Graph Embedding for Recommendation against Attribute Inference Attacks
Shijie Zhang, Hongzhi Yin, Tong Chen, Zi Huang, Lizhen Cui, Xiangliang Zhang
摘要
In recent years, recommender systems play a pivotal role in helping users identify the most suitable items that satisfy personal preferences. As user-item interactions can be naturally modelled as graph-structured data, variants of graph convolutional networks (GCNs) have become a well-established building block in the latest recommenders. Due to the wide utilization of sensitive user profile data, existing recommendation paradigms are likely to expose users to the threat of privacy breach, and GCN-based recommenders are no exception. Apart from the leakage of raw user data, the fragility of current recommenders under inference attacks offers malicious attackers a backdoor to estimate users' private attributes via their behavioral footprints and the recommendation results. However, little attention has been paid to developing recommender systems that can defend such attribute inference attacks, and existing works achieve attack resistance by either sacrificing considerable recommendation accuracy or only covering specific attack models or protected information. In our paper, we propose GERAI, a novel differentially private graph convolutional network to address such limitations. Specifically, in GERAI, we bind the information perturbation mechanism in differential privacy with the recommendation capability of graph convolutional networks. Furthermore, based on local differential privacy and functional mechanism, we innovatively devise a dual-stage encryption paradigm to simultaneously enforce privacy guarantee on users' sensitive features and the model optimization process. Extensive experiments show the superiority of GERAI in terms of its resistance to attribute inference attacks and recommendation effectiveness. CCS CONCEPTS • Information systems → Collaborative filtering.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper18
- Interaction-level Membership Inference Attack Against Federated Recommender SystemsWei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui 等WWW 2023 · 被引用 101 次
- Semi-decentralized Federated Ego Graph Learning for RecommendationLiang Qu, Ningzhi Tang, Ruiqi Zheng, Quoc Viet Hung Nguyen 等WWW 2023 · 被引用 71 次
- Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagationSixiao Zhang, Hongxu Chen, Xiangguo Sun, Yicong Li 等WWW 2022 · 被引用 52 次
- Thinking inside The Box: Learning Hypercube Representations for Group RecommendationTong Chen, Hongzhi Yin, Jing Long, Quoc Viet Hung Nguyen 等SIGIR 2022 · 被引用 52 次
- Towards Personalized Privacy: User-Governed Data Contribution for Federated RecommendationLiang Qu, Wei Yuan, Ruiqi Zheng, Lizhen Cui 等WWW 2024 · 被引用 44 次
它引用的顶会 Paper5
- Locally Differentially Private Protocols for Frequency EstimationTianhao Wang, Jeremiah Blocki, Ninghui Li, Somesh JhaUSENIX Security 2017 · 被引用 629 次
- Self-Supervised Hypergraph Convolutional Networks for Session-based RecommendationXin Xia, Hongzhi Yin, Junliang Yu, Qinyong Wang 等AAAI 2021 · 被引用 615 次
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen 等SIGIR 2020 · 被引用 163 次
- You Are Who You Know and How You Behave: Attribute Inference Attacks via Users' Social Friends and BehaviorsNeil Zhenqiang Gong, Bin LiuUSENIX Security 2016 · 被引用 156 次
- Next Point-of-Interest Recommendation on Resource-Constrained Mobile DevicesQinyong Wang, Hongzhi Yin, Tong Chen, Zi Huang 等WWW 2020 · 被引用 116 次
相关 Paper
- GCON: Differentially Private Graph Convolutional Network via Objective PerturbationJianxin Wei, Yizheng Zhu, Xiaokui Xiao, Ergute Bao 等ICDE 2025 · 被引用 2 次
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu 等CCS 2023 · 被引用 9 次
- Defending against Attribute Inference Attacks in Post-Training of Recommendation Systems via UnlearningWenhan Wu, Yili Gong, Jiawei Jiang, Chuang Hu 等ICDE 2025 · 被引用 1 次
- Safeguarding Graph Neural Networks against Topology Inference AttacksJie Fu, Yuan Hong, Zhili Chen, Wendy Hui WangCCS 2025
- Aegis: Post-Training Attribute Unlearning in Federated Recommender Systems against Attribute Inference AttacksWenhan Wu, Jiawei Jiang, Chuang HuWWW 2025 · 被引用 4 次
