Inferring Communities of Interest in Collaborative Learning-based Recommender Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Belal, Yacine, Mokhtar, Sonia Ben, Maouche, Mohamed, Simonet-Boulogne, Anthony
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916689455611904
author Belal, Yacine
Mokhtar, Sonia Ben
Maouche, Mohamed
Simonet-Boulogne, Anthony
author_facet Belal, Yacine
Mokhtar, Sonia Ben
Maouche, Mohamed
Simonet-Boulogne, Anthony
contents Collaborative-learning-based recommender systems, such as those employing Federated Learning (FL) and Gossip Learning (GL), allow users to train models while keeping their history of liked items on their devices. While these methods were seen as promising for enhancing privacy, recent research has shown that collaborative learning can be vulnerable to various privacy attacks. In this paper, we propose a novel attack called Community Inference Attack (CIA), which enables an adversary to identify community members based on a set of target items. What sets CIA apart is its efficiency: it operates at low computational cost by eliminating the need for training surrogate models. Instead, it uses a comparison-based approach, inferring sensitive information by comparing users' models rather than targeting any specific individual model. To evaluate the effectiveness of CIA, we conduct experiments on three real-world recommendation datasets using two recommendation models under both Federated and Gossip-like settings. The results demonstrate that CIA can be up to 10 times more accurate than random guessing. Additionally, we evaluate two mitigation strategies: Differentially Private Stochastic Gradient Descent (DP-SGD) and a Share less policy, which involves sharing fewer, less sensitive model parameters. Our findings suggest that the Share less strategy offers a better privacy-utility trade-off, especially in GL.
format Preprint
id arxiv_https___arxiv_org_abs_2306_08929
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Inferring Communities of Interest in Collaborative Learning-based Recommender Systems
Belal, Yacine
Mokhtar, Sonia Ben
Maouche, Mohamed
Simonet-Boulogne, Anthony
Information Retrieval
Cryptography and Security
Machine Learning
Social and Information Networks
H.3.3; I.2.6; I.2.11; K.6.5
Collaborative-learning-based recommender systems, such as those employing Federated Learning (FL) and Gossip Learning (GL), allow users to train models while keeping their history of liked items on their devices. While these methods were seen as promising for enhancing privacy, recent research has shown that collaborative learning can be vulnerable to various privacy attacks. In this paper, we propose a novel attack called Community Inference Attack (CIA), which enables an adversary to identify community members based on a set of target items. What sets CIA apart is its efficiency: it operates at low computational cost by eliminating the need for training surrogate models. Instead, it uses a comparison-based approach, inferring sensitive information by comparing users' models rather than targeting any specific individual model. To evaluate the effectiveness of CIA, we conduct experiments on three real-world recommendation datasets using two recommendation models under both Federated and Gossip-like settings. The results demonstrate that CIA can be up to 10 times more accurate than random guessing. Additionally, we evaluate two mitigation strategies: Differentially Private Stochastic Gradient Descent (DP-SGD) and a Share less policy, which involves sharing fewer, less sensitive model parameters. Our findings suggest that the Share less strategy offers a better privacy-utility trade-off, especially in GL.
title Inferring Communities of Interest in Collaborative Learning-based Recommender Systems
topic Information Retrieval
Cryptography and Security
Machine Learning
Social and Information Networks
H.3.3; I.2.6; I.2.11; K.6.5
url https://arxiv.org/abs/2306.08929