Manipulation and Destruction: A Novel Hybrid Poisoning Attack Against Federated Recommender Systems

Ziyi Wang, Liyuan Liu · 2024

Due to its ability to protect privacy, federated recommender systems have received widespread attention. Federated recommender systems collaboratively learn recommendation models without sharing user data, effectively preserving privacy. In recent years, researchers have not only focused on improving recommendation efficiency, but also begun to pay attention to security issues of federated recommendations. Since all clients can upload gradients to train the model, adversaries can also exploit this property to carry out poisoning attacks. However, research on attacks against federated recommendation is still incomplete, and attackers need to rely on excessive prior knowledge and manipulate a large number of malicious ellen ts. In addition, existing research only focuses on a single attack method and objective. To reveal the vulnerability of federated recommender systems, we propose a novel hybrid attack called FedRecHP A.It can attack recommender systems without relying on any prior knowledge, achieving the goal of manipulating and destroying recommendation systems. We conducted extensive experiments on two real-world datasets. The results indicate that our proposed method can effectively attack recommender systems, even if we manipulate a small proportion of fake users.

Read the paper · More papers on PaperTik