Exposing Private User Behaviors of Collaborative Filtering via Model Inversion Techniques

Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, Goichiro Hanaoka · Proceedings on Privacy Enhancing Technologies · 2020

Abstract Privacy risks of collaborative filtering (CF) have been widely studied. The current state-of-theart inference attack on user behaviors (e.g., ratings/purchases on sensitive items) for CF is by Calandrino et al. (S&P, 2011). They showed that if an adversary obtained a moderate amount of user’s public behavior before some timeT, she can infer user’s private behavioraftertimeT. However, the existence of an attack that infers user’s private behaviorbefore Tremains open. In this paper, we propose the first inference attack that reveals past private user behaviors. Our attack departs from previous techniques and is based onmodel inversion(MI). In particular, we propose the first MI attack on factorization-based CF systems by leveraging data poisoning by Li et al. (NIPS, 2016) in a novel way. We inject malicious users into the CF system so that adversarialy chosen “decoy” items are linked with user’s private behaviors. We also show how to weaken the assumption made by Li et al. on the information available to the adversary from the whole rating matrix to only the item profile and how to create malicious ratings effectively. We validate the effectiveness of our inference algorithm using two real-world datasets.

Read the paper · More papers on PaperTik