Rethinking Byzantine Robustness in Federated Recommendation from Sparse Aggregation Perspective
Zhongjian Zhang, Mengmei Zhang, Xiao Wang, Lingjuan Lyu, Bo Yan, Junping Du, Chuan Shi
Abstract
To preserve user privacy in recommender systems, federated recommendation (FR) based on federated learning (FL) emerges, keeping the personal data on the local client and updating a model collaboratively. Unlike FL, FR has a unique sparse aggregation mechanism, where the embedding of each item is updated by only partial clients, instead of full clients in a dense aggregation of general FL. Recently, as an essential principle of FL, model security has received increasing attention, especially for Byzantine attacks, where malicious clients can send arbitrary updates. The problem of exploring the Byzantine robustness of FR is particularly critical since in the domains applying FR, e.g., e-commerce, malicious clients can be injected easily by registering new accounts. However, existing Byzantine works neglect the unique sparse aggregation of FR, making them unsuitable for our problem. Thus, we make the first effort to investigate Byzantine attacks on FR from the perspective of sparse aggregation, which is non-trivial: it is not clear how to define Byzantine robustness under sparse aggregations and design Byzantine attacks under limited knowledge/capability. In this paper, we reformulate the Byzantine robustness under sparse aggregation by defining the aggregation for a single item as the smallest execution unit. Then we propose a family of effective attack strategies, named Spattack, which exploit the vulnerability in sparse aggregation and are categorized along the adversary's knowledge and capability. Extensive experimental results demonstrate that Spattack can effectively prevent convergence and even break down defenses under a few malicious clients, raising alarms for securing FR systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bf71e641-6bbc-45db-9dad-b4defa1e2b5eCited by top-tier papers3
- Spattack: Subgroup Poisoning Attacks on Federated Recommender SystemsBo Yan, Yurong Hao, Dingqi Liu, Huabin Sun et al.WWW 2026
- Toward Graph-Tokenizing Large Language Models with Reconstructive Graph Instruction TuningZhongjian Zhang, Xiao Wang, Mengmei Zhang, Jiarui Tan et al.WWW 2026
- Bridging Semantic Understanding and Popularity Bias with LLMsRenqiang Luo, Dong Zhang, Yupeng Gao, Wen Shi et al.WWW 2026
Builds on11
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Unlearning Concepts in Diffusion Model via Concept Domain Correction and Concept Preserving GradientYongliang Wu, Shiji Zhou, Mingzhuo Yang, Lianzhe Wang et al.AAAI 2025 · 69 citations
- Federated Heterogeneous Graph Neural Network for Privacy-preserving RecommendationBo Yan, Yang Cao, Haoyu Wang, Wenchuan Yang et al.WWW 2024 · 62 citations
- Robust Heterogeneous Graph Neural Networks against Adversarial AttacksMengmei Zhang, Xiao Wang, Meiqi Zhu, Chuan Shi et al.AAAI 2022 · 55 citations
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen et al.SIGIR 2023 · 46 citations
Related papers
- Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated LearningYuchen Liu, Chen Chen, Lingjuan Lyu, Yaochu Jin et al.AAAI 2025 · 3 citations
- zPROBE: Zero Peek Robustness Checks for Federated LearningZahra Ghodsi, Mojan Javaheripi, Nojan Sheybani, Xinqiao Zhang et al.ICCV 2023 · 27 citations
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
- Byzantine-Robust Learning on Heterogeneous Data via Gradient SplittingYuchen Liu, Chen Chen, Lingjuan Lyu, Fangzhao Wu et al.ICML 2023 · 27 citations
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen et al.ICDE 2022 · 76 citations
