Recommendation system preference forgetting method based on user angle
By constructing a two-layer optimization method of interactive perturbation matrix and attack target function in the recommendation system, the problem of low efficiency in forgetting user preferences in the existing technology is solved, and the target user information is efficiently forgotten without modifying the model structure, while maintaining the overall performance of the recommendation system and other user experiences.
Patent Information
- Application Number
- CN202511264121.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Existing methods for forgetting user preferences in recommendation systems are inefficient, complex to deploy, and highly dependent on model structure, making it difficult to completely forget target user information without affecting the user experience of other users.
By constructing an interaction perturbation matrix to add small perturbations to the black-box model, combined with the attack objective function, the model is guided to forget the preferences of a specified user while maintaining the recommendation quality for other users. The two-layer optimization training process does not require modification of the recommendation model structure.
It achieves efficient and low-overhead forgetting of target user preferences without retraining the model, while maintaining the overall performance of the recommendation system and other user experiences, which is suitable for black-box recommendation systems.
Smart Images

Figure CN120821891A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security and privacy protection of personalized recommendation systems, and specifically to a method for achieving preference forgetting by constructing a perturbation interaction matrix from the user's perspective without modifying the recommendation model system. Background Art
[0002] With the rapid development of the internet and mobile internet, personalized recommendation systems have become widely used in various online services, such as e-commerce platforms and short video applications. Recommendation systems build user profiles by collecting historical user behavior data, such as clicks, browsing, favorites, likes, purchases, and ratings. This data then models the user's potential interests and enables personalized recommendations. This improves user experience while also creating numerous business opportunities for the platform. However, recommendation systems have gradually exposed privacy issues during their use. Their high reliance on user data has inevitably led to user concerns about privacy leaks. For example, if user information is illegally leaked or misused by a third party, it could expose user preferences, habits, and even identities.
[0003] Currently, four main types of technologies exist to address the need for forgetting user preferences in recommender systems. The most straightforward approach is to remove the target user's data from the original training data and retrain the model. While this approach can completely erase user information, it is time-consuming and labor-intensive, making it difficult to implement in real-world scenarios. Another approach relies on incremental updates or parameter projections, partially adjusting model weights to reduce the influence of the target user. While these methods are more efficient than retraining from scratch, due to the highly nonlinear nature of recommendation models, they often struggle to completely forget the target user's information. Differential privacy techniques reduce the influence of individual users by injecting noise during training, but this approach does not guarantee true forgetting, and introducing excessive noise can significantly impair the accuracy of the recommender system. In recent years, some have proposed using adversarial example attacks, which inject carefully crafted perturbations into the input or training data to force the model to forget specific user information. This approach eliminates the need for retraining, but research on forgetting user preferences in recommender systems remains in its early stages and lacks a systematic, well-defined technical framework.
[0004] In summary, existing methods all have their own shortcomings. Therefore, there is an urgent need for an efficient, low-cost, and highly directional method for forgetting user preferences that can effectively forget the personalized information of target users while maximally maintaining the overall performance of the recommendation system and the experience of other users. Summary of the Invention
[0005] To address the low efficiency, complex deployment, and high dependence on model structure of existing recommendation system preference forgetting methods, this paper proposes a recommendation system preference forgetting method based on adding interactive perturbations from the user's perspective. This method can be directly applied in black-box model scenarios without modifying the recommendation model structure. By constructing an interaction matrix that adds small perturbations, it guides the model to actively "forget" the preferences of specific users during training. At the same time, by introducing a directional attack objective function, it achieves precise performance reduction for the target user (the forgotten user) while ensuring the stability of recommendation quality for other users. Furthermore, this method is flexibly compatible with mainstream recommendation models such as DMF and LightGCN, demonstrating excellent versatility and practical application value.
[0006] In order to achieve the above-mentioned object of the invention, the present invention adopts the following technical solutions:
[0007] The recommendation system preference forgetting method based on the user perspective includes the following steps:
[0008] Step 1: Based on the recommendation system, establish an interaction matrix between users and items.
[0009] Step 2: Construct a recommendation system module to learn preference information from the interaction matrix, and construct an attack module to modify the interaction matrix through the interaction perturbation matrix, so that the preferences of the target user set forgotten by the preference cannot be learned by the recommendation system module.
[0010] Step 3: Through double-layer optimization, the interaction perturbation matrix that modifies the interaction matrix is trained and optimized.
[0011] Furthermore, the specific implementation process of step 1 is as follows:
[0012] The recommendation system used is based on collaborative filtering (CF) as its basic structure. In the CF model, there are two groups of entities, including user sets. and item collections ; Let the interaction matrix Represents the original training interaction behavior. In implicit feedback, if the user With the project If there is interaction, the elements =1; otherwise, =0; the embedding-based CF model embeds users and items into a latent embedding space, expressed as , represents the embedding dimension, Elements in and Represents users With items The predicted preference of each user for unknown items is represented as an inner point between the corresponding embeddings; the user With items The predicted preference between ,in express The transpose of .
[0013] Divide the user set into two parts: Represents the set of users who need recommended services; represents the set of users who have the need to forget. and The number of users in and ,use As an indicator matrix, it indicates whether the user has a need to forget. If the user For users who have the need to forget, =1; otherwise, =0.
[0014] Furthermore, the specific implementation process of step 2 is as follows:
[0015] against For medium users, use represents the interaction perturbation matrix, the interaction matrix As the original dataset, Represented by the original dataset Add the interaction perturbation matrix The modified interactive dataset obtained does not Modify the user's interaction in the
[0016] Build a recommendation system module by any recommendation algorithm, learn preference information from the user's historical interaction matrix; build an attack module so that the target user set The preference cannot be learned by the recommendation system module, and the interaction perturbation matrix The following constraints are imposed:
[0017] First, the modification behavior is limited to the set of users who have the need to forget ; Secondly, each perturbation element It is 0 or 1, indicating whether to add a new interaction. Duplicate addition is not allowed, so it must meet And for all existing interactions ; For the total amount of added interactions, define the following average maximum modification limit: the sum of all perturbation elements and divided by the number of non-learnable users is less than the maximum average number of interactions allowed to be added by each user.
[0018] Furthermore, the specific implementation process of step 3 is as follows: the recommendation system module will learn user preferences and predict the user's interest in unknown items; the recommendation system module will be trained to fit the current interaction data to obtain the optimal embedding parameters of the recommendation system module. , in obtaining After that, we get the predicted preference matrix The goal of the attack module is to modify the interaction data so that the recommendation system module is misled and the prediction preference matrix , train to get the optimal interaction perturbation matrix ; Alternate the above two training processes until the attack module achieves the goal of forgetting the preference.
[0019] Furthermore, the loss functions for training the recommendation system module and the attack module are respectively the recommendation loss and the attacker's loss ;
[0020] Recommendation loss :Inner optimization seeks the optimal embedding parameters of the recommendation system module to fit the first Training data at iteration , using weighted regularized matrix factorization WRMF loss as .
[0021] Attacker's loss : Construct a dual attacker loss function: The interactive modification should satisfy The current prediction recommendation result of the training Different from the test data for users with forgetfulness needs, first obtain users on clean training data A collection of potentially interesting items ,use To indicate whether the user-item pair belongs to ,like ,otherwise, ; Finally, the attacker’s loss function is expressed as:
[0022]
[0023] in, is a balanced hyperparameter; if , then only consider reducing the recommendation performance; if , the result is completely determined by maintaining the recommendation performance of normal users, Indicates the preference ranking of users with forgetfulness needs. On the contrary, Indicates the preference ranking of normal users.
[0024] Based on recommendation loss and the attacker's loss , using stochastic gradient descent to obtain the optimal constraint .
[0025] Furthermore, during the training of the recommendation system module and the attack module, two convergence principles are defined. The first principle is related to the attacker's goal. Specifically, the user The modification of has reached the convergence condition. If the CF model cannot infer its preference in this iteration, that is, should decrease, i.e. the true preference should be completely different from the currently predicted preference; compare the cosine similarity between the two preferences and Set as the threshold, if the similarity is lower than , then the user The optimization reaches the convergence condition; another principle is the maximum addition number of Δ. Specifically, the upper threshold of the average number of interaction modifications is set so that the sum of all perturbation elements and the sum divided by the number of non-learnable users is less than the maximum average number of interactions allowed to be added by each user.
[0026] Compared with the prior art, the present invention has the following advantages: (1) the present invention does not need to delete the original user data or modify the recommendation system model structure, nor does it need to fully retrain the model, thus avoiding the huge computational overhead caused by retraining in traditional methods; (2) the present invention proposes a user preference forgetting method from the perspective of data attack. By adding a limited amount of forged interaction data to the interaction matrix of the target user, the prediction score of the recommendation system for the target user's sensitive items can be significantly reduced, thereby achieving a forgetting effect without invading the model or relying on model parameter information. The method is suitable for common black box recommendation system scenarios in practice and has high versatility and feasibility; (3) the present invention can effectively weaken the personalized characteristics of the target user while maintaining the recommendation accuracy for non-target users to the greatest extent. Therefore, while ensuring the forgetting effect, the overall performance of the recommendation system can be maintained. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 It is a flow chart of the recommendation system preference forgetting method based on the user perspective of the present invention. DETAILED DESCRIPTION
[0028] In order to achieve the above-mentioned object of the invention, the present invention adopts the following technical solutions:
[0029] Recommendation system preference forgetting method based on adding interactive perturbations from the user perspective, such as Figure 1 As shown, the following steps are included:
[0030] Step 1: Based on the recommendation system, determine the user group and preference protection target, and establish the interaction matrix between users and items. The recommendation system adopted by this invention is based on collaborative filtering (CF). In the CF model, there are two groups of entities, including user set and item collections Since implicit feedback (such as clicks, purchases) is more common in the real world, we consider the recommendation scenario of implicit feedback. In the implicit feedback, if the user With items If there is interaction, =1; otherwise, = 0. The classic embedding-based CF model embeds users and items into a latent embedding space, expressed as . represents the embedding dimension, Elements in and Represents users With items Each user’s predicted preference for an unknown item can be represented as an inlier between the corresponding embeddings. With items The prediction preference between ,in express The transpose of .
[0031] In this paper, we consider that in real-world scenarios, some users need to pass their forgetting preferences to the recommendation system as required. The user set is divided into two parts: Represents ordinary users who need high-quality recommendation services. Indicates users who have the need to forget and who are concerned about their own personalized information. As an indicator matrix to indicate whether the user has a need to forget. For users with demand, = 1; otherwise, = 0.
[0032] There are two modules in this invention, one is the recommendation system module and the other is the attack module. Indicates interactive modification, represents the original dataset, Represents the dataset after modification of the interaction, which means that normal user interaction will not be increased.
[0033] Step 2: Modify the constraints of the interaction. The recommendation system module used in the present invention can be any recommendation algorithm, and its responsibility is to learn preference information from the user's historical interaction data. In contrast, the goal of the attack module is to prevent the preferences of the target user set from being learned by the recommendation system module. It should be emphasized that in the real world, ordinary users can neither understand nor modify the internal structure or parameters of the recommendation system module. Therefore, the attack module does not have the authority to modify the recommendation system, such as deleting historical data or replacing the recommendation algorithm to achieve the goal of "forgetting". Therefore, there are constraints on the forgetting problem from the user's perspective. In order to ensure the feasibility of the attack process in real scenarios, this paper modifies the interaction perturbation matrix The following constraints are imposed to limit the operational capabilities of the attack module. First, since the modification behavior is limited to the set of unlearnable users , so the disturbance to normal users is zero. Secondly, each disturbance element Only 0 or 1 is allowed, indicating whether a new interaction is added. Duplicate addition is not allowed, so it must meet And for all existing interactions In addition, to prevent system detection, the total amount of added interactions must also be limited, and the following average maximum modification limit is defined:
[0034]
[0035] in is the number of unlearnable users, represents the maximum average number of interactions allowed for each user. Taking into account the above constraints, the attack module's behavior is strictly limited to a reasonable and controllable range in terms of data dimensions, achieving effective forgetting while maintaining the concealment and feasibility of the operation.
[0036] Step 3: Construct a two-layer optimization process. Based on the above user and item interactions, this step establishes a two-layer optimization process to effectively achieve the forgetting goal. First, analyze the unlearnable target from the perspective of the recommendation system and the attack module. Given the historical interaction , the recommendation system module will learn user preferences and predict the user’s interest in unknown items. The predicted preference matrix is The process of training the recommendation system module to fit the current interaction data is defined as:
[0037]
[0038] in represents the optimal embedding parameter of the recommendation system module. After that, we get the predicted preference matrix The goal of the attack module is to modify the interaction data so that the recommendation system module is misled. It is defined as follows:
[0039]
[0040] It is worth noting that these two steps can be trained alternately until the attack module effectively achieves the goal of forgetting the bias. The iterative training process can be formulated as a two-level optimization:
[0041]
[0042]
[0043] in, Indicates the The optimization iteration, Indicates the The training data with modified interactions at the iteration. The above two equations are expressed as "inner optimization" and "outer optimization".
[0044] Step 4: Construct the recommendation loss and the attacker's loss .
[0045] In this step, the present invention will construct the recommendation loss , and the attacker's loss To achieve double-layer optimization.
[0046] Recommendation loss :Inner optimization seeks the optimal embedding parameters of the recommendation system module to fit the first Training data at iteration Directly adopt weighted regularized matrix decomposition WRMF loss as .
[0047] Attacker's loss : To connect the external optimization with the goal of forgetting preference, it is crucial to correctly define the attacker loss Specifically, a dual attacker loss function is constructed: the interactive modification should satisfy The current prediction recommendation result of the training Should be different from the test data for users with forgetfulness needs , and similar to normal users (i.e. reducing Recommended performance, maintain Recommended performance) test data However, access to test data during training is prohibited. Therefore, the present invention proposes a CF model based on original clear training data that can accurately predict the true preference, i.e., test data. In practice, first, the user’s preference is obtained on the clean training data. Potential projects of interest (a list). Specifically, use To indicate whether the user-item pair belongs to .like , then the user right The preference belongs to the top-ranked prediction score. Otherwise, Finally, the attacker’s loss function can be expressed as:
[0048]
[0049] in, is a balancing hyperparameter. If , then only consider reducing the recommended performance. , then the result is entirely determined by maintaining the recommendation performance of normal users. Indicates the preference ranking of users with forgetting needs. On the contrary, indicates the preference ranking of normal users.
[0050] Step 5: Stochastic gradient descent to obtain the optimal constraint. The present invention uses stochastic gradient descent to obtain the optimal constraint For the optimization based on stochastic gradient descent, we first train the recommendation module several times and then record the gradients of the external optimization.
[0051] Step 6: Setting the convergence conditions.
[0052] The final step is to set the convergence conditions. This invention defines two convergence principles. The first principle is related to the attacker's goal. Specifically, the user The modification of has reached the convergence condition. If the CF model cannot infer its preference in this iteration, that is, should be reduced. This requires a true preference should be completely different from the currently predicted preference. Compare the cosine similarity between the two preferences and Set as the threshold. If the similarity is lower than , then the user The optimization reaches the convergence condition. Another principle is the maximum addition number of Δ. Specifically, the upper threshold of the average number of interaction modifications is set, and the formula is .
[0053] To validate the effectiveness of the proposed method for forgetting user perspective preferences, experiments were conducted on the classic MovieLens-100K implicit feedback dataset (denoted as M1-100k). Three mainstream recommendation models, LightGCN, DMF, and NCF, were employed to evaluate the adaptability and stability of the two-layer optimization method under different models. In the experimental setup, the user set was divided into two categories: "normal users" and "users with forgetting needs." The Hit Ratio (HR@K) and Normalized Discounted Cumulative Gain (NDCG@K) metrics were calculated for each user in the recommendation task to measure the degree to which the recommendation system retains or forgets user interests. HR@K reflects the hit rate of the target item among the top K recommended results, while NDCG@K further examines the rationality of the recommendation result ranking, comprehensively reflecting recommendation performance. All models were retrained after injecting the perturbed interaction matrix and evaluated on the same test set.
[0054] As shown in Table 1, the recommendation performance of all three models for non-learnable users decreased significantly, while performance for normal users remained largely stable. For example, in the LightGCN model, the HR@20 and NDCG@20 metrics for non-learnable users decreased from 0.1935 and 0.0672 to 0.1527 and 0.0575, respectively, indicating that the model's learning of their sensitive item preferences was significantly weakened, achieving the forgetting goal. Meanwhile, the metrics for normal users remained largely unchanged, verifying the controllability of this method's impact on non-target users. Furthermore, in the DMF model, the NDCG@20 for forgotten users decreased by over 18%, while the performance for normal users decreased by less than 5%, further demonstrating the proposed method's superior balance between target orientation and overall robustness. Overall, this method, independent of model structure and without deleting historical user data, achieves efficient and low-overhead personalized information forgetting, demonstrating excellent performance.
[0055] Table 1
[0056]
Claims
1. A recommendation system preference forgetting method based on the user perspective, characterized by: The following steps are involved: Step 1: Based on the recommendation system, establish an interaction matrix between users and items; Step 2: Construct a recommendation system module to learn preference information from the interaction matrix, and construct an attack module to modify the interaction matrix through the interaction perturbation matrix, so that the preferences of the target user set forgotten by the preference cannot be learned by the recommendation system module; Step 3: Through double-layer optimization, the interaction perturbation matrix that modifies the interaction matrix is trained and optimized.
2. The method for forgetting user-based recommendation system preferences according to claim 1, characterized in that: The specific implementation process of step 1 is as follows: The recommendation system used is based on collaborative filtering (CF) as its basic structure. In the CF model, there are two groups of entities, including user sets. and item collections ; Let the interaction matrix Represents the original training interaction behavior. In implicit feedback, if the user With the project If there is interaction, the elements =1; otherwise, =0; the embedding-based CF model embeds users and items into a latent embedding space, expressed as , represents the embedding dimension, Elements in and Represents users With items The predicted preference of each user for unknown items is represented as an inner point between the corresponding embeddings; the user With items The predicted preference between ,in express The transpose of .
3. The method for forgetting user-based recommendation system preferences according to claim 2, characterized in that: The step 1 further includes dividing the user set into two parts: Represents the set of users who need recommended services; represents the set of users who have the need to forget. and The number of users in and ,use As an indicator matrix, it indicates whether the user has a need to forget. If the user For users who have the need to forget, =1; otherwise, =0.
4. The method for forgetting user-based recommendation system preferences according to claim 3, characterized in that: The specific implementation process of step 2 is as follows: against For medium users, use represents the interaction perturbation matrix, the interaction matrix As the original dataset, Represented by the original dataset Add the interaction perturbation matrix The modified interactive dataset obtained does not Modify the user's interaction in Build a recommendation system module based on any recommendation algorithm and learn preference information from the user's historical interaction matrix; Construct an attack module to make the target user set The preference cannot be learned by the recommendation system module and the interaction perturbation matrix Imposing constraints.
5. The method for forgetting user-based recommendation system preferences according to claim 4, characterized in that: The interaction perturbation matrix The constraints include: First, the modification behavior is limited to the set of users who have the need to forget ; Secondly, each perturbation element It is 0 or 1, indicating whether a new interaction is added. Duplicate addition is not allowed, so it satisfies And for all existing interactions ; For the total amount of interactions added, define an average maximum modification limit: the sum of all perturbation elements and divided by the number of non-learnable users is less than the maximum average number of interactions allowed to be added by each user.
6. The method for forgetting user-based recommendation system preferences according to claim 5, characterized in that: The specific implementation process of step 3 is as follows: the recommendation system module will learn user preferences and predict the user's interest in unknown items; the recommendation system module will be trained to fit the current interaction data to obtain the optimal embedding parameters of the recommendation system module. , in obtaining After that, we get the predicted preference matrix The goal of the attack module is to modify the interaction data so that the recommendation system module is misled and the prediction preference matrix , train to get the optimal interaction perturbation matrix ; Alternate the above two training processes until the attack module achieves the goal of forgetting the preference.
7. The method for forgetting user-based recommendation system preferences according to claim 6, characterized in that: The loss functions for training the recommendation system module and the attack module are respectively the recommendation loss and the attacker's loss ; Recommendation loss :Inner optimization seeks the optimal embedding parameters of the recommendation system module to fit the first Training data at iteration , using weighted regularized matrix factorization WRMF loss as ; Attacker's loss : Construct a dual attacker loss function: The interactive modification should satisfy The current prediction recommendation result of the training Different from the test data for users with forgetfulness needs, first obtain users on clean training data A collection of potentially interesting items ,use Indicates whether the user-item pair belongs to ,like ,otherwise, ; Finally, the attacker’s loss function is expressed as: ; in, is a balanced hyperparameter; if , then only consider reducing the recommendation performance; if , the result is completely determined by maintaining the recommendation performance of normal users, Indicates the preference ranking of users with forgetting needs; on the contrary, Indicates the preference ranking of normal users; Based on recommendation loss and the attacker's loss , using stochastic gradient descent to obtain the optimal constraint .
8. The method for forgetting user-based recommendation system preferences according to claim 7, characterized in that: During the training of the recommendation system module and the attack module, two convergence principles are defined. The first principle is related to the attacker's goal. Specifically, the user The modification has reached the convergence condition. If the CF model cannot infer its preference in this iteration, that is, the true preference should be completely different from the currently predicted preferences; Compare the cosine similarity between two preferences and Set as the threshold, if the similarity is lower than , then the user The optimization reaches the convergence condition; another principle is the maximum addition number of Δ. Specifically, the upper threshold of the average number of interaction modifications is set so that the sum of all perturbation elements and the sum divided by the number of non-learnable users is less than the maximum average number of interactions allowed to be added by each user.
Citation Information
Patent Citations
Federal learning-based product information recommendation method and device, equipment and medium
CN115718847A
Activity recommendation method based on multi-granularity feature fusion
CN116049549A
Recommendation model forgetting
CN117634637A
Recommendation method and device based on large language model, equipment and storage medium
CN117973545A
Multi-modal sequence recommendation method based on large-scale multi-modal model
CN119862318A
Cited By
Sensitive attribute forgetting method and device for recommendation system
CN121996847A