Poisoning Decentralized Collaborative Recommender System and Its Countermeasures
Ruiqi Zheng, Liang Qu, Tong Chen, Kai Zheng, Yuhui Shi, Hongzhi Yin
摘要
To make room for privacy and efficiency, the deployment of many recommender systems is experiencing a shift from central servers to personal devices, where the federated recommender systems (FedRecs) and decentralized collaborative recommender systems (DecRecs) are arguably the two most representative paradigms. While both leverage knowledge (e.g., gradients) sharing to facilitate learning local models, FedRecs rely on a central server to coordinate the optimization process, yet in DecRecs, the knowledge sharing directly happens between clients. On the flip side, knowledge sharing also opens a backdoor for model poisoning attacks, where adversaries disguise themselves as benign clients and disseminate polluted knowledge to achieve malicious goals like promoting an item's exposure rate. Although research on such poisoning attacks provides valuable insights into finding security loopholes and corresponding countermeasures, existing attacks mostly focus on FedRecs, and are either inapplicable or ineffective for DecRecs. Compared with FedRecs where the tampered information can be universally distributed to all clients once uploaded to the cloud, each adversary in DecRecs can only communicate with neighbor clients of a small size, confining its impact to a limited range.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin 等KDD 2024 · 被引用 16 次
- Diversity-aware Dual-promotion Poisoning Attack on Sequential RecommendationYuchuan Zhao, Tong Chen, Junliang Yu, Kai Zheng 等SIGIR 2025 · 被引用 6 次
- ID-Free Not Risk-Free: LLM-Powered Agents Unveil Risks in ID-Free Recommender SystemsZongwei Wang, Min Gao, Junliang Yu, Xinyi Gao 等SIGIR 2025 · 被引用 4 次
它引用的顶会 Paper11
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 被引用 1,778 次
- Next Point-of-Interest Recommendation on Resource-Constrained Mobile DevicesQinyong Wang, Hongzhi Yin, Tong Chen, Zi Huang 等WWW 2020 · 被引用 116 次
- Interaction-level Membership Inference Attack Against Federated Recommender SystemsWei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui 等WWW 2023 · 被引用 101 次
- Distributed Distillation for On-Device LearningIlai Bistritz, Ariana J. Mann, Nicholas BambosNeurIPS 2020 · 被引用 97 次
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen 等ICDE 2022 · 被引用 76 次
相关 Paper
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen 等SIGIR 2023 · 被引用 46 次
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu 等AAAI 2023 · 被引用 73 次
- Preventing the Popular Item Embedding Based Attack in Federated RecommendationsJun Zhang, Huan Li, Dazhong Rong, Yan Zhao 等ICDE 2024 · 被引用 7 次
- Revisit Targeted Model Poisoning on Federated Recommendation: Optimize via Multi-objective TransportJiajie Su, Chaochao Chen, Weiming Liu, Zibin Lin 等SIGIR 2024 · 被引用 10 次
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu 等CCS 2024 · 被引用 4 次
