Aegis: Post-Training Attribute Unlearning in Federated Recommender Systems against Attribute Inference Attacks
Wenhan Wu, Jiawei Jiang, Chuang Hu
Abstract
As privacy concerns in recommender systems become increasingly prominent, federated recommender systems (FedRecs) have emerged as a promising distributed training paradigm.FedRecs enable the collaborative training of a shared global recommendation model without requiring the exchange of raw client interaction data.However, models trained using standard FedRec methods remain vulnerable to personal information leakage, particularly through attribute inference attacks, which can expose sensitive user attributes such as gender and race.In this paper, we address these user-sensitive attributes as targets for federated unlearning.To protect users' sensitive information, attribute unlearning aims to eliminate sensitive attributes from user embeddings, thereby preventing inference attacks while preserving recommendation performance.We introduce a novel post-training federated unlearning framework, Aegis, which performs unlearning based on private attribute requests after the model has been trained, minimizing the degradation in recommendation accuracy.Aegis employs an information-theoretic multi-component loss function to balance privacy protection and recommendation performance.Additionally, Aegis adapts to scenarios where training interaction data may be unavailable, reflecting real-world centralized protection scenarios.Comprehensive evaluations of various benchmark datasets demonstrate that our proposed method effectively safeguards user privacy while maintaining high-quality recommendations. CCS Concepts• Information systems → Social recommendation
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8e87ea95-65d1-4b2d-ad34-26deffb971a8Cited by top-tier papers1
Ask how each one uses itRelated papers
- Making Users Indistinguishable: Attribute-wise Unlearning in Recommender SystemsYuyuan Li, Chaochao Chen, Xiaolin Zheng, Yizhao Zhang et al.ACM MM 2023 · 26 citations
- Defending against Attribute Inference Attacks in Post-Training of Recommendation Systems via UnlearningWenhan Wu, Yili Gong, Jiawei Jiang, Chuang Hu et al.ICDE 2025 · 1 citation
- LEGO: A Lightweight and Efficient Multiple-Attribute Unlearning Framework for Recommender SystemsFengyuan Yu, Yuyuan Li, Xiaohua Feng, Junjie Fang et al.ACM MM 2025 · 3 citations
- Plug and Play: Enabling Pluggable Attribute Unlearning in Recommender SystemsXiaohua Feng, Yuyuan Li, Fengyuan Yu, Li Zhang et al.WWW 2025 · 5 citations
- Attribute Inference Attacks for Federated Regression TasksFrancesco Diana, Othmane Marfoq, Chuan Xu, Giovanni Neglia et al.AAAI 2025 · 2 citations
