Graph Embedding for Recommendation against Attribute Inference Attacks
Shijie Zhang, Hongzhi Yin, Tong Chen, Zi Huang, Lizhen Cui, Xiangliang Zhang
Abstract
In recent years, recommender systems play a pivotal role in helping users identify the most suitable items that satisfy personal preferences. As user-item interactions can be naturally modelled as graph-structured data, variants of graph convolutional networks (GCNs) have become a well-established building block in the latest recommenders. Due to the wide utilization of sensitive user profile data, existing recommendation paradigms are likely to expose users to the threat of privacy breach, and GCN-based recommenders are no exception. Apart from the leakage of raw user data, the fragility of current recommenders under inference attacks offers malicious attackers a backdoor to estimate users' private attributes via their behavioral footprints and the recommendation results. However, little attention has been paid to developing recommender systems that can defend such attribute inference attacks, and existing works achieve attack resistance by either sacrificing considerable recommendation accuracy or only covering specific attack models or protected information. In our paper, we propose GERAI, a novel differentially private graph convolutional network to address such limitations. Specifically, in GERAI, we bind the information perturbation mechanism in differential privacy with the recommendation capability of graph convolutional networks. Furthermore, based on local differential privacy and functional mechanism, we innovatively devise a dual-stage encryption paradigm to simultaneously enforce privacy guarantee on users' sensitive features and the model optimization process. Extensive experiments show the superiority of GERAI in terms of its resistance to attribute inference attacks and recommendation effectiveness. CCS CONCEPTS • Information systems → Collaborative filtering.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a6dedf53-9fa2-4aef-8db1-f3e81c465cd3Cited by top-tier papers18
- Interaction-level Membership Inference Attack Against Federated Recommender SystemsWei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui et al.WWW 2023 · 101 citations
- Semi-decentralized Federated Ego Graph Learning for RecommendationLiang Qu, Ningzhi Tang, Ruiqi Zheng, Quoc Viet Hung Nguyen et al.WWW 2023 · 71 citations
- Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagationSixiao Zhang, Hongxu Chen, Xiangguo Sun, Yicong Li et al.WWW 2022 · 52 citations
- Thinking inside The Box: Learning Hypercube Representations for Group RecommendationTong Chen, Hongzhi Yin, Jing Long, Quoc Viet Hung Nguyen et al.SIGIR 2022 · 52 citations
- Towards Personalized Privacy: User-Governed Data Contribution for Federated RecommendationLiang Qu, Wei Yuan, Ruiqi Zheng, Lizhen Cui et al.WWW 2024 · 44 citations
Builds on5
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 629 citations
- Self-Supervised Hypergraph Convolutional Networks for Session-based RecommendationXin Xia, Hongzhi Yin, Junliang Yu, Qinyong Wang et al.AAAI 2021 · 615 citations
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen et al.SIGIR 2020 · 163 citations
- You Are Who You Know and How You Behave: Attribute Inference Attacks via Users' Social Friends and BehaviorsNeil Zhenqiang Gong, Bin LiuUSENIX Security 2016 · 156 citations
- Next Point-of-Interest Recommendation on Resource-Constrained Mobile DevicesQinyong Wang, Hongzhi Yin, Tong Chen, Zi Huang et al.WWW 2020 · 116 citations
Related papers
- GCON: Differentially Private Graph Convolutional Network via Objective PerturbationJianxin Wei, Yizheng Zhu, Xiaokui Xiao, Ergute Bao et al.ICDE 2025 · 2 citations
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu et al.CCS 2023 · 9 citations
- Defending against Attribute Inference Attacks in Post-Training of Recommendation Systems via UnlearningWenhan Wu, Yili Gong, Jiawei Jiang, Chuang Hu et al.ICDE 2025 · 1 citation
- Safeguarding Graph Neural Networks against Topology Inference AttacksJie Fu, Yuan Hong, Zhili Chen, Wendy Hui WangCCS 2025
- Aegis: Post-Training Attribute Unlearning in Federated Recommender Systems against Attribute Inference AttacksWenhan Wu, Jiawei Jiang, Chuang HuWWW 2025 · 4 citations
