Poisoning Attacks Against Federated Recommender Systems and the Defenses: A Survey

Donglin Pan, Yifan Liu, Ziyi Wang, Yi Liu, Zhao Ze · 2025

Federated recommender systems (FedRecs) can effectively address the problem of information overload without using users' private data. Based on federated learning, FedRecs have achieved significant success in protecting user privacy. FedRecs allow users to train recommendation models locally and upload the trained gradients to the server, which effectively protect privacy. However, this decentralized learning paradigm also makes federated recommender systems vulnerable to poisoning attacks. Attackers can manipulate the recommendation results by poisoning local training datasets or uploading toxic gradients. This paper provides an overview of poisoning attacks against federated recommender systems, introducing them from three perspectives. Classify and discuss based on the purpose of the attacker, the prior knowledge of the attacker, and the method of the attack, respectively. In addition, we also summarize defense strategies and discuss future directions, offering a broader perspective for researchers in this field. In order to address the security issues in federated recommender systems, we need to continuously explore effective defense mechanisms to ensure the security of the system and provide users with reliable recommendation services.

Read the paper · More papers on PaperTik