Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the Defense
Yang Yu, Qi Liu, Likang Wu, Runlong Yu, Sanshi Lei Yu, Zaixi Zhang
Abstract
Federated recommendation (FedRec) can train personalized recommenders without collecting user data, but the decentralized nature makes it susceptible to poisoning attacks. Most previous studies focus on the targeted attack to promote certain items, while the untargeted attack that aims to degrade the overall performance of the FedRec system remains less explored. In fact, untargeted attacks can disrupt the user experience and bring severe financial loss to the service provider. However, existing untargeted attack methods are either inapplicable or ineffective against FedRec systems. In this paper, we delve into the untargeted attack and its defense for FedRec systems. (i) We propose ClusterAttack, a novel untargeted attack method. It uploads poisonous gradients that converge the item embeddings into several dense clusters, which make the recommender generate similar scores for these items in the same cluster and perturb the ranking order. (ii) We propose a uniformity-based defense mechanism (UNION) to protect FedRec systems from such attacks. We design a contrastive learning task that regularizes the item embeddings toward a uniform distribution. Then the server filters out these malicious gradients by estimating the uniformity of updated item embeddings. Experiments on two public datasets show that ClusterAttack can effectively degrade the performance of Fe-dRec systems while circumventing many defense methods, and UNION can improve the resistance of the system against various untargeted attacks, including our ClusterAttack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 92db2520-88db-4a36-abef-e37fda7e942dCited by top-tier papers7
- Exploring Large Language Model for Graph Data Understanding in Online Job RecommendationsLikang Wu, Zhaopeng Qiu, Zhi Zheng, Hengshu Zhu et al.AAAI 2024 · 120 citations
- FedCSL: A Scalable and Accurate Approach to Federated Causal Structure LearningXianjie Guo, Kui Yu, Lin Liu, Jiuyong LiAAAI 2024 · 17 citations
- PPIDSG: A Privacy-Preserving Image Distribution Sharing Scheme with GAN in Federated LearningYuting Ma, Yuanzhi Yao, Xiaohua XuAAAI 2024 · 9 citations
- Rethinking Byzantine Robustness in Federated Recommendation from Sparse Aggregation PerspectiveZhongjian Zhang, Mengmei Zhang, Xiao Wang, Lingjuan Lyu et al.AAAI 2025 · 5 citations
- Data-Free Model Extraction for Black-box Recommender Systems via Graph ConvolutionsZeyu Wang, Yidan Song, Shihao Qin, Shanqing Yu et al.NeurIPS 2025 · 4 citations
Builds on11
- Understanding Contrastive Representation Learning through Alignment and Uniformity on the HypersphereTongzhou Wang, Phillip IsolaICML 2020 · 2,360 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 293 citations
- Provably Secure Federated Learning against Malicious ClientsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongAAAI 2021 · 161 citations
- FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client PerspectiveJingwei Sun, Ang Li, Louis DiValentin, Amin Hassanzadeh et al.NeurIPS 2021 · 131 citations
Related papers
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen et al.SIGIR 2023 · 46 citations
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu et al.CCS 2024 · 4 citations
- Spattack: Subgroup Poisoning Attacks on Federated Recommender SystemsBo Yan, Yurong Hao, Dingqi Liu, Huabin Sun et al.WWW 2026
- Revisit Targeted Model Poisoning on Federated Recommendation: Optimize via Multi-objective TransportJiajie Su, Chaochao Chen, Weiming Liu, Zibin Lin et al.SIGIR 2024 · 10 citations
- Preventing the Popular Item Embedding Based Attack in Federated RecommendationsJun Zhang, Huan Li, Dazhong Rong, Yan Zhao et al.ICDE 2024 · 7 citations
