Spattack: Subgroup Poisoning Attacks on Federated Recommender Systems
Bo Yan, Yurong Hao, Dingqi Liu, Huabin Sun, Pengpeng Qiao, Wei Yang Bryan Lim, Yang Cao, Chuan Shi
摘要
Federated recommender systems (FedRec) have emerged as a promising approach to provide personalized recommendations while protecting user privacy. However, recent studies have demonstrated their vulnerability to poisoning attacks, wherein malicious clients can inject carefully crafted gradients to prompt target items to benign users. Existing attacks typically target the full user group, which compromises stealth and increases the risk of detection. In contrast, real-world adversaries may prefer to target specific user subgroup, such as promoting health supplements to older individual, to maximize attack success while preserving stealth to evade detection. Motivated by this gap, we introduce Spattack, the first poisoning attack designed to manipulate recommendations for specific user subgroups in federated setting. Specifically, Spattack adopts an approximate-and-promote paradigm, which first approximate user embeddings of target/non-target subgroups and then prompts target items to the target subgroups. We further reveal a trade-off in achieving strong attack performance on the target group while keeping the non-target group largely unaffected. To achieve a better trade-off, we propose enhanced approximation and promotion strategies. For the approximation, we push the embeddings of different subgroup away based on contrastive learning and augment the target group's relevant item set via clustering. For the promotion, we align target and relevant item embeddings to strengthen their semantic connections. An adaptive weighting strategy is further proposed to balance promotion effects between target and non-target subgroups. Experiments on three real-world datasets demonstrate that Spattack consistently achieves strong attack performance on the target subgroup with minimal impact on non-target users, even when only 0.1% of users are malicious. Moreover, Spattack maintains competitive recommendation performance and exhibits strong resilience against mainstream defenses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper15
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li 等SIGIR 2020 · 被引用 4,448 次
- Efficient Heterogeneous Collaborative Filtering without Negative Sampling for RecommendationChong Chen, Min Zhang, Yongfeng Zhang, Weizhi Ma 等AAAI 2020 · 被引用 185 次
- FedRec++: Lossless Federated Recommendation with Explicit FeedbackFeng Liang, Weike Pan, Zhong MingAAAI 2021 · 被引用 152 次
- Neural Interactive Collaborative FilteringLixin Zou, Long Xia, Yulong Gu, Xiangyu Zhao 等SIGIR 2020 · 被引用 121 次
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu 等ICDE 2020 · 被引用 83 次
相关 Paper
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu 等AAAI 2023 · 被引用 73 次
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen 等SIGIR 2023 · 被引用 46 次
- Revisit Targeted Model Poisoning on Federated Recommendation: Optimize via Multi-objective TransportJiajie Su, Chaochao Chen, Weiming Liu, Zibin Lin 等SIGIR 2024 · 被引用 10 次
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu 等CCS 2024 · 被引用 4 次
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 被引用 32 次
