News recommendation is critical for personalized news distribution. Federated news recommendation enables collaborative model learning from many clients without sharing their raw data. It is promising for privacy-preserving news recommendation. However, the security of federated news recommendation is still unclear. In this paper, we study this problem by proposing an untargeted attack called UA-FedRec. By exploiting the prior knowledge of news recommendation and federated learning, UA-FedRec can effectively degrade the model performance with a small percentage of malicious clients. First, the effectiveness of news recommendation highly depends on user modeling and news modeling. We design a news similarity perturbation method to make representations of similar news farther and those of dissimilar news closer to interrupt news modeling, and propose a user model perturbation method to make malicious user updates in opposite directions of benign updates to interrupt user modeling. Second, updates from different clients are typically aggregated by weighted-averaging based on their sample sizes. We propose a quantity perturbation method to enlarge sample sizes of malicious clients in a reasonable range to amplify the impact of malicious updates. Extensive experiments on two real-world datasets show that UA-FedRec can effectively degrade the accuracy of existing federated news recommendation methods, even when defense is applied. Our study reveals a critical security issue in existing federated news recommendation systems and calls for research efforts to address the issue.
翻译:新闻推荐对于个性化新闻分发至关重要。联邦新闻推荐能够在无需共享客户端原始数据的情况下,协同多个客户端进行模型学习,在隐私保护的新闻推荐领域极具前景。然而,联邦新闻推荐的安全性尚不明确。本文通过提出一种名为UA-FedRec的未目标攻击来研究该问题。通过利用新闻推荐与联邦学习的先验知识,UA-FedRec能够以少量恶意客户端有效降低模型性能。首先,新闻推荐的效果高度依赖于用户建模与新闻建模。我们设计了新闻相似度扰动方法,使相似新闻的表示距离更远、非相似新闻的表示距离更近,从而干扰新闻建模;同时提出用户模型扰动方法,使恶意用户更新方向与良性更新方向相反,以干扰用户建模。其次,不同客户端的更新通常基于样本量进行加权平均聚合。我们提出数量扰动方法,在合理范围内放大恶意客户端的样本量,以增强恶意更新的影响。在两个真实数据集上的大量实验表明,即使采用防御机制,UA-FedRec仍能有效降低现有联邦新闻推荐方法的准确率。本研究揭示了现有联邦新闻推荐系统中的关键安全问题,亟需研究予以应对。