Collaborative-learning based recommender systems emerged following the success of collaborative learning techniques such as Federated Learning (FL) and Gossip Learning (GL). In these systems, users participate in the training of a recommender system while keeping their history of consumed items on their devices. While these solutions seemed appealing for preserving the privacy of the participants at a first glance, recent studies have shown that collaborative learning can be vulnerable to a variety of privacy attacks. In this paper we propose a novel privacy attack called Community Detection Attack (CDA), which allows an adversary to discover the members of a community based on a set of items of her choice (e.g., discovering users interested in LGBT content). Through experiments on three real recommendation datasets and by using two state-of-the-art recommendation models, we assess the sensitivity of an FL-based recommender system as well as two flavors of Gossip Learning-based recommender systems to CDA. Results show that on all models and all datasets, the FL setting is more vulnerable to CDA than Gossip settings. We further evaluated two off-the-shelf mitigation strategies, namely differential privacy (DP) and a share less policy, which consists in sharing a subset of model parameters. Results show a better privacy-utility trade-off for the share less policy compared to DP especially in the Gossip setting.
翻译:基于协作学习的推荐系统在联邦学习(FL)和八卦学习(GL)等协作学习技术成功应用后应运而生。在这类系统中,用户参与推荐系统的训练,同时将其消费项目历史保留在本地设备上。尽管这些方案乍看之下对保护参与者隐私颇具吸引力,但近期研究表明协作学习可能面临多种隐私攻击的威胁。本文提出一种名为社区发现攻击(CDA)的新型隐私攻击方法,该方法允许攻击者根据其选定的项目集(例如发现对LGBT内容感兴趣的用户)来识别社区成员。通过在三个真实推荐数据集上使用两种先进的推荐模型进行实验,我们评估了基于FL的推荐系统以及两种基于八卦学习的推荐系统对CDA的敏感程度。结果表明,在所有模型和数据集上,FL场景比八卦场景更易受到CDA攻击。我们进一步评估了两种现成的缓解策略:差分隐私(DP)和参数共享缩减策略(即共享部分模型参数)。结果显示,与DP相比,参数共享缩减策略在隐私-效用权衡方面表现更优,尤其是在八卦学习场景中。