Data-Free Model Extraction for Black-box Recommender Systems via Graph Convolutions
Zeyu Wang, Yidan Song, Shihao Qin, Shanqing Yu, Yujin Huang, Qi Xuan, Xin Zheng
Abstract
Privacy and security concerns are becoming increasingly critical for recommender systems, as model extraction attack provides an effective way to probe system robustness by replicating the model’s recommendation logic — potentially exposing sensitive user preferences and proprietary algorithmic knowledge. Despite the promising performance of existing model extraction methods, they still face two key challenges: unrealistic assumptions on the requirement of accessible member or surrogate data and generalization problem where surrogate model architecture constraints lead to overfitting on generated data. To tackle these challenges, in this paper, we first thoroughly analyze how the architecture of surrogate models influences extraction attack performance, highlighting the superior effectiveness of the graph convolution architecture. Based on this, we propose a novel D ata-free B lack-box G raph convolution-based R ecommender M odel E xtraction method, dubbed DBGRME . Specifically, DBGRME contains: (1) an interaction generator to alleviate the need for member data requirements in a data-free scenario; and (2) a generalization-aware graph convolution-based surrogate model to capture diverse and complex recommender interaction patterns for mitigating the overfitting issue. Experimental results on various datasets and victim models demonstrate the superiority of our attack in data-free scenarios (e.g., surpassing PTQ data-require methods with 17 . 4% improvement on LightGCN). Code is available: https://github.com/Vencent-Won/DBGRME.git .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext fbe73ee5-c5a8-47fd-9a1e-df5e49c5fddbBuilds on9
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- Nonuniform-to-Uniform Quantization: Towards Accurate Quantization via Generalized Straight-Through EstimationZechun Liu, Kwang-Ting Cheng, Dong Huang, Eric P. Xing et al.CVPR 2022 · 108 citations
- Towards Data-Free Model Stealing in a Hard Label SettingSunandini Sanyal, Sravanti Addepalli, R. Venkatesh BabuCVPR 2022 · 76 citations
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Training-free Lexical Backdoor Attacks on Language ModelsYujin Huang, Terry Yue Zhuo, Qiongkai Xu, Han Hu et al.WWW 2023 · 56 citations
Related papers
- Sim4Rec: Data-Free Model Extraction Attack on Sequential RecommendationYihao Wang, Jiajie Su, Chaochao Chen, Meng Han et al.AAAI 2025 · 7 citations
- Data-Free Model ExtractionJean-Baptiste Truong, Pratyush Maini, Robert J. Walls, Nicolas PapernotCVPR 2021
- Unveiling the Secrets without Data: Can Graph Neural Networks Be Exploited through Data-Free Model Extraction Attacks?Yuanxin Zhuang, Chuan Shi, Mengmei Zhang, Jinghui Chen et al.USENIX Security 2024 · 11 citations
- Revisiting Black-box Ownership Verification for Graph Neural NetworksRuikai Zhou, Kang Yang, Xiuling Wang, Wendy Hui Wang et al.S&P 2024 · 5 citations
- Let Graph Be the Go Board: Gradient-Free Node Injection Attack for Graph Neural Networks via Reinforcement LearningMingxuan Ju, Yujie Fan, Chuxu Zhang, Yanfang YeAAAI 2023 · 48 citations
