Differential Privacy in Social Recommender Systems
Suchitha Malisetty, G. Sudha Sadasivam, Vani Kandasamy · 2025
Recommender systems search through large amounts of dynamically generated information to provide users with personalized content and services. But they suffer from the "Cold Start" problem where preferences of new users remain unknown to make recommendations. Web 2.0 provides us with social data of the users. Adopting the phenomenon of homophily, social information can be incorporated into the recommender systems to resolve the cold start problem. However, the preferences of users and their social information are vulnerable to privacy breaches, so, privacy-preserving mechanisms are required. K–Anonymity [1] is a widely used Anonymization mechanism. But it is vulnerable to various other attacks like attribute disclosure, background information attack, and homogeneity attacks. Differential privacy [2], the rigorous notion of privacy, can be incorporated into social recommender systems, ensuring the consistency of the outcome irrespective of the presence of a particular user’s sensitive data while training the models. Most of the state-of-the-art privacy preserving social recommenders work on the assumption that the central recommender server, which stores both user-user and user-item interactions in a centralized manner for training models, is trustworthy. But in case of an untrusted recommender, it may lead to a risk of sensitive user information getting leaked. This risk can be reduced by leveraging federated learning [3] into the social recommender systems thereby enabling data privacy. However, it is still possible to uncover user-specific preferences through locally learned weights. So, differential privacy mechanisms can be introduced into federated social recommender systems by perturbing the weights to ensure privacy in such a way that accuracy is also maintained.