Poisoning Deep Learning Based Recommender Model in Federated Learning Scenarios

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Rong, Dazhong, He, Qinming, Chen, Jianhai
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911256361828352
author Rong, Dazhong
He, Qinming
Chen, Jianhai
author_facet Rong, Dazhong
He, Qinming
Chen, Jianhai
contents Various attack methods against recommender systems have been proposed in the past years, and the security issues of recommender systems have drawn considerable attention. Traditional attacks attempt to make target items recommended to as many users as possible by poisoning the training data. Benifiting from the feature of protecting users' private data, federated recommendation can effectively defend such attacks. Therefore, quite a few works have devoted themselves to developing federated recommender systems. For proving current federated recommendation is still vulnerable, in this work we probe to design attack approaches targeting deep learning based recommender models in federated learning scenarios. Specifically, our attacks generate poisoned gradients for manipulated malicious users to upload based on two strategies (i.e., random approximation and hard user mining). Extensive experiments show that our well-designed attacks can effectively poison the target models, and the attack effectiveness sets the state-of-the-art.
format Preprint
id arxiv_https___arxiv_org_abs_2204_13594
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Poisoning Deep Learning Based Recommender Model in Federated Learning Scenarios
Rong, Dazhong
He, Qinming
Chen, Jianhai
Information Retrieval
Cryptography and Security
Machine Learning
Various attack methods against recommender systems have been proposed in the past years, and the security issues of recommender systems have drawn considerable attention. Traditional attacks attempt to make target items recommended to as many users as possible by poisoning the training data. Benifiting from the feature of protecting users' private data, federated recommendation can effectively defend such attacks. Therefore, quite a few works have devoted themselves to developing federated recommender systems. For proving current federated recommendation is still vulnerable, in this work we probe to design attack approaches targeting deep learning based recommender models in federated learning scenarios. Specifically, our attacks generate poisoned gradients for manipulated malicious users to upload based on two strategies (i.e., random approximation and hard user mining). Extensive experiments show that our well-designed attacks can effectively poison the target models, and the attack effectiveness sets the state-of-the-art.
title Poisoning Deep Learning Based Recommender Model in Federated Learning Scenarios
topic Information Retrieval
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2204.13594