[논문 리뷰] Graph Embedding for Recommendation against Attribute Inference Attacks
GERAI는 국소적 차별적 프라이버시(LDP)와 기능 메커니즘을 적용하여 사용자 특징과 모델 기울기를 모두 흐리게 함으로써 속성 유추 공격에 대비하는 차별적 프라이버시 보장 기반 그래프 컬러이션 네트워크(GCN) 추천 시스템을 제안한다. 이는 추천 정확도를 희생시키지 않은 채 강력한 프라이버시 보호를 달성하며, 공격 저항성과 유틸리티 측면에서 기존 방법들을 능가한다.
In recent years, recommender systems play a pivotal role in helping users identify the most suitable items that satisfy personal preferences. As user-item interactions can be naturally modelled as graph-structured data, variants of graph convolutional networks (GCNs) have become a well-established building block in the latest recommenders. Due to the wide utilization of sensitive user profile data, existing recommendation paradigms are likely to expose users to the threat of privacy breach, and GCN-based recommenders are no exception. Apart from the leakage of raw user data, the fragility of current recommenders under inference attacks offers malicious attackers a backdoor to estimate users' private attributes via their behavioral footprints and the recommendation results. However, little attention has been paid to developing recommender systems that can defend such attribute inference attacks, and existing works achieve attack resistance by either sacrificing considerable recommendation accuracy or only covering specific attack models or protected information. In our paper, we propose GERAI, a novel differentially private graph convolutional network to address such limitations. Specifically, in GERAI, we bind the information perturbation mechanism in differential privacy with the recommendation capability of graph convolutional networks. Furthermore, based on local differential privacy and functional mechanism, we innovatively devise a dual-stage encryption paradigm to simultaneously enforce privacy guarantee on users' sensitive features and the model optimization process. Extensive experiments show the superiority of GERAI in terms of its resistance to attribute inference attacks and recommendation effectiveness.
연구 동기 및 목표
- GCN 기반 추천 시스템이 상호작용 이력과 추천 결과로부터 민감한 사용자 속성을 유추당할 수 있는 취약성을 해결하기 위해.
- 원시 사용자 특징과 모델 최적화 과정을 모두 보호하면서 추천 성능 저하 없이 프라이버시 보존 추천 프레임워크를 개발하기 위해.
- 차별적 프라이버시와 그래프 신경망 간 격차를 메우기 위해 수학적 프라이버시 보장을 보장하기 위해.
- 이전 연구들이 정확도를 희생하거나 특정 공격 모델 또는 데이터 유형에 대해서만 방어하는 등의 한계를 극복하기 위해.
제안 방법
- GERAI는 사용자 특징을 모델 훈련 이전에 국소적 차별적 프라이버시(LDP)를 적용하여 민감한 속성의 프라이버시를 보장한다.
- 최적화 과정 중 모델 기울기에 보정된 노이즈를 추가하기 위해 기능 메커니즘을 활용하여 훈련 과정을 속성 유추 공격으로부터 보호한다.
- 이중 단계 암호화 파라다임을 설계함: 첫 번째로 사용자 특징을 LDP를 통해 흐리게 하고, 두 번째로 기능 메커니즘 기반 노이즈 주입을 통해 모델 업데이트를 보호한다.
- 편향된 그러나 의미적으로 유의미한 데이터로부터 학습함으로써 사용자 선호 표현을 유지함으로써 추천 유틸리티를 유지한다.
- 입력 특징과 모델 파라미터 양쪽에 대해 차별적 프라이버시를 공식적으로 적용하여 (ε, δ)-DP 프레임워크 하에 엄격한 프라이버시 보장을 확보한다.
- 추천 정확도와 프라이버시 제약 조건을 균형 잡는 가중 가능한 손실 함수를 사용해 종단 간(end-to-end)으로 프레임워크를 훈련한다.
실험 결과
연구 질문
- RQ1GCN 기반 추천 시스템이 추천 정확도에 상당한 손실 없이 속성 유추 공격에 강건하게 만들 수 있는가?
- RQ2그래프 기반 추천 환경에서 사용자 특징과 모델 기울기에 차별적 프라이버시를 효과적으로 적용할 수 있는가?
- RQ3특징과 기울기 양쪽에 대한 이중 단계 흐림 처리가 그래프 추천 시스템에서 프라이버시-유틸리티 트레이드오프에 어떤 영향을 미치는가?
- RQ4국소적 차별적 프라이버시와 기능 메커니즘을 조합하여 협업 필터링 환경에서 강력하고 수학적으로 탄탄한 프라이버시 보장을 제공할 수 있는가?
주요 결과
- GERAI는 기준 방법들에 비해 속성 유추 공격에 뛰어난 저항성을 보이며, 공격자가 민감한 속성을 유추하는 데 성공할 확률을 크게 감소시켰다.
- 모델은 비공개 GCN 기준 방법들과 비교해도 높은 추천 정확도를 유지하며, 효과적인 프라이버시-유틸리티 트레이드오프를 입증했다.
- 이중 단계 흐림 처리 메커니즘—특징에 LDP 적용, 기울기에 기능 메커니즘 적용—이 사용자 데이터와 모델 최적화 과정을 모두 효과적으로 보호하는 것으로 입증되었다.
- 실험 결과, GERAI는 기존의 프라이버시 보존 추천 시스템보다 프라이버시 보호 능력과 추천 효과성 측면에서 모두 뛰어난 성능을 보였다.
더 나은 연구,지금 바로 시작하세요
논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.
카드 등록 없음 · 무료 플랜 제공
이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.