Stronger privacy for federated collaborative filtering with implicit feedback
File(s) 2105.03941v2.pdf (570.92 KB)
Accepted version
Author(s)
Minto, Lorenzo
Haller, Moritz
Haddadi, Hamed
Livshits, Benjamin
Type
Conference Paper
Abstract
Recommender systems are commonly trained on centrally collected user
interaction data like views or clicks. This practice however raises serious
privacy concerns regarding the recommender's collection and handling of
potentially sensitive data. Several privacy-aware recommender systems have been
proposed in recent literature, but comparatively little attention has been
given to systems at the intersection of implicit feedback and privacy. To
address this shortcoming, we propose a practical federated recommender system
for implicit data under user-level local differential privacy (LDP). The
privacy-utility trade-off is controlled by parameters $\epsilon$ and $k$,
regulating the per-update privacy budget and the number of $\epsilon$-LDP
gradient updates sent by each user respectively. To further protect the user's
privacy, we introduce a proxy network to reduce the fingerprinting surface by
anonymizing and shuffling the reports before forwarding them to the
recommender. We empirically demonstrate the effectiveness of our framework on
the MovieLens dataset, achieving up to Hit Ratio with K=10 (HR@10) 0.68 on 50k
users with 5k items. Even on the full dataset, we show that it is possible to
achieve reasonable utility with HR@10>0.5 without compromising user privacy.
interaction data like views or clicks. This practice however raises serious
privacy concerns regarding the recommender's collection and handling of
potentially sensitive data. Several privacy-aware recommender systems have been
proposed in recent literature, but comparatively little attention has been
given to systems at the intersection of implicit feedback and privacy. To
address this shortcoming, we propose a practical federated recommender system
for implicit data under user-level local differential privacy (LDP). The
privacy-utility trade-off is controlled by parameters $\epsilon$ and $k$,
regulating the per-update privacy budget and the number of $\epsilon$-LDP
gradient updates sent by each user respectively. To further protect the user's
privacy, we introduce a proxy network to reduce the fingerprinting surface by
anonymizing and shuffling the reports before forwarding them to the
recommender. We empirically demonstrate the effectiveness of our framework on
the MovieLens dataset, achieving up to Hit Ratio with K=10 (HR@10) 0.68 on 50k
users with 5k items. Even on the full dataset, we show that it is possible to
achieve reasonable utility with HR@10>0.5 without compromising user privacy.
Date Issued
2021-09
Date Acceptance
2021-07-07
Citation
2021, pp.342-350
Publisher
ACM
Start Page
342
End Page
350
Copyright Statement
© 2021 Copyright held by the owner/author(s). Publication rights licensed to ACM.
Sponsor
Engineering & Physical Science Research Council (E
Engineering & Physical Science Research Council (EPSRC)
Engineering & Physical Science Research Council (EPSRC)
Engineering & Physical Science Research Council (E
Engineering & Physical Science Research Council (E
Engineering & Physical Science Research Council (E
Identifier
http://arxiv.org/abs/2105.03941v2
Grant Number
EP/R511547/1
EP/N028260/2
EP/R0222091/1
RGS128099 (EP/R03351X/1)
PO: 20232790 (Ref: 301671)
EP/V502354/1
Source
15th ACM Conference on Recommender Systems
Subjects
cs.LG
cs.LG
cs.CR
cs.MA
Notes
9 pages, 5 figures
Publication Status
Published
Start Date
2021-09-27
Finish Date
2021-10-01
Coverage Spatial
Amsterdam, Netherlands
Date Publish Online
2021-09-13
