A highly robust privacy-preserving recommendation method based on adversarial learning
Through adversarial learning methods, a neural collaborative filtering model and member inference model are constructed, and iterative adversarial training is carried out, which solves the balance between privacy protection and recommendation performance in the existing technology, and achieves the two-way improvement of the personalized recommendation system.
Patent Information
- Application Number
- CN202111187124.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-12
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-10-12
AI Technical Summary
While protecting user privacy, the prior art is difficult to maintain the predictive performance of the recommendation model and faces the risk of member reasoning attacks.
Adversarial learning-based approach is adopted to construct neural collaborative filtering models and member inference models, and a unified minimum maximization objective function is designed through iterative adversarial training, which explicitly gives the recommended algorithm the ability to defend against member inference attacks.
On the premise of protecting user privacy, improve the prediction performance and generalization capabilities of the recommendation model, enhance the robustness of the model, and achieve two-way improvement of the personalized recommendation system.
Smart Images

Figure CN113918814B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of personalized recommendation, and particularly to a highly robust privacy protection recommendation method based on adversarial learning. Background Art
[0002] As an effective supplementary means of traditional information retrieval, the personalized recommendation system makes full use of the content features of users and items themselves and the interaction data between the two to automatically filter out useless information. It is a common application that can help users discover their potential interests and has received increasing attention in the academic and industrial fields. The core technical support behind the personalized recommendation system is the recommendation algorithm that uses machine learning ideas to train users' historical browsing data.
[0003] The reason why the recommendation algorithm can master users' future interest preferences is that it needs to collect as much user personal information and behavior information as possible to achieve accurate recommendation services, such as content-based recommendation systems and collaborative filtering-based recommendation systems. In addition, according to the social homophily theory, the behaviors of friends tend to be more consistent. Therefore, many studies have incorporated social information into traditional collaborative filtering methods. By integrating more and more information and combining different types of data, the prediction performance of the recommendation system has undoubtedly been significantly improved, but this inevitably leads to the risk of user privacy leakage. Therefore, in recent years, more and more attention has been paid to the problem of protecting users' sensitive information privacy. However, most of the previous work has focused on protecting sensitive information such as users' demographic characteristics and users' historical purchase behaviors. It mainly uses differential privacy technology and perturbation technology to protect the privacy of user information. These methods mostly directly perturb the original data, which, although protecting users' private data to a certain extent, inevitably causes the degradation of the model's prediction performance.
[0004] Since the current mainstream service mode is the machine learning as a service mode, it is difficult to obtain the original data of the model and directly perturb it. Therefore, it becomes unrealistic to perform a white-box attack on the original training data of the model. The latest research shows that the trained data and the untrained data often have different statistical characteristics. Therefore, the machine learning model is prone to privacy leakage of the information of the dataset it has trained. More specifically, the attacker can infer whether certain samples are the data it has trained based on the above different statistical characteristics by constructing an inference model. Such an inference process is called a membership inference attack. Since this method can easily attack the black-box model, it has become the mainstream attack method in recent years.
[0005] Currently, there are two major categories of methods for defending against member inference attacks in the existing technology. The first category includes simple mitigation techniques, which is to limit the prediction results of the model, such as outputting only the first three categories sorted by probability for a five-category prediction task. Obviously, such an operation will reduce the prediction accuracy of the model; or regularize the prediction model, such as using the common L2 paradigm. Although these techniques can guarantee the prediction accuracy of the model to a certain extent, they cannot guarantee any strict definition of privacy protection.
[0006] The second major category of defense technology is to use different differential privacy mechanisms. However, the existing differential privacy mechanisms often cause serious prediction accuracy loss because they strictly meet the privacy protection requirements in a mathematical sense and do not explicitly incorporate model prediction performance into the design goals of the privacy mechanism. Therefore, it is particularly important to design a robust algorithm that takes into account both model prediction performance and training data privacy protection. Summary of the invention
[0007] The embodiments of the present invention provide a highly robust privacy-preserving recommendation method based on adversarial learning, so as to accurately recommend items of interest to users while protecting their privacy.
[0008] In order to achieve the above object, the present invention adopts the following technical scheme.
[0009] A highly robust privacy-preserving recommendation method based on adversarial learning, comprising:
[0010] Step S1: Construct a neural collaborative filtering model and the required training set, and randomly initialize the parameters P, Q, Θ of the neural collaborative filtering recommendation model. R , represents the user feature matrix, represents the item feature matrix, Θ R Unified representation of the parameter matrix of the hidden layer of the recommendation model;
[0011] Step S2: Construct the membership inference model and the required reference set, and randomly initialize the parameter matrix Θ of the membership inference model M , Θ M Unify the learnable parameters of the membership inference model;
[0012] Step S3: constructing a neural collaborative filtering joint model with a member reasoning regularization term using the neural collaborative filtering model and the member reasoning model, designing a unified minimum-maximum objective function based on adversarial learning and performing iterative adversarial training to obtain a robust user feature matrix P and an item feature matrix Q;
[0013] Step S4: Predict the user's rating of unobserved items based on the trained P and Q: right Arrange in descending order row by row, and recommend several items with relatively high middle evaluation scores and not yet evaluated to the corresponding users. represents the predicted user-item rating matrix.
[0014] Preferably, the construction of the neural collaborative filtering model in step S1 includes:
[0015] The input layer of the neural collaborative filtering model f(P, Q, Θ R |U, i) includes two one-hot feature sparse vectors v u and v i that respectively describe user u and item i. Map the sparse vectors to user feature vectors p u = P T v u and item feature vectors q i = Q T v i where and matrices respectively represent the user feature matrix and the item feature matrix, d is the dimension after low-dimensional embedding. Input the obtained user and item latent vectors into a multi-layer neural network to map the low-dimensional vectors of the user and the item to the predicted click probability The predicted click probability The closer it is to 1, the more the user likes the item. The closer it is to 0, the less the user likes the item. The predicted click probability The closer it is to the true label y ui , the higher the recommendation accuracy of the recommendation system is proved.
[0016] Preferably, the construction of the training set in step S1 includes:
[0017] Use the existing data set to construct a user-item rating matrix R ∈ {0, 1, 2, 3, 4, 5} m×n , the rows and columns in the rating matrix respectively represent users and items, and the element values in the rating matrix represent the ratings of users for items. Where m and n respectively represent the number of users and items. Normalize the user-item rating matrix data to obtain a rating matrix Y ∈ {0, 1} m×n applicable to the classification task. The value 1 indicates that the user has clicked on the item, and 0 indicates no behavior. Generate a triple data set for the elements with the value 1 in the rating matrix where u represents the user label, i represents the item label, and y ui = 1 indicates the positive sample of the user clicking on the item;
[0018] Generate negative samples of user clicks using negative sampling technology according to the principle of the same distribution as positive samples Using the positive samples of user clicks And negative samples of user clicks Together constitute the training set for training the neural collaborative filtering recommendation model
[0019] Preferably, the construction of the member inference model in step S2 includes:
[0020] The member inference model g(Θ M ) is modeled using a classification task based on the statistical difference between member predictions and non-member predictions, that is, if the sample exists in the training set, it is a positive sample, otherwise it is a negative sample. The member inference attack model is regarded as a binary classification task, and the member inference attack model is instantiated as g(Θ M |u, i×Y 2 )→[0, 1]. Use a deep neural network good at feature extraction to fit the complex relationship between the input sample and the label. For any sample (u, i, y ui ) in the neural collaborative filtering model dataset and the output vector of the corresponding personalized recommendation model Together constitute the input sample of the member inference attack model If the output result after passing through the member inference model Is close to 1, it is a member, otherwise it is a non-member.
[0021] Preferably, the construction of the reference set in step S2 includes:
[0022] The dataset participating in the training of the neural collaborative filtering recommendation model Is used as the positive sample for training the member inference model Also known as the member set of the member inference model, where h ui = 1 indicates a member sample participating in the training of the neural collaborative filtering recommendation model; according to the principle of independent and identical distribution, negative samples for the member inference model are sampled in the same proportion Where h ui = 0 indicates a non-member sample that has not participated in the training of the neural collaborative filtering recommendation model, also known as the non-member set of the member inference model;
[0023] The member set and non-member set of the member inference model together constitute the reference set required for training the member inference model
[0024] Preferably, the objective function of the neural collaborative filtering joint model based on the member inference regular term in step S3 is defined as follows:
[0025]
[0026] Among them, the goal of the internal maximization function is to find the strongest membership inference attack model g(Θ R ) for a given recommendation model f(Θ M ). The goal of the external minimization function is to find the most robust personalized recommendation model for a given strongest membership inference attack model g(Θ M ). The parameter λ controls the trade-off between recommendation accuracy and membership privacy;
[0027] The optimization goal of the neural collaborative filtering model f(Θ R ) is to minimize the expected empirical loss. Using the cross-entropy loss as the target loss function, the expected empirical loss of the neural collaborative filtering model is expressed as follows:
[0028]
[0029] where is the training set for optimizing the neural collaborative filtering model, y ui are the predicted click probability and the true label of the recommendation model respectively;
[0030] The goal of the membership inference attack model is to maximize the empirical gain. That is, in order to model the statistical difference between the prediction distribution and the true distribution, the cross-entropy loss is used to calculate the supervised loss of the membership inference attack model, where the empirical gain is expressed as follows:
[0031]
[0032] After combining the terms, the unified min-max adversarial objective function is refined into the following mathematical form:
[0033]
[0034] Among them, the training set required for constructing the neural collaborative filtering model and the reference set required for the membership inference model are constructed in a ratio of 4:1 and The training set is used for the training of the recommendation model and the positive samples of the membership inference attack model. The reference set does not participate in the training of the recommendation system but is used as the negative samples of the membership inference model. The training set is used as the positive samples in the reference set. The neural collaborative filtering joint recommendation model with a membership inference regular term is iteratively adversarially trained using the above training set and reference set.
[0035] Preferably, the iterative adversarial training of the neural collaborative filtering joint recommendation model with a membership inference regular term in step S3 is as follows:
[0036] Randomly initialize the parameters P, Q, and Θ of the neural collaborative filtering recommendation model R ; Randomly initialize the parameters Θ of the membership inference model M , and enter the iterative training process: Fix the algorithm parameters P, Q, and Θ of the recommendation model R , calculate the gradient of the objective benefit with respect to Θ M , and update the parameter matrix Θ using the gradient ascent algorithm M ; Fix the algorithm parameters Θ of the membership inference model M , calculate the gradients of the objective loss with respect to P, Q, and Θ respectively R , and update the parameter matrices P, Q, and Θ respectively using the gradient descent algorithm R ; Repeat the above steps, continuously and alternately update the parameters P, Q, and Θ R , Θ M , until the convergence condition is met;
[0037] Through the above algorithm, find the equilibrium point of this min-max game problem, and obtain a robust personalized recommendation system with membership privacy protection capabilities.
[0038] Preferably, the convergence condition includes that the value of the objective function is less than a certain preset threshold or the number of iteration rounds reaches a certain magnitude.
[0039] As can be seen from the technical solutions provided by the embodiments of the present invention above, the present invention designs a unified min-max objective function through adversarial learning to explicitly endow the recommendation algorithm with the ability to defend against membership inference attacks; through the game adversarial training of the personalized recommendation model and the membership inference model, the membership inference attack model can learn the potential membership privacy risks in the recommendation model, and at the same time, the recommendation model can defend against the trained membership attack model through defensive learning, so as to achieve the purpose of being able to defend against membership inference attacks and alleviate the overfitting of the recommendation model, thereby enhancing the generalization ability and robustness. Ultimately, a two-way improvement in the algorithm performance of the personalized recommendation model and the degree of training data privacy protection is achieved, so as to achieve the goal of accurately recommending items of interest to users while protecting the privacy of members.
[0040] Additional aspects and advantages of the present invention will be given in part in the following description, and these will become obvious from the following description, or can be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0042] Figure 1 A flowchart of a model adversarial training process provided by an embodiment of the present invention;
[0043] Figure 2 A processing flowchart of a personalized recommendation method for member privacy protection based on an adversarial learning paradigm provided by an embodiment of the present invention;
[0044] Figure 3 A specific instantiation structure diagram of a personalized neural collaborative filtering recommendation model method provided by an embodiment of the present invention.
[0045] Figure 4 A specific instantiation structure diagram of a member inference model method provided by an embodiment of the present invention. Detailed implementation manners
[0046] The following details the implementation manners of the present invention. Examples of the implementation manners are shown in the accompanying drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. The implementation manners described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.
[0047] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present invention means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or coupling. The phrase "and / or" used herein includes any unit and all combinations of one or more related listed items.
[0048] Those skilled in the art of the present technology can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art and will not be interpreted with an idealized or overly formal meaning unless defined as such herein.
[0049] For ease of understanding of the embodiments of the present invention, the following will further explain with several specific embodiments in conjunction with the accompanying drawings, and each embodiment does not constitute a limitation to the embodiments of the present invention.
[0050] The present invention first considers the problem of member privacy protection in the recommendation system, and designs the recommendation accuracy and the degree of member protection as a min-max game framework. In the recommendation system model, the privacy protection problem is explicitly considered in the form of a member inference regularization term, and an algorithm for balancing the recommendation accuracy and the member privacy protection effect is designed to achieve the goal of accurate recommendation while protecting user privacy.
[0051] The embodiment of the present invention proposes a robust personalized recommendation framework for member privacy protection based on the adversarial learning paradigm. The framework performs adversarial training between the personalized neural collaborative filtering recommendation model and the member inference model, and finally reaches the game balance point of the recommendation performance and the member privacy protection ability, so that the method can improve the generalization ability of the neural collaborative filtering recommendation model while having the ability to protect against member inference, thereby achieving a two-way improvement in the generalization ability of the recommendation system and the degree of member privacy protection.
[0052] The present invention formulates the trade-off problem between the prediction performance of the recommendation algorithm and the member privacy protection as a min-max game problem. By designing a special adversarial training algorithm, the algorithm framework maximizes the member inference attack ability while minimizing the prediction error of the recommendation algorithm and improving the defense ability of the model against member inference attacks, that is, achieving the purpose of accurate recommendation on the premise that it is impossible to accurately judge whether the data participates in the training of the neural collaborative filtering recommendation model. Specifically, the member inference model seeks to accurately infer the member information of the user, that is, whether the target data appears in the training set, by learning the click-through rate prediction distribution of the neural collaborative filtering recommendation model for the input data; the neural collaborative filtering recommendation model explicitly adds a member inference regularization term, so that the model can accurately fit the potential distribution of the original training set on the one hand during the entire training process, and at the same time enables the model to have the ability to defend against the strongest member inference attacks. This strategy alleviates the overfitting problem of the neural collaborative filtering recommendation model from the side, thereby improving the generalization ability and robustness of the neural collaborative filtering recommendation model, and finally realizing the service of providing accurate recommendations for users while ensuring member privacy protection.
[0053] The method of the present invention mainly includes the following contents:
[0054] (1) Construct the training set required for the neural collaborative filtering model The training set includes the user click positive samples given in the original dataset and the user click negative samples generated by using the negative sampling technique according to the same distribution principle as the positive samples The above two subsets together constitute the training set for training the neural collaborative filtering recommendation model
[0055] (2) Construct the reference set required for the member inference model The reference set contains a member set participating in the training of the neural collaborative filtering recommendation model (which has the same meaning as ), and a non-member set of the same scale and distribution that does not participate in the training of the neural collaborative filtering recommendation model The above two subsets together constitute the reference set for training the member inference model
[0056] (3) Instantiate the neural collaborative filtering model f(Θ R ) and the member inference model g(Θ M ). Use the neural collaborative filtering model and the member inference model to construct a neural collaborative filtering joint model with a member inference regularization term, and design a unified min-max objective function based on adversarial learning. Use the training set and the reference set to perform iterative adversarial training on the neural collaborative filtering joint recommendation model with the member inference regularization term to generate a robust user feature matrix P and item feature matrix Q;
[0057] (4) Predict the items of interest to the user according to the generated user feature matrix P and item feature matrix Q
[0058] An embodiment of the present invention provides a workflow diagram for model adversarial training as Figure 1 shown, which specifically includes the following steps
[0059] Step S1: Construct a training set required for the neural collaborative filtering model. The training set contains the user click positive samples given in the original dataset and user click negative samples generated using the negative sampling technique according to the same distribution principle as the positive samples
[0060] Step S1-1: Normalize the user click positive samples given in the original dataset
[0061] Use the existing data to construct a user-item rating matrix R∈{0, 1, 2, 3, 4, 5} m×n , where the rows and columns in the rating matrix represent users and items respectively, and the element values in the rating matrix represent the ratings of users for items. Here, m and n represent the number of users and items respectively. Subsequently, normalize the rating data to obtain a rating matrix Y∈{0, 1} m×n suitable for classification tasks. The value 1 indicates that the user has clicked on the item, and 0 indicates no action. Generate a triple data set for the elements with a value of 1 in the rating matrix where u represents the user label, i represents the item label, and y ui =1 indicates the positive sample of the user clicking on the item
[0062] Step S1-2: Generate user clicked negative samples based on the negative sampling strategy for construction.
[0063] Generally, we can use the original user-item rating matrix described above to train the neural collaborative filtering model. However, due to the large number of negative sample data in the matrix, optimizing a large number of negative samples will greatly slow down the training process, and the serious imbalance between positive and negative samples will have a great impact on the model's performance. Therefore, we propose a negative sampling technique to accelerate the training process of the model and improve the prediction accuracy of the model. Generate a user negative sample set based on the negative sampling strategy for the user clicked positive samples completed above. The negative sample strategy mainly randomly samples the unobserved interactions at a sampling ratio of 1:4 in each iteration to generate user clicked negative sample data where y ui = 0 represents the negative sample of the item not clicked by the user. The positive samples of user click behavior and the negative samples of click behavior together constitute the training set for training the neural collaborative filtering recommendation model
[0064] Step S2: Construct the reference set required for the membership inference model The reference set includes the member set participating in the training of the neural collaborative filtering recommendation model and the non-member set of the same scale and distribution that does not participate in the training of the neural collaborative filtering recommendation model
[0065] Generally speaking, to train the membership inference model, positive samples participating in the training of the neural collaborative filtering recommendation model are required, and at the same time, negative samples that do not participate in the training of the neural collaborative filtering recommendation model are also required. For the membership inference model, the training set required by the neural collaborative filtering model is the member, and the set that does not participate in the training of the neural collaborative filtering model is the non-member. Therefore, the data set participating in the training of the neural collaborative filtering recommendation model can be used as the positive sample for training the membership inference model That is has the same meaning as, and can be replaced synonymously in the following text, where h ui = 1 represents the member sample participating in the training of the neural collaborative filtering recommendation model.
[0066] To ensure the normal training of the membership inference model, according to the principle of independent and identically distributed, negative samples for the membership inference model are sampled at the same ratio where h ui= 0 represents non - member samples that did not participate in the training of the neural collaborative filtering recommendation model. The member set and the non - member set together constitute the reference set required for training the member inference model
[0067] Step S3: Instantiate the neural collaborative filtering model f(Θ R ) and the member inference model g(Θ M ), use the neural collaborative filtering model and the member inference model to construct a neural collaborative filtering joint model with a member inference regularization term, and design a unified min - max objective function based on adversarial learning. Use the training set and the reference set to perform iterative adversarial training on the neural collaborative filtering joint recommendation model with the member inference regularization term, and generate a robust user feature matrix P and item feature matrix Q
[0068] After the above processing of the data set, we obtain the training set required for the neural collaborative filtering model and the reference set required for the member inference model. The adversarial training framework mainly involves the game learning between the neural collaborative filtering recommendation model and the member inference model. Among them, the member inference model seeks to accurately infer the member information of users by learning the click - through rate prediction distribution of the neural collaborative filtering recommendation model for the input data; the neural collaborative filtering recommendation model explicitly adds a member inference regularization term, so that the model can accurately fit the latent distribution of the original training set on the one hand during the entire training process, and at the same time enables the model to have the ability to defend against the strongest member inference attacks. In the following part, we first introduce the neural collaborative filtering model and the member inference model respectively, then introduce the unified objective function of their combination, and finally elaborate on the adversarial training process of the two
[0069] Part of the neural collaborative filtering model: Its input layer includes two one - hot feature sparse vectors v u and v i describing the user u and the item i respectively. Then, the sparse vectors are mapped to the user feature vector p u = P T v u and the item feature vector q i = Q T v i , where and matrices represent the user feature matrix and the item feature matrix respectively, and d is the dimension after low - dimensional embedding. Subsequently, the obtained user and item latent vectors are input into a multi - layer neural network (which we call the neural collaborative filtering layer), and finally the latent vectors are mapped to the predicted click probability The specific network structure is as Figure 3 shown. Among them, the predicted click probability The closer it is to 1, the more the user likes the item; the closer it is to 0, the less the user likes the item. Predict the click probability The closer it is to the true label y ui , the higher the recommendation accuracy of the recommendation system is proved.
[0070] We can formally express the prediction function of the neural collaborative filtering model as follows:
[0071]
[0072] where is the latent variable matrix of users, is the latent variable matrix of items, and Θ R are the model parameters of the neural collaborative filtering recommendation model f.
[0073] Since the neural collaborative filtering model is a multi-layer neural network, the prediction model can be expressed as:
[0074]
[0075]
[0076] ……
[0077]
[0078] where W L , b L , a L are respectively the weight matrix, bias vector and activation function of the L-th perceptron. We can choose activation functions such as sigmoid, tanh, ReLU, etc. In the present invention, the ReLU function is selected.
[0079] The optimization objective of the neural collaborative filtering model is to minimize the expected empirical loss. In the present invention, the cross-entropy loss is used as the target loss function, and the expected empirical loss of the neural collaborative filtering model is expressed as follows:
[0080]
[0081] where is the training set of the neural collaborative filtering model, y ui are respectively the predicted click probability and the true label of the neural collaborative filtering recommendation model.
[0082] Member inference model: It infers whether the input sample exists in the original data set based on the different performance of the input data in the model prediction distribution. That is, the model prediction results generated by the trained member data often have a very high confidence in a certain category, while the model prediction results generated by the untrained non-member data are often distributed more evenly. Based on this statistical law and other background knowledge, attackers can easily launch member inference attacks on the model, ultimately leading to the leakage of member privacy issues.
[0083] Therefore, based on the above statistical laws, the membership inference model is based on the statistical difference between the prediction of members and the prediction of non-members, and is often modeled using classification tasks, that is, if the sample exists in the training set, it is a positive sample, otherwise it is a negative sample. In this invention, we regard the membership inference model as a binary classification task, and instantiate the membership inference model as g(Θ M |u,i×Y 2 )→[0, 1], using a deep neural network that is good at feature extraction to fit the complex relationship between input samples and labels. The specific network structure is as follows Figure 4 As shown. For any sample (u, i, y ui ) and the corresponding output vector of the personalized neural collaborative filtering recommendation model The input samples that together constitute the membership inference model If the output result after the member reasoning model If it is close to 1, it is a member, otherwise it is a non-member. We can formally express the prediction function of the membership inference model as:
[0084]
[0085] in is the input data of the model, which respectively represents the user label, item label, the predicted distribution of the neural collaborative filtering recommendation model and the true label of the sample, Θ M The model parameters of the member inference model g.
[0086] Here, in order to model the statistical difference between the predicted distribution and the true distribution, we also use the cross entropy loss to calculate the supervision loss of the member reasoning model. The goal of the member reasoning model is to maximize the empirical gain, where the empirical gain can be expressed as follows:
[0087]
[0088] Through the above content, we have introduced the structure, input and output, and loss function of the neural collaborative filtering model and the member reasoning model. Next, we will mainly introduce the principle and optimization algorithm of adversarial training between the two in detail.
[0089] Inspired by the currently popular adversarial learning idea, we can naturally regard the recommendation system with membership inference protection as a min-max game problem. The membership inference model adjusts its own parameters of the attack model according to the background knowledge it has and the set objective function, with the ultimate goal of maximizing its attack gain on the existing neural collaborative filtering recommendation model; the personalized neural collaborative filtering recommendation model adjusts its own parameters according to its own objective function, with the primary goal of minimizing its own model prediction error and reducing the risk of its own member privacy leakage. This means that the defender and the attacker have conflicting goals, so it can be considered a game trade-off problem. The defender needs to find a neural collaborative filtering recommendation model that not only minimizes its own loss but also minimizes the maximum gain of the opponent. This problem can be modeled as a min-max game problem.
[0090] If solely for resisting membership inference attacks, we can simply make there be no connection between the input and output of the model, but this will greatly affect the recommendation utility of the neural collaborative filtering recommendation model. Therefore, the present invention innovatively designs the goal of the recommendation system to minimize the risk of member privacy leakage when facing the strongest membership inference attack while minimizing the loss of recommendation performance, thereby designing the optimal member privacy mechanism and ensuring the maximization of model utility at the same time.
[0091] We formalize member privacy and recommendation performance in the following adversarial objective function:
[0092]
[0093] Among them, the goal of the inner maximization function is to find the strongest membership inference model \(g(\Theta\) R ) for a given neural collaborative filtering recommendation model \(f(\Theta\) M ). The goal of the outer minimization function is to find the most robust personalized neural collaborative filtering recommendation model for a given strongest membership inference model \(g(\Theta\) M ), so that it can not only protect member information but also provide accurate recommendation services. The parameter \(\lambda\) controls the trade-off between recommendation accuracy and member privacy. The member privacy protection model serves as a regularization term for the neural collaborative filtering recommendation model, and additionally serves the purpose of preventing the neural collaborative filtering recommendation model from overfitting the original training data to enhance the robustness of the model.
[0094] More specifically, the above-mentioned unified adversarial objective function can be refined into the following mathematical form:
[0095]
[0096] Among them, for the training effect of the neural collaborative filtering recommendation model, we ensure that the training set required for constructing the neural collaborative filtering model is constructed according to a ratio of 4:1 and the reference set required for the membership inference model The training set is used for the training of the neural collaborative filtering recommendation model and the positive samples of the membership inference model. The reference set does not participate in the training of the recommendation system but serves as the negative samples of the membership inference model. Since the training set is the positive sample in the reference set, therefore
[0097] The workflow of training and optimizing a personalized recommendation algorithm for membership privacy protection based on adversarial learning provided by an embodiment of the present invention is that in each round of training, the neural collaborative filtering recommendation model f and the membership inference model g are alternately trained to find the optimal models for each other. In the internal optimization step, for a fixed neural collaborative filtering recommendation model f, the membership inference model is trained to distinguish whether the target data belongs to the training set D t or the reference set D r . In this step, maximizing the empirical gain of the membership inference model is In the external optimization step, for a fixed membership inference model g, the empirical gain of the membership inference model is used as the regularization term of the neural collaborative filtering recommendation model, and the neural collaborative filtering recommendation model is trained on the training set D t , and in this step, the empirical recommendation loss is minimized
[0098] More specifically, the workflow of training and optimizing a personalized recommendation algorithm for membership privacy protection based on adversarial learning provided by an embodiment of the present invention is as Figure 2 shown, including the following steps:
[0099] S3-1: Randomly initialize the parameters P, Q, Θ of the neural collaborative filtering recommendation model R ;
[0100] S3-2: Randomly initialize the parameters Θ of the membership inference model M , and enter the iterative training process:
[0101] S3-3: Fix the algorithm parameters P, Q, Θ of the neural collaborative filtering recommendation model R , calculate the gradient of the objective gain with respect to Θ M , and update the parameter matrix Θ using the gradient ascent algorithm M ;
[0102] S3-4: Fix the algorithm parameters Θ of the membership inference model M , calculate the gradients of the objective loss with respect to P, Q, Θ R respectively, and update the parameter matrices P, Q, Θ using the gradient descent algorithm R ;
[0103] S3-5: Repeat steps S3-3 to S3-4, continuously and alternately update the parameters P, Q, Θ R , Θ M , until the convergence condition is met, such as the objective function value being less than a certain preset threshold or the number of iteration rounds reaching a certain magnitude, and finally output the parameter model.
[0104] Through the above algorithm, we can finally find the equilibrium point of the min-max game problem, and ultimately obtain a personalized recommendation system with member privacy protection, achieving a double improvement in the generalization ability and member privacy protection ability of the recommendation system.
[0105] Step S4: Predict the rating value of the user for unobserved items based on the feature matrices of users and items: Sort in descending order row by row, and recommend several items with relatively high (and unrated) rating values in to the corresponding users. Among them, represents the user feature matrix, represents the item feature matrix, represents the predicted user-item rating matrix.
[0106] In summary, the present invention designs a unified min-max objective function through adversarial learning to explicitly endow the recommendation algorithm with the ability to defend against membership inference attacks; through the game adversarial training of the personalized neural collaborative filtering recommendation model and the membership inference model, the membership inference model can learn the potential membership privacy risks in the neural collaborative filtering recommendation model, and at the same time, the neural collaborative filtering recommendation model can defend against the trained membership attack model through defensive learning, so as to achieve the purpose of being able to defend against membership inference attacks and alleviate the overfitting of the neural collaborative filtering recommendation model, thereby enhancing the generalization ability and robustness. Finally, the two-way improvement of the algorithm performance of the personalized neural collaborative filtering recommendation model and the privacy protection degree of the training data is realized, so as to achieve the goal of accurately recommending the items of interest to the user on the premise of protecting the member privacy.
[0107] Those of ordinary skill in the art can understand that the drawings are only schematic diagrams of an embodiment, and the modules or processes in the drawings are not necessarily essential for implementing the present invention.
[0108] From the description of the above embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of the present invention.
[0109] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the device or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments. The device and system embodiments described above are only illustrative. The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0110] As described above, only the preferred specific embodiments of the present invention are given, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A highly robust privacy-preserving recommendation method based on adversarial learning, characterized in that, it includes: Step S1: Construct a neural collaborative filtering model and the required training set, and randomly initialize the parameters P, Q, and Θ of the neural collaborative filtering recommendation model R , represents the user feature matrix, represents the item feature matrix, and Θ R collectively represents the parameter matrix of the hidden layer of the recommendation model; Step S2: Construct a member inference model and the required reference set, and randomly initialize the parameter matrix Θ of the member inference model M , Θ M uniformly represents the learnable parameters of the member inference model; Step S3: Use the neural collaborative filtering model and the membership inference model to construct a neural collaborative filtering joint model with a membership inference regular term, design a unified min-max objective function based on adversarial learning and perform iterative adversarial training to obtain a robust user feature matrix P and item feature matrix Q; Step S4: Predict the rating values of the unobserved items for the users based on the trained P and Q: Sort in descending order row by row, and recommend several unrated items in to the corresponding users, which represents the predicted user-item rating matrix; The objective function of the neural collaborative filtering joint model with a membership inference regular term in Step S3 is defined as follows: Among them, the goal of the internal maximization function is to find the strongest member inference model g(Θ R ) for a given recommendation model f(Θ M ). The goal of the external minimization function is to find the most robust personalized recommendation model for a given strongest member inference model g(Θ M ). The parameter λ controls the trade-off between recommendation accuracy and member privacy; Neural collaborative filtering model f(Θ R ) aims to minimize the expected empirical loss. Using cross-entropy loss as the target loss function, the expected empirical loss of the neural collaborative filtering model is expressed as follows: Among them To optimize the training set of the neural collaborative filtering model y ui are the predicted click probability and the true label of the recommendation model respectively; The objective of the membership inference model is to maximize the empirical gain. To model the statistical difference between the prediction distribution and the true distribution, cross-entropy loss is used to calculate the supervised loss of the membership inference model, where the empirical gain is expressed as follows: After combining all terms, the unified min-max objective function is refined into the following mathematical form: Among them, the training set required for constructing the neural collaborative filtering model is constructed in a ratio of 4:1 and the reference set required for the membership inference model The training set is used as the positive sample for the training of the recommendation model and the optimization of the membership inference model. The reference set does not participate in the training of the recommendation system but is used as the negative sample for the optimization of the membership inference model. The training set serves as the positive sample in the reference set. Iterative adversarial training is performed on the neural collaborative filtering joint recommendation model with the membership inference regularization term using the above training set and reference set; The iterative adversarial training of the neural collaborative filtering joint recommendation model with a membership inference regular term is as follows: Randomly initialize the parameters P, Q, and Θ of the neural collaborative filtering recommendation model R ; Randomly initialize the parameters Θ of the membership inference model M , and enter the iterative training process: Fix the algorithm parameters P, Q, and Θ of the recommendation model R , calculate the gradient of the objective benefit with respect to Θ M , and update the parameter matrix Θ using the gradient ascent algorithm M ; Fix the algorithm parameters Θ of the membership inference model M , calculate the gradients of the objective loss with respect to P, Q, and Θ respectively R , and update the parameter matrices P, Q, and Θ respectively using the gradient descent algorithm R ; Repeat the above steps and continuously update the parameters P, Q, and Θ alternately R , Θ M , until the convergence condition is met; Through the above algorithm, find the balance point of the min-max objective function and obtain a robust personalized recommendation system with the ability to protect member privacy.
2. The method according to claim 1, characterized in that, the construction of the neural collaborative filtering model in Step S1 includes: The input layer of the neural collaborative filtering model f(P, Q, Θ R |u, i) includes two one-hot feature sparse vectors v u and v i that respectively describe the user u and the item i. The sparse vectors are mapped to the user feature vector p u = P T v u and the item feature vector q i = Q T v i , where and matrices represent the user feature matrix and the item feature matrix respectively, d is the dimension after low-dimensional embedding. The obtained user and item latent vectors are input into a multi-layer neural network to map the user and item low-dimensional vectors to the predicted click probability The predicted click probability The closer it is to 1, the more the user likes the item. The closer it is to 0, the less the user likes the item. The predicted click probability The closer it is to the true label y ui , which proves that the recommendation accuracy of the recommendation system is higher.
3. The method according to claim 1, characterized in that, the construction of the training set in Step S1 includes: Construct a user-item rating matrix \(R\in\{0, 1, 2, 3, 4, 5\}\) using the existing dataset m×n , where the rows and columns in the rating matrix represent users and items respectively, and the element values in the rating matrix represent the ratings given by users to items. Here, \(m\) and \(n\) represent the number of users and items respectively. Normalize the user-item rating matrix data to obtain a rating matrix \(Y\in\{0, 1\}\) suitable for classification tasks m×n . The value 1 indicates that the user has clicked on the item, and 0 indicates no such behavior. Generate a set of triple data for the elements with value 1 in the rating matrix , where \(u\) represents the user label, \(i\) represents the item label, and \(y\) ui = 1 indicates a positive sample where the user clicks on the item; Generate user click negative samples using negative sampling technology according to the principle of the same distribution as positive samples Use the positive samples of user clicks and negative samples of user clicks to jointly form a training set for training a neural collaborative filtering recommendation model 4. The method according to claim 1, characterized in that, the construction of the membership inference model in Step S2 includes: The membership inference model g(Θ M ) is modeled based on the statistical difference between member prediction and non-member prediction using the classification task, that is, if the sample exists in the training set, it is a positive sample, otherwise it is a negative sample. The member inference model g(Θ M ) is regarded as a binary classification task, and the instantiated membership inference model is g(Θ M |u,i×Y 2 )→[0, 1], using deep neural networks that are good at feature extraction to fit the complex relationship between input samples and labels. For any sample (u, i, y ui ) and the corresponding output vector of the personalized recommendation model The input samples that together constitute the membership inference model If the output result after the member reasoning model If it is close to 1, it is a member, otherwise it is a non-member.
5. The method according to claim 1, characterized in that, the construction of the reference set in Step S2 includes: The dataset involved in the training of the neural collaborative filtering recommendation model is used as the positive sample for training the member inference model Also known as the member set of the member inference model, where h ui = 1 indicates the member sample involved in the training of the neural collaborative filtering recommendation model; according to the principle of independent and identical distribution, negative samples for the member inference model are generated by sampling at the same ratio where h ui = 0 indicates the non-member sample not involved in the training of the neural collaborative filtering recommendation model, also known as the non-member set of the member inference model; The member set and non-member set of the member inference model together constitute the reference set required for training the member inference model 6. The method according to claim 1, characterized in that, the convergence condition includes that the objective function value is less than a certain preset threshold or the number of iteration rounds reaches a certain value.