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin et al.KDD 2024 · 16 citations
- Diversity-aware Dual-promotion Poisoning Attack on Sequential RecommendationYuchuan Zhao, Tong Chen, Junliang Yu, Kai Zheng et al.SIGIR 2025 · 6 citations
- ID-Free Not Risk-Free: LLM-Powered Agents Unveil Risks in ID-Free Recommender SystemsZongwei Wang, Min Gao, Junliang Yu, Xinyi Gao et al.SIGIR 2025 · 4 citations
Builds on11
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Next Point-of-Interest Recommendation on Resource-Constrained Mobile DevicesQinyong Wang, Hongzhi Yin, Tong Chen, Zi Huang et al.WWW 2020 · 116 citations
- Interaction-level Membership Inference Attack Against Federated Recommender SystemsWei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui et al.WWW 2023 · 101 citations
- Distributed Distillation for On-Device LearningIlai Bistritz, Ariana J. Mann, Nicholas BambosNeurIPS 2020 · 97 citations
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen et al.ICDE 2022 · 76 citations
Related papers
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen et al.SIGIR 2023 · 46 citations
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Preventing the Popular Item Embedding Based Attack in Federated RecommendationsJun Zhang, Huan Li, Dazhong Rong, Yan Zhao et al.ICDE 2024 · 7 citations
- Revisit Targeted Model Poisoning on Federated Recommendation: Optimize via Multi-objective TransportJiajie Su, Chaochao Chen, Weiming Liu, Zibin Lin et al.SIGIR 2024 · 10 citations
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu et al.CCS 2024 · 4 citations
