Eyes on Federated Recommendation: Targeted Poisoning with Competition and Its Mitigation

Yurong Hao,Xihui Chen,Wei Wang,Jiqiang Liu,Tao Li,Junyong Wang,Witold Pedrycz
DOI: https://doi.org/10.1109/tifs.2024.3488500
IF: 7.231
2024-01-01
IEEE Transactions on Information Forensics and Security
Abstract:Federated recommendation (FR) addresses privacy concerns in recommender systems by training a global model without requiring raw user data to leave individual devices. A server, known as the aggregator, integrates users’ local gradients and updates the global model parameters. However, FR is vulnerable to attacks where malicious users manipulate these updates, known as model poisoning attacks. In this work, we propose a new targeted attack called StairClimbing to promote specific items through model poisoning, and a new defence mechanism CrossEU. StairClimbing adopts a new strategy resembling stair climbing to enable target items to beat competitive items and increase their popularity level by level. Compared to prior attacks, StairClimbing guarantees balanced effectiveness , efficiency and stealthiness simultaneously. Our defence mechanism CrossEU leverages two patterns regarding the lists of items updated by benign users between iterative epochs. Extensive experiments on six real-world datasets demonstrate StairClimbing’s superiority across all three desirable attack properties, even with a small proportion of malicious users (1%). In addition, CrossEU effectively delays the impact of all tested attacks and even eliminates their damage entirely.
What problem does this paper attempt to address?