An information recommendation method based on privacy protection and fairness enhancement
By employing an improved differential privacy-preserving stochastic gradient descent and fair sampling mechanism, the privacy protection and fairness issues in recommender systems are addressed, thereby enhancing the accuracy and fairness of the recommender system and ensuring user privacy and fairness in recommendations.
Patent Information
- Application Number
- CN202510054729.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-01-14
AI Technical Summary
Existing recommendation systems struggle to find an effective comprehensive solution that balances privacy protection and fairness, which means that privacy protection measures may affect recommendation accuracy and fairness.
An improved differential privacy stochastic gradient descent method and a gradient-based fair sampling mechanism are employed to optimize model parameter updates through adaptive pruning and dynamic noise addition, thereby improving recommendation quality and fairness.
While protecting user privacy, we will improve the accuracy and fairness of the recommendation system, ensure that projects from different groups receive recommendations fairly, and enhance user trust and system experience.
Smart Images

Figure CN119988725B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data privacy protection and fairness enhancement technology, and in particular to an information recommendation method based on privacy protection and fairness enhancement. Background Technology
[0002] Recommender systems, as the core technology for information filtering and personalized recommendations, are widely used in e-commerce, social networks, media platforms, and other fields. Their main purpose is to recommend personalized information or products to users by analyzing their behavior, interests, and historical data. Common recommendation methods include collaborative filtering, content recommendation, and model-based recommendation. However, with the rapid growth of user data and the continuous improvement of recommendation accuracy, traditional recommendation algorithms also face problems such as privacy leaks, recommendation bias, and fairness. In recent years, with the development of big data technology, research on large-scale recommender systems has gradually become an important direction in the field. In the process of large-scale data processing, how to improve recommendation quality while protecting user privacy and ensuring the fairness of recommendation results has become a pressing challenge.
[0003] With increasing awareness of privacy, users are paying more and more attention to the security of their personal data when sharing it. Traditional recommendation systems often rely on large amounts of user personal data to improve recommendation accuracy, but this also brings the risk of privacy leaks, especially during data storage and processing, where sensitive user information may be maliciously accessed or misused. To address this issue, data privacy protection technologies have emerged, including differential privacy, homomorphic encryption, and secure multi-party computation. Differential privacy technology protects sensitive user data by adding noise, ensuring that even if the data is leaked, external attackers cannot deduce the user's specific information. In recent years, differential privacy technology has been widely used in recommendation systems to ensure user privacy is protected while making personalized recommendations. However, the application of privacy protection technologies often involves a trade-off between computational efficiency and recommendation accuracy, requiring the design of more efficient privacy protection algorithms with minimal loss of accuracy.
[0004] Fairness has been a hot topic in recommender system research in recent years. Traditional recommender systems often focus on optimizing recommendation accuracy but neglect the fairness of the results, potentially leading to the deprivation of recommendation opportunities for specific groups or users, or the presence of bias. For example, factors such as gender, age, and region may unconsciously create system bias during the recommendation process, affecting user experience and trust. Collaborative filtering, as one of the most representative techniques in recommender systems, aims to learn recommendation models by encoding implicit user-item feedback (e.g., user clicks and purchases), employing a pairwise learning paradigm, such as Bayesian Personalized Ranking (BPR). Generally, this mainstream learning paradigm first constructs training data through random negative sample sampling, typically pairing a positive sample (from items the user has interacted with) with a negative sample (from items the user has not interacted with), and then encouraging the predicted score of the positive sample to be higher than that of the negative sample. Due to the inherent bias in the data, items belonging to a dominant group will have a higher probability of being sampled as negative samples than items belonging to a disadvantaged group. For example, in movie recommendations, comedy items belong to a dominant group, while horror items belong to a disadvantaged group. Therefore, during training, the BPR loss pushes items from the dominant group towards biased (lower) prediction scores, leading to differences in recommendation performance between different item groups. In other words, this random negative sampling strategy inherits group bias from the item side, which misleads the recommendation model into learning biased user preferences and weakens the recommendation quality for items from the dominant group.
[0005] Although privacy protection and fairness are two independent issues that urgently need to be addressed in recommender systems, they often interact in practical applications. On the one hand, privacy protection requires protecting users' sensitive information during data processing and analysis, which may affect data availability and algorithm accuracy. On the other hand, the fairness issue in recommender systems may become more complex due to the introduction of privacy protection measures. For example, differential privacy algorithms often introduce noise, which may affect the fairness of the system because the introduction of noise may unevenly affect the data of different groups, leading to biased recommendation results. Therefore, how to ensure privacy protection without compromising the fairness of recommendation results has become an important challenge in large-scale recommender system research. Existing research often makes trade-offs between privacy protection and fairness, lacking an effective comprehensive solution. Therefore, how to design a recommender method that balances privacy protection and fairness enhancement has become an urgent problem to be solved in this field. Summary of the Invention
[0006] The purpose of this invention is to provide an information recommendation method based on privacy protection and fairness enhancement, which can effectively improve the recommendation quality of the recommendation system while ensuring user data privacy.
[0007] To achieve the above object, the present invention provides the following solutions:
[0008] An information recommendation method based on privacy protection and enhanced fairness includes:
[0009] Obtain behavioral data from target users;
[0010] The behavioral data is input into a preset large-scale recommendation model, which outputs recommendation results for the target user. The large-scale recommendation model is constructed based on a user encoder and an item encoder. The large-scale recommendation model is trained on a training set, which includes several users and items. During the training of the large-scale recommendation model, an improved differential privacy stochastic gradient descent method is used to update the model parameters, and a gradient-based fair sampling mechanism is introduced during the training process.
[0011] Optionally, updating the model parameters using an improved differential privacy stochastic gradient descent method during the training of the large-scale recommendation model includes:
[0012] In each iteration, samples are sampled and the gradient of the samples is calculated;
[0013] The gradient is adaptively clipped, and Gaussian noise is added to the clipped gradient to obtain a privacy gradient.
[0014] The model parameters are updated based on the privacy gradient.
[0015] Optionally, the gradient of the sample can be calculated as follows:
[0016]
[0017] Among them, g t,i Let represent the gradient of sample i in the t-th iteration, and ← denotes assignment. To express differentiation, Let be the BPR loss for sample i.
[0018] Optionally, the method for adaptively pruning the gradient is as follows:
[0019]
[0020] in, Let ||g| represent the gradient after clipping, C be the clipping threshold, r be the regularization term, and ||g| be the gradient after clipping. t,i || represents g t,i The l2-norm.
[0021] Optionally, Gaussian noise is added to the clipped gradient to obtain the privacy gradient.
[0022]
[0023] in, Representing the privacy gradient, B t Let be the sampled in the t-th iteration, and ⊙ represent the product of the elements of the two vectors. It is a function with a mean of 0 and a covariance of σ. 2 Gaussian distribution, δ e ∈{0,1} p+e This is used to determine whether noise needs to be added to the gradient value of the corresponding parameter, where p is the number of non-embedded parameters and e is the number of embedded parameters.
[0024] Optionally, introducing a gradient-based fair sampling mechanism during the training process includes:
[0025] After a training epoch, calculate the cross-entropy loss for each project group, and calculate the gradient and gradient norm for each project group.
[0026] Noise is added to the gradient norm, and the sampling probability of each project group is calculated based on the gradient norm after adding noise.
[0027] In the next training round, the project samples are trained based on the sampling probability.
[0028] Optionally, the method for calculating the cross-entropy loss for each project group is as follows:
[0029]
[0030] Among them, L a Y represents the cross-entropy loss of project group a. a Let represent the set of all user-item pairs in project group a, Q represent the predicted score from user u to item v, and σ(·) represent the sigmoid activation function.
[0031] Optionally, the method for adding noise to the gradient norm is as follows:
[0032]
[0033] Among them, g a Let ||g| represent the gradient of project group a. a || represents the gradient norm of project group a. This represents the gradient norm after adding noise. It is a function with a mean of 0 and a covariance of σ′ 2 The distribution is Gaussian, and β represents the scaling parameter.
[0034] Optionally, the method for calculating the sampling probability of each project group based on the gradient norm after adding noise is as follows:
[0035]
[0036] Among them, h a Let A represent the sampling probability of project group a, and let A represent the set of project groups.
[0037] The beneficial effects of the present invention are:
[0038] This invention introduces a privacy protection mechanism based on differential privacy, which effectively improves the recommendation quality of a recommendation system while ensuring user data privacy. Compared with traditional privacy protection methods, differential privacy methods can protect sensitive user data while maintaining recommendation accuracy to the greatest extent. This invention employs dynamic noise and an adaptive gradient pruning adjustment algorithm to dynamically optimize the noise addition method according to different data features, thereby reducing the negative impact of privacy protection on recommendations. This method not only alleviates the damage to recommendation accuracy caused by traditional privacy protection algorithms, but also improves the overall user experience of the system through an adaptive adjustment mechanism.
[0039] The fairness enhancement strategy proposed in this invention effectively mitigates potential item bias in recommender systems, ensuring that items from different groups receive recommendations fairly. This fairness enhancement method can ensure diversity and impartiality in large-scale recommender systems, increase user trust in the system, and promote the healthy development of the platform. Attached Figure Description
[0040] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0041] Figure 1 This is a flowchart illustrating the improved and optimized method for constructing and training a large-scale recommendation model according to an embodiment of the present invention.
[0042] Figure 2 This is a schematic diagram illustrating the structural framework and training process of a large-scale recommendation model according to an embodiment of the present invention;
[0043] Figure 3 This is a flowchart of the improved differential privacy stochastic gradient descent method according to an embodiment of the present invention;
[0044] Figure 4 This is a flowchart of the fair sampling mechanism in an embodiment of the present invention. Detailed Implementation
[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0046] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0047] This embodiment provides an information recommendation method based on privacy protection and fairness enhancement, such as Figure 1 Shown, including:
[0048] Obtain behavioral data from target users;
[0049] The behavioral data is input into a preset large-scale recommendation model, which outputs recommendation results for the target user. The large-scale recommendation model is constructed based on a user encoder and an item encoder. The large-scale recommendation model is trained on a training set, which includes several users and items. During the training of the large-scale recommendation model, an improved differential privacy stochastic gradient descent method is used to update the model parameters, and a gradient-based fair sampling mechanism is introduced during the training process.
[0050] Specifically, this embodiment introduces a privacy protection mechanism based on differential privacy, which effectively improves the recommendation quality of the recommendation system while ensuring user data privacy. Compared with traditional privacy protection methods, differential privacy methods can protect sensitive user data while maintaining recommendation accuracy to the greatest extent. This embodiment employs dynamic noise and an adaptive gradient pruning adjustment algorithm to dynamically optimize the noise addition method according to different data features, thereby reducing the negative impact of privacy protection on recommendations. This method not only alleviates the damage to recommendation accuracy caused by traditional privacy protection algorithms but also improves the overall user experience of the system through an adaptive adjustment mechanism.
[0051] The fairness enhancement strategy proposed in this embodiment effectively mitigates potential item bias in recommender systems, ensuring that items from different groups receive recommendations fairly. This fairness enhancement method can ensure diversity and impartiality in large-scale recommender systems, increase user trust in the system, and promote the healthy development of the platform.
[0052] Furthermore, during the training of the large-scale recommendation model, the improved differential privacy stochastic gradient descent method is used to update the model parameters, including:
[0053] In each iteration, samples are sampled and the gradient of the samples is calculated;
[0054] The gradient is adaptively clipped, and Gaussian noise is added to the clipped gradient to obtain a privacy gradient.
[0055] The model parameters are updated based on the privacy gradient.
[0056] Specifically, the method for calculating the gradient of the sample is as follows:
[0057]
[0058] Among them, g t,i Let represent the gradient of sample i in the t-th iteration, and ← denotes assignment. To express differentiation, Let be the BPR loss for sample i.
[0059] Specifically, the method for adaptively pruning the gradient is as follows:
[0060]
[0061] in, Let ||g| represent the gradient after clipping, C be the clipping threshold, r be the regularization term, and ||g| be the gradient after clipping. t,i || represents g t,i The l2-norm.
[0062] Specifically, the method for adding Gaussian noise to the clipped gradient to obtain the privacy gradient is as follows:
[0063]
[0064] in, Representing the privacy gradient, B t Let be the sampled in the t-th iteration, and ⊙ represent the product of the elements of the two vectors. It is a function with a mean of 0 and a covariance of σ. 2 Gaussian distribution, δ e ∈{0,1} p+e This is used to determine whether noise needs to be added to the gradient value of the corresponding parameter, where p is the number of non-embedded parameters and e is the number of embedded parameters.
[0065] Furthermore, the introduction of a gradient-based fair sampling mechanism during the training process includes:
[0066] After a training epoch, calculate the cross-entropy loss for each project group, and calculate the gradient and gradient norm for each project group.
[0067] Noise is added to the gradient norm, and the sampling probability of each project group is calculated based on the gradient norm after adding noise.
[0068] In the next training round, the project samples are trained based on the sampling probability.
[0069] Specifically, the method for calculating the cross-entropy loss for each project group is as follows:
[0070]
[0071] Among them, L a Y represents the cross-entropy loss of project group a. a Let represent the set of all user-item pairs in project group a, Q represent the predicted score from user u to item v, and σ(·) represent the sigmoid activation function.
[0072] Specifically, the method for adding noise to the gradient norm is as follows:
[0073]
[0074] Among them, g a Let ||g| represent the gradient of project group a. a || represents the gradient norm of project group a. This represents the gradient norm after adding noise. It is a function with a mean of 0 and a covariance of σ′ 2 The distribution is Gaussian, and β represents the scaling parameter.
[0075] Specifically, the method for calculating the sampling probability of each project group based on the gradient norm after adding noise is as follows:
[0076]
[0077] Among them, h a Let A represent the sampling probability of project group a, and let A represent the set of project groups.
[0078] The following combination Figure 1-Figure 4 The construction and training optimization of the large-scale recommendation model in this embodiment are described in detail, including the following:
[0079] (1) Obtain user-related behavioral data and perform relevant preprocessing. The dataset D consisting of n preprocessed data points will be used as input for a large-scale recommendation model.
[0080] In recommendation-related scenarios, dataset D typically includes two entity sets: a user set U = (|U| = M) and an item set V = (|V| = N), where the set of items that have interacted with user u is denoted as R. u .
[0081] (2) Figure 2 As shown, a large-scale recommendation model with two encoders is constructed, including a user encoder and an item encoder. Depending on the task, these two encoders can be composed of neural networks or Transformers. Let θ represent the parameters of this dual-encoder model, where the number of non-embedded layer parameters is p and the number of embedded layer parameters is e. The learning rate is set to η, and the model will be trained on the following optimization problem:
[0082]
[0083] in, For a large-scale recommendation model, the BPR loss is given by σ(·), where σ is the sigmoid activation function and D is the value of D. u Let D be the set of tuples containing items v that user u has interacted with and items k that user u has not interacted with. u ={(v,k)|v∈R u ∩k∈VR u}, where u is the user, M is the number of users, v is the number of items interacted with, k is the number of items not interacted with, and Q is the number of items not interacted with. + =e u e v Q - =e u e k , e indicates embedding.
[0084] (3) Figure 3 As shown, an improved differential privacy stochastic gradient descent method is used to update the model parameters. While protecting gradient privacy, the training speed of the model is improved by ensuring gradient sparsity, and the utility of the model is improved by adaptive pruning.
[0085] In each training epoch, samples are sampled and their gradients are calculated; the gradients are adaptively cropped, and Gaussian noise is added to the cropped gradients to obtain privacy gradients; the model parameters are updated based on these privacy gradients. Specifically, this includes the following steps:
[0086] (3.1) First, for each iteration t, Poisson sampling is used to sample a mini-batch of samples B. t For each sample, calculate its corresponding gradient:
[0087]
[0088] Among them, gt,i Let represent the gradient of sample i in the t-th iteration, and ← denotes assignment. To express differentiation, Let be the BPR loss for sample i.
[0089] (3.2) For the gradient of each sample, calculate the corresponding l2 norm ||g t,i Using the following non-monotonic adaptive weighting formula, while ensuring gradient sensitivity, small gradient samples are assigned a weight close to 1, while large gradients are assigned a weight close to... Weights:
[0090]
[0091] in, This represents the gradient after clipping, where C is the clipping threshold and r is the regularization term to improve training stability.
[0092] (3.3) Generate privacy gradients by injecting Gaussian noise into the sum of the clipped gradients:
[0093]
[0094] Where ⊙ represents the product of the elements of two vectors. It is a function with a mean of 0 and a covariance of σ. 2 Gaussian distribution, δ e ∈{0,1} p+e This is used to determine whether noise needs to be added to the gradient values of the corresponding parameters, where p is the number of non-embedded parameters and e is the number of embedded parameters. The determination rule is as follows:
[0095]
[0096] By ensuring gradient sparsity in large-scale recommendation models, training speed can be improved by adding noise only to the non-zero gradients of the embedding layers.
[0097] (3.4) The noise multiplier σ is calculated from the privacy budget (ε, δ) using inverse privacy accounting. In practice, (ε, δ) is typically calculated using Rayleigh differential privacy:
[0098]
[0099] Where α>1, τ is calculated by the sampling Gaussian mechanism, and δ is manually set, usually as the reciprocal of the dataset size, or 10. -5 .
[0100] (4) During the learning process, the recommendation results gradually meet the requirements of project fairness. This embodiment uses a gradient-based fair sampling method to achieve this, such as... Figure 4 As shown, after the end of one training round, calculate the cross-entropy loss of each item group, and calculate the gradient and gradient norm of each item group; add noise to the gradient norm, and calculate the sampling probability of each item group based on the gradient norm after adding noise; in the next training round, train the item samples based on the sampling probability. Specifically, it includes the following steps:
[0101] (4.1) To measure the impact of fairness, the recall rate difference between groups should be used. Since this recall rate difference is non-differentiable, in this embodiment, the cross-entropy loss is used as an approximation of the recall rate.
[0102] After the end of one training round, calculate the cross-entropy loss of each item group:
[0103]
[0104] Among them, Y a represents all user-item sets of item group a, and Q represents the predicted score from user u to item v. Taking the binary group (a ∈ {0, 1}) as an example, if L0 < L1, it means that the recall ability of item group 1 (the disadvantaged group) is lower, that is, the recommendation model assigns a lower recommendation probability to the items in group 1. This gap between groups leads to a larger gradient norm for the samples in group 1 compared to the samples in group 0. Using this discovery, the subsequent item fairness enhancement scheme can be designed.
[0105] After taking the derivative of the cross-entropy loss, obtain the gradient between groups, and calculate its l2-norm:
[0106]
[0107] (4.2) Set a partial noise multiplier σ′ and a scaling parameter β to add noise protection to each gradient norm, so that the process of setting the sampling probability satisfies the definition of differential privacy:
[0108]
[0109] (4.3) The sampling probability of each group is proportional to its gradient norm, as follows:
[0110]
[0111] Among them, A represents the set of item groups. This sampling probability will be updated after the end of each training round and before the start of the next training round.
[0112] (4.4) In the next training round, the set sampling probability will be used to train the negative samples, but simply using sampling cannot well eliminate the bias. In this embodiment, a simple random augmentation operation is used To further improve fairness, the project feature augmentation and user behavior sequence augmentation can be used to oversample the samples of the disadvantaged project group. Therefore, in the t-th iteration, a fair sampling method is used to sample a small batch of negative samples k∈VR. u ~h. The final model update steps can be represented as:
[0113]
[0114] Where, θ t+1 For the model in the (t+1)th iteration, θ t The model in the t-th iteration, where η is the learning rate, B t The sample is the one taken in the t-th iteration.
[0115] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made to the technical solutions of the present invention by those skilled in the art without departing from the spirit of the present invention should fall within the protection scope defined by the claims of the present invention.
Claims
1. An information recommendation method based on privacy protection and fairness enhancement, characterized in that, include: Obtain behavioral data from target users; The behavioral data is input into a preset large-scale recommendation model, and the recommendation result for the target user is output. The large-scale recommendation model is constructed based on a user encoder and an item encoder. The large-scale recommendation model is trained based on a training set, which includes several users and items. During the training process of the large-scale recommendation model, an improved differential privacy stochastic gradient descent method is used to update the model parameters, and a gradient-based fair sampling mechanism is introduced during the training process. The improved differential privacy stochastic gradient descent method is used to update the model parameters during the training process of the large-scale recommendation model, including: In each iteration, samples are sampled and the gradient of the samples is calculated; The gradient is adaptively clipped, and Gaussian noise is added to the clipped gradient to obtain a privacy gradient. The model parameters are updated based on the privacy gradient; The method for adaptively pruning the gradient is as follows: in, Let g denote the gradient after clipping, C be the clipping threshold, r be the regularization term, and ||g||. t,i || represents g t,i The l2 norm, g t,i Let be the gradient of sample i in the t-th iteration; The method for obtaining the privacy gradient by adding Gaussian noise to the clipped gradient is as follows: in, Represents the privacy gradient, B t Let be the sampled in the t-th iteration, and ⊙ represent the product of the elements of the two vectors. It is a function with a mean of 0 and a covariance of σ. 2 Gaussian distribution, δ e ∈{0,1} p+e This is used to determine whether noise needs to be added to the gradient value of the corresponding parameter, where p is the number of non-embedded parameters and e is the number of embedded parameters.
2. The information recommendation method based on privacy protection and fairness enhancement according to claim 1, characterized in that, The method for calculating the gradient of the sample is as follows: Among them, g t,i Let represent the gradient of sample i in the t-th iteration, and ← denotes assignment. To express differentiation, Let be the BPR loss for sample i.
3. The information recommendation method based on privacy protection and fairness enhancement according to claim 1, characterized in that, Introducing a gradient-based fair sampling mechanism during the training process includes: After a training epoch, calculate the cross-entropy loss for each project group, and calculate the gradient and gradient norm for each project group. Noise is added to the gradient norm, and the sampling probability of each project group is calculated based on the gradient norm after adding noise. In the next training round, the project samples are trained based on the sampling probability.
4. The information recommendation method based on privacy protection and fairness enhancement according to claim 3, characterized in that, The method for calculating the cross-entropy loss for each project group is as follows: Among them, L a Y represents the cross-entropy loss of project group a. a Let represent the set of all user-item pairs in project group a, Q represent the predicted score from user u to item v, and σ(·) represent the sigmoid activation function.
5. The information recommendation method based on privacy protection and fairness enhancement according to claim 4, characterized in that, The method for adding noise to the gradient norm is as follows: Among them, g a Let ||g| represent the gradient of project group a. a || represents the gradient norm of project group a. This represents the gradient norm after adding noise. It is a function with a mean of 0 and a covariance of σ′ 2 The distribution is Gaussian, and β represents the scaling parameter.
6. The information recommendation method based on privacy protection and fairness enhancement according to claim 5, characterized in that, The method for calculating the sampling probability of each project group based on the gradient norm after adding noise is as follows: Among them, h a Let A represent the sampling probability of project group a, and let A represent the set of project groups.
Citation Information
Patent Citations
Recommendation method based on self-attention mechanism
CN113822742A
Sample sampling method, device and system, electronic equipment and storage medium
CN114529009A
Federal learning privacy protection method based on adaptive differential privacy
CN116340990A