Comprehensive Privacy Analysis on Recommendation With Causal Embedding Against Model Inversion Attacks
Hanyang Liu, Yong Wang, Zhiqiang Zhang, Jiangzhou Deng, Yongdong Wang · IEEE Transactions on Big Data · 2025
In recommendation systems, the interactions between users and items are influenced by two factors: the user's conformity towards popular items and the user's real interest. Training individual user embeddings and item embeddings to capture these two factors can effectively improve the accuracy of recommendations. However, recommendation systems often exchange item embeddings with third-party servers, which may expose sensitive information to malicious attackers. Specifically, attackers can infer sensitive user information based on published item embeddings and partial public user information. In this paper, we first design a model inversion attack to analyze the influence of conformity item embeddings and interest item embeddings on privacy. This analysis reveals that different item embeddings have varying resistances against inversion attack. Based on the resistance levels of the two item embeddings, we propose a novel adaptive differential privacy protection method that enhances resistance against model inversion attacks while ensuring recommendation accuracy. We conduct experiments on three real datasets, and the results demonstrate the outstanding performance of our method in terms of both recommendation accuracy and resistance to inversion attack.