Privacy evaluation and defense method and system of cross-domain recommendation system and storage medium
Patent Information
- Application Number
- CN202610782402.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-02
- Publication Date
- 2026-09-25
AI Technical Summary
因此,该领域亟需解决两大核心挑战:一方面,亟需构建一种鲁棒的攻击评估框架,使其能够在各个领域嘈杂的推荐列表中有效解耦领域特定噪声,并精准提取跨域不变的用户兴趣作为稳健的“身份指纹” ;另一方面,针对该漏洞的防御机制设计绝不能以牺牲原有的系统效用为代价,必须在有效降低账号可链接性与严格保留推荐实用性之间取得最优的平衡
[0022]第三方面,基于上述方案,本发明提供一种计算机可读存储介质,其上存储有计算机程序,该程序被处理器执行时实现所述的跨域推荐系统的隐私评估与防御方法。
Smart Images

Figure CN122818397A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of information systems and deep learning security, specifically relating to privacy assessment and defense methods, systems, and storage media for cross-domain recommendation systems. Background Technology
[0002] Cross-domain recommendation uses data from one domain to recommend items to another. By transferring knowledge between different domains, it effectively alleviates the data sparsity and cold start problems faced by traditional recommendation systems, and is widely used in e-commerce, video, and other platforms. In actual deployment, this knowledge transfer usually relies on sharing user representations or cross-domain alignment goals. However, while significantly improving the accuracy of personalized recommendations, cross-domain recommendation also raises easily overlooked privacy risks. In real-world scenarios, most users tend to maintain strict identity isolation between different online services (such as video and reading platforms) and do not want their accounts distributed across various independent domains to be linked together.
[0003] However, this expectation of identity segregation is under serious threat, as cross-domain user re-identification attacks have an extremely low threshold for implementation in reality. First, although the internal model parameters of recommendation systems are strictly confidential, the Top-K recommendation lists routinely exposed to end users highly condense users' deep preferences, forming easily observable and highly identifiable "behavioral fingerprints." Second, a small number of accounts voluntarily and publicly share cross-domain connections in the real-world network ecosystem (e.g., for commercial promotion purposes). This public information provides attackers with genuine public link seeds. Based on these conditions, attackers can launch attacks under strict black-box conditions, using only publicly available Top-K lists, and accurately infer whether anonymous accounts from different domains belong to the same real-world individual.
[0004] However, existing research on cross-domain privacy protection mainly focuses on attribute inference and membership inference. For the "cross-domain user re-identification" vulnerability—a security vulnerability unique to cross-domain recommendation scenarios and potentially extremely dangerous—the academic community still lacks systematic evaluation and exploration. Therefore, this field urgently needs to address two core challenges: First, it urgently needs to construct a robust attack assessment framework that can effectively decouple domain-specific noise from noisy recommendation lists across various domains and accurately extract cross-domain invariant user interests as robust "identity fingerprints"; second, the design of defense mechanisms against this vulnerability must not sacrifice the original system utility, but must achieve the optimal balance between effectively reducing account linkability and strictly preserving the practicality of recommendations. Summary of the Invention
[0005] Purpose of the invention: This invention provides a privacy assessment and defense method, system, and storage medium for cross-domain recommendation systems. It aims to utilize only the publicly available Top-K recommendation list as implicit feedback, and accurately extract users' cross-domain invariant interests as robust "identity fingerprints" through knowledge decoupling and comparative learning mechanisms. This overcomes the problems of existing cross-domain privacy research, such as the lack of systematic assessment of identity link threats and the over-reliance on the internal state of the model in traditional inference attacks.
[0006] Technical Solution: A privacy assessment and defense method for cross-domain recommendation systems, comprising a cross-domain recommendation privacy assessment and defense process based on knowledge decoupling and inverse contrastive learning, including: Acquire the interaction data of the target user in the first and second recommendation domains; Based on the interaction data, the cross-domain invariant representation and domain-specific representation of the target user are extracted through a multi-view decoupling model, and the cross-domain invariant representation and the domain-specific representation are fused to construct attack features in order to assess the risk of cross-domain identity re-identification. Based on the interaction data, determine the set of behaviorally similar neighbors of the target user; During the parameter update process of the cross-domain recommendation model, in response to the satisfaction of a preset trigger condition, a representation convergence constraint is activated. This representation convergence constraint is used to narrow the gap between the embedded representation of the target user and the original representation. The distance between the embedded representations of target neighbors sampled in a set of behaviorally similar neighbors; Based on the updated cross-domain recommendation model, cross-domain recommendation results are generated.
[0007] Furthermore, based on interactive data, a multi-view decoupling model is used to extract cross-domain invariant and domain-specific representations of the target user, including: Build interactive data into cross-domain global views and single-domain local views; The cross-domain global view is used to extract features through a graph convolutional encoder to obtain a global representation; The single-domain local view is decoupled by using a multi-factor graph convolution model, and the feature dimension is divided into multiple subspaces for independent propagation, so as to separate the cross-domain invariant representation from the domain-specific representation.
[0008] Furthermore, the optimization process of the multi-view decoupling model introduces a contrastive alignment objective, which includes cross-domain invariant alignment loss and factor-level contrastive learning loss. The formula for calculating the cross-domain invariant alignment loss is as follows:
[0009] in, For cosine similarity calculation, For temperature hyperparameters, Represents the current batch. This represents a sample set of users with known cross-domain relationships. and These are the cross-domain invariant representations of the same user in two recommendation domains, respectively. The formula for calculating the factor-level contrastive learning loss is as follows:
[0010] in, and These are the normalized domain-specific representations.
[0011] Furthermore, the attack features are constructed by fusing the cross-domain invariant representation with the domain-specific representation, including: The multi-view representations are initially stitched together to obtain the stitched vector; Calculate the absolute difference between the cross-domain invariant representations under the first recommendation domain and the second recommendation domain; Calculate the element-wise product of the cross-domain invariant representations under the first recommendation domain and the second recommendation domain; The concatenated vector, the absolute difference, and the element-wise product are fused to generate a composite attack feature vector. The composite attack feature vector is represented as follows:
[0012] in, For the concatenated vector, The absolute difference, For the element-level product, This indicates a splicing operation; the assessment of cross-domain identity re-identification risk includes inputting the composite attack feature vector into a multilayer perceptron classifier, and predicting the probability of anonymous users linking to the same entity by minimizing the binary cross-entropy loss function.
[0013] Furthermore, based on the interaction data, a set of behaviorally similar neighbors for the target user is determined, including: Based on the set of items that the target user has interacted with in the first recommendation domain and the second recommendation domain, calculate the behavioral similarity between any two users; A predetermined number of users with the highest behavioral similarity scores are selected to form the behavioral similarity neighbor set for the target user. The formula for calculating the behavioral similarity is:
[0014] in, and users respectively and users A collection of all interacted items; The target neighbor sampled from the set of behaviorally similar neighbors is: a neighbor node is randomly sampled uniformly from the set of behaviorally similar neighbors as the target neighbor.
[0015] Furthermore, the representation proximity constraint is used to minimize the sum of the distances between the embedded representation of the target user and the embedded representation of the target neighbor in the first recommendation domain and the second recommendation domain; The preset triggering condition is a comparison indicator function based on the current training round and the preset warm-up period, so as to control the representation convergence constraint to be activated only when the current training round is greater than the preset warm-up period.
[0016] Furthermore, traditional contrastive learning aims to bring the representations of the same user closer together and push apart the representations of different users to enhance discriminative power. This invention brings the target user's representation closer to the representations of its neighbors, aiming to break the uniqueness of user representations in the latent space and integrate them into the feature distribution of similar groups, thereby achieving an identity confusion effect similar to k-anonymization. The representation-bringing constraint is not always in effect throughout the entire training process, but is controlled by preset triggering conditions. This is because in the early stages of model training, the recommendation model has not yet fully learned the user's basic preference distribution. Forcibly imposing privacy constraints at this time would lead to conflicting optimization objectives, severely impairing the model's convergence performance and recommendation accuracy. By setting triggering conditions (e.g., a warm-up mechanism based on training rounds), this invention ensures that the defense mechanism only intervenes for fine-tuning after the model has acquired a certain recommendation capability, thus achieving a dynamic balance between privacy protection and recommendation utility.
[0017] Furthermore, to balance privacy protection and recommendation utility, this invention introduces a dynamic activation mechanism based on the training phase. The preset triggering condition is a comparison indicator function based on the current training epoch and a preset warm-up period, controlling that the representation convergence constraint is activated only when the current training epoch is greater than the preset warm-up period. Specifically, the model's joint optimization total loss function is defined as:
[0018] in, The main loss function for recommendation tasks (such as BPR loss). To control the hyperparameters of privacy protection strength, For the current training round, For the preset preheating cycle, For indicator functions, when The value is 1 if the condition is met, and 0 otherwise. The design principle of this warm-up mechanism is that in the early stages of model training, the recommendation model has not yet fully learned the user's basic preference distribution. If a reverse contrast constraint is forcibly applied at this time, it will cause a severe gradient conflict between the privacy optimization objective and the recommendation optimization objective, making it difficult for the model to converge or even completely losing its recommendation ability. By setting a warm-up period… This allows the model to focus on learning accurate personalized preferences first, and then activate defensive constraints for fine-tuning after the representation space has been initially formed, effectively avoiding the instability of early optimization. Meanwhile, the weight parameters... It provides a flexible adjustment knob, enabling the system to adaptively configure itself based on varying tolerances for privacy and utility in different business scenarios. For example, in privacy-critical scenarios such as finance or healthcare recommendations, the adjustment knob can be appropriately increased. This enhances the obfuscation effect; however, in precision-sensitive e-commerce scenarios, it can reduce... To retain more personalized details.
[0019] Based on the above approach, this invention proposes a complete "risk assessment-privacy defense" framework to address the threat of cross-domain user re-identification caused by the public Top-K recommendation lists in cross-domain recommendation systems. Specifically, in the risk assessment phase, a shadow graph relying solely on the recommendation list is constructed, and multi-view knowledge is used to decouple contrastive learning to separate domain-invariant and domain-specific preferences, training a classifier to accurately assess the system's re-identification vulnerabilities. In the privacy defense phase, a similarity graph based on user interaction behavior is constructed, and a random sampling inverse contrastive learning mechanism is introduced into the model training to shorten the representation distance between the user and their behavioral neighbors in the latent space.
[0020] On the other hand, the present invention also provides a privacy assessment and defense system for cross-domain recommendation systems, comprising: The data acquisition module is used to acquire the interaction data of the target user in the first recommendation domain and the second recommendation domain; The risk assessment module is used to extract the cross-domain invariant representation and domain-specific representation of the target user based on the interaction data through a multi-view decoupling model, and to fuse the cross-domain invariant representation and the domain-specific representation to construct attack features in order to assess the risk of cross-domain identity re-identification. A neighbor building module is used to determine a set of behaviorally similar neighbors of the target user based on the interaction data. The constraint optimization module is used to activate the representation merging constraint in response to the satisfaction of a preset trigger condition during the parameter update of the cross-domain recommendation model. The representation merging constraint is used to reduce the distance between the embedded representation of the target user and the embedded representation of the target neighbor sampled from the set of behaviorally similar neighbors. The recommendation generation module is used to generate cross-domain recommendation results based on the updated cross-domain recommendation model.
[0021] When the system is running, it executes the aforementioned attack and defense methods, and the system can be applied to any two recommendation domains containing the same user entities, including cross-domain recommendation tasks such as clothing-beauty and movies-music.
[0022] Thirdly, based on the above solution, the present invention provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the privacy assessment and defense method of the cross-domain recommendation system.
[0023] Beneficial Effects: The method described in this invention can be evaluated using only the publicly available Top-K recommendation list. Through multi-view feature decoupling, domain-specific noise is effectively removed, and highly stable cross-domain identity fingerprints are extracted, resulting in evaluation results significantly superior to traditional membership inference or attribute inference methods. This invention innovatively proposes a reverse contrastive learning defense mechanism, which effectively obscures the user's unique "digital fingerprint" by randomly pulling the target user's representation towards the representations of its behaviorally similar neighbors in the latent space, achieving high-strength privacy protection similar to k-anonymization in a continuous space. This invention not only accurately quantifies the risk of user identity linking in cross-domain recommendation systems but also achieves representation obfuscation similar to k-anonymization with almost no loss of recommendation utility, significantly improving the system's privacy and security. Attached Figure Description
[0024] Figure 1 This is a model framework diagram constructed by the method described in this invention; Figure 2 This is a schematic diagram of the re-identification risk assessment process based on decoupling and contrastive learning as described in this invention.
[0025] Figure 3 This is a schematic diagram of the privacy defense process based on reverse contrastive learning as described in this invention. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0027] like Figure 1-3 As shown, the privacy assessment and defense method for a cross-domain recommendation system provided by this invention includes the following specific implementation steps: S1. Construct risk assessment data by obtaining the Top-K recommendation lists publicly available from the target cross-domain recommendation system in Domain A (first recommendation domain) and Domain B (second recommendation domain) as implicit feedback. Domain A and Domain B can be any two service platforms with potentially overlapping users but different business content, such as an e-commerce platform and a video platform, or a sports equipment store and a beauty store. Interaction data includes not only explicit user ratings or reviews, but more importantly, the Top-K recommendation lists publicly available to end users by the system, as well as implicit feedback behaviors such as user clicks, browsing, and purchases. The two recommendation domains are business-independent, but some cross-domain accounts belong to the same real individual.
[0028] In this embodiment, a single-domain graph is first constructed based on the recommendation lists within each domain. and Subsequently, a small set of known publicly known cross-domain linking users (i.e., shadow users) was introduced. ), construct a global shadow graph In building At the same time, a node merging strategy is implemented for shadow users, unifying their source and target domain nodes into shared nodes to bridge the two domains; a node splitting strategy is implemented for non-shadow users to strictly prevent the leakage of real-time ground information.
[0029] S2. Perform multi-view knowledge decoupling representation learning on the single-domain graph to extract the user's domain-invariant representation and domain-specific representation under the single-domain view; perform lightweight graph convolution on the cross-domain global shadow graph to extract the user's global representation under the global view.
[0030] To capture high-order cooperative signals across domains, in the global shadow graph The LightGCN encoder is used for global view learning.
[0031] set up For the initialized node embedding matrix, the first... The propagation formula for the layer representation is:
[0032] in, It is the adjacency matrix (including self-loops) of the global graph. This is a degree matrix. After... After layer propagation, extract the user's global overall representation. .
[0033] S3. For some known publicly linked users (shadow users), construct cross-domain invariant contrastive learning objectives, align the domain-invariant features of the same user in domain A and domain B, and establish cross-domain association channels.
[0034] This step separates stable inter-domain preferences from domain-specific noise in a single-domain graph. and Perform latent factor decoupling based on multi-factor graph convolution. Divide the feature dimensions into... Each independently evolving subspace (in this embodiment) ), No. The propagation formula for each subspace is:
[0035] in, For a specific factor, a trainable weight matrix, This is the activation function. After... After the layer network, the user's domain-invariant representation is extracted respectively. ) and domain-specific representations ( ).
[0036] This step introduces a dual contrastive learning objective to encourage the shadow model to mimic the cross-domain alignment logic of the target system. First, for the shadow user set... We construct a cross-domain invariant alignment loss to bring the domain-invariant representations of the same user across different domains closer together.
[0037] in, To calculate cosine similarity, For temperature hyperparameters, Represents the current batch. This represents a set of shadow users.
[0038] S4. For some known publicly linked users across domains (shadow users), construct a multi-factor contrastive learning objective to maximize the mutual information between specific representations of the same user in domain A and domain B, unify the domain-specific preferences of the same user in different domains, and thus enhance the uniqueness of attack features.
[0039] Secondly, a factor-level contrastive learning loss is constructed to maximize the domain-specific representations of the same user across different domains (after...). After normalization Mutual information between them:
[0040] in, , , This is a temperature hyperparameter (typically adjusted between 0.05 and 0.5 depending on the size of the dataset and the noise level). This represents the current batch. Then, the two contrastive losses mentioned above are jointly optimized with the BPR loss from the recommendation task to complete the training of the shadow model.
[0041] S5. Re-identification Risk Assessment: Combine the multi-view representations extracted in step S2 to construct a composite attack feature vector, train a binary classifier to predict the link probability of anonymous user pairs in domain A and domain B, and quantify the re-identification vulnerability of the system.
[0042] This step involves using a trained shadow model to extract multi-view representations and constructing a representation for anonymous users. Composite attack feature vector The specific steps are as follows: By stitching together all view features Calculate the absolute difference of the invariant representation. To measure invariance differences and to compute element-wise products To capture the joint activation state.
[0043] The final feature is represented as:
[0044] The feature vector is input into a three-layer multilayer perceptron classifier, and the loss function is minimized by minimizing the binary cross-entropy function. The system predicts the probability that two users belong to the same entity, thereby quantifying the risk of re-identification in the system.
[0045] S6. Defense Neighbor Graph Construction: Calculate the Jaccard similarity between users based on their historical interaction records in domains A and B, and select a set of neighbors with similar behaviors for each user.
[0046] To address the identified privacy vulnerabilities, a defense mechanism is activated. First, an "anonymous set" of each user's behavior is identified. This is based on the union of items the user has interacted with in the source and target domains (let's assume...). and users respectively and users The similarity between any two users is calculated using the Jaccard coefficient (the union of all interacted items).
[0047] For each user Select the top-K users with the highest similarity scores to form their behavioral neighbor set. .
[0048] S7. Reverse Contrast Defense: In the recommendation model training iteration, a random sampling strategy is used to select target neighbors from the neighbor set, constructing a reverse contrast loss to minimize the distance between the user embedding and the target neighbor embedding in order to confuse identity features.
[0049] Unlike traditional contrastive learning, which aims to differentiate users, this stage introduces inverse contrastive learning to obfuscate digital fingerprints. At each step of model training, this is done for each user... From its neighbor set Uniformly randomize a target neighbor :
[0050] Subsequently, the inverse contrast loss was calculated. This regularization shortens the distance between the user embedding and its sampled neighbor embeddings in the latent space, and is applied to both domains simultaneously.
[0051] in, For training batches, Embedding representations for users, These are neighbor nodes that are uniformly and randomly sampled from the neighbor set.
[0052] This step prevents user representations from becoming unique outliers in the latent space through a dynamic stretching effect.
[0053] S8. Joint Optimization Output: A preheating mechanism is introduced to jointly optimize the recommendation task loss and the inverse comparison loss, outputting a cross-domain recommendation model and recommendation results with resistance to re-identification attacks. This step integrates the inverse comparison regularization term into the optimization objective of the main recommendation task.
[0054] To prevent privacy constraints from interfering with the model's initial learning of user preferences, a warm-up mechanism is introduced. The final joint loss function is defined as:
[0055] in, To recommend losses, To control the hyperparameters of privacy protection strength, For the current training round, For the preset preheating cycle, This is an indicator function.
[0056] Optimizing this objective function will yield a cross-domain recommendation model that balances high recommendation effectiveness with strong resistance to duplicate detection attacks.
[0057] This embodiment uses real-world Amazon cross-domain datasets (such as Phone-Sport, Cloth-Beauty, Video-Toy, and Movie-CD) for validation, as shown in Table 1. This embodiment covers various mainstream recommendation frameworks, including Classical Matrix Factorization (CMF), Graph Neural Networks (BiTGCF, CoPD), and Decoupled Matrix Approach (DIDA). During the risk assessment phase, without deployed defense mechanisms, using the Phone-Sport dataset combined with the CoPD model as an example, the evaluation method of this invention (LiSA-Link) successfully exposed extremely high re-identification risks, with an Attack AUC as high as 0.9687 and an F1-Score of 0.9211, significantly demonstrating the existence of serious privacy vulnerabilities in cross-domain systems. After deploying the reverse comparison defense mechanism (DeLink-RCL) of this invention, the system's security is significantly improved. Similarly, on the Phone-Sport dataset, the Attack AUC of the CoPD model dropped significantly to 0.8659; in the BiTGCF model, the Attack AUC plummeted from 0.8527 to 0.6842, severely degrading the attacker's linking ability. Crucially, this defense mechanism provides strong privacy protection while almost completely preserving recommendation performance, with minimal fluctuation in the HR@10 recommendation hit rate. In some architectures, such as BiTGCF, the regularization of the defense mechanism filters out specific noise, and the HR@10 actually increases from 0.4132 to 0.4659, achieving a perfect balance between privacy protection and recommendation utility.
[0058] Table 1. Test results of this invention based on Amazon cross-domain dataset
[0059] The above embodiments are only for helping to understand the present invention and are not intended to limit the scope of the present invention. Other embodiments implemented by those skilled in the art based on the content of the present invention without inventive effort are all within the protection scope of the present invention. The description in this specification should not be considered as a limitation of the present invention. Any modifications, equivalent substitutions, or improvements made within the core ideas and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A privacy assessment and defense method for a cross-domain recommendation system, characterized in that, This method includes a cross-domain recommendation privacy assessment and defense process based on knowledge decoupling and inverse contrastive learning, and also includes: Acquire the interaction data of the target user in the first and second recommendation domains; Based on the interaction data, the cross-domain invariant representation and domain-specific representation of the target user are extracted through a multi-view decoupling model, and the cross-domain invariant representation and the domain-specific representation are fused to construct attack features in order to assess the risk of cross-domain identity re-identification. Based on the interaction data, determine the set of behaviorally similar neighbors of the target user; During the parameter update process of the cross-domain recommendation model, in response to the satisfaction of a preset trigger condition, a representation convergence constraint is activated. This representation convergence constraint is used to narrow the gap between the embedded representation of the target user and the original representation. The distance between the embedded representations of the target neighbors sampled in the set of behaviorally similar neighbors; Based on the updated cross-domain recommendation model, cross-domain recommendation results are generated.
2. The privacy assessment and defense method for cross-domain recommendation systems according to claim 1, characterized in that, The process of extracting the cross-domain invariant representation and domain-specific representation of the target user includes: Build interactive data into cross-domain global views and single-domain local views; The cross-domain global view is used to extract features through a graph convolutional encoder to obtain a global representation; The local view of a single domain is decoupled by a multi-factor graph convolution model, and the feature dimension is divided into multiple subspaces for independent propagation, so as to separate the cross-domain invariant representation and the domain-specific representation.
3. The privacy assessment and defense method for cross-domain recommendation systems according to claim 2, characterized in that, The optimization process of the multi-view decoupling model introduces a contrastive alignment objective, which includes cross-domain invariant alignment loss and factor-level contrastive learning loss. The formula for calculating the cross-domain invariant alignment loss is as follows: in, For cosine similarity calculation, For temperature hyperparameters, Represents the current batch. This represents a sample set of users with known cross-domain relationships. and These are the cross-domain invariant representations of the same user in two recommendation domains, respectively. The formula for calculating the factor-level contrastive learning loss is as follows: in, and These are the normalized domain-specific representations.
4. The privacy assessment and defense method for cross-domain recommendation systems according to claim 1, characterized in that, The process of constructing attack features by integrating cross-domain invariant representations and domain-specific representations includes: The multi-view representations are initially stitched together to obtain the stitched vector; Calculate the absolute difference between the cross-domain invariant representations under the first recommendation domain and the second recommendation domain; Calculate the element-wise product of the cross-domain invariant representations under the first recommendation domain and the second recommendation domain; The concatenated vector, the absolute difference, and the element-wise product are fused to generate a composite attack feature vector.
5. The privacy assessment and defense method for cross-domain recommendation systems according to claim 4, characterized in that, The composite attack feature vector is represented as follows: in, For the concatenated vector, The absolute difference, For the element-level product, This indicates a splicing operation; the assessment of cross-domain identity re-identification risk includes inputting the composite attack feature vector into a multilayer perceptron classifier, and predicting the probability of anonymous users linking to the same entity by minimizing the binary cross-entropy loss function.
6. The privacy assessment and defense method for cross-domain recommendation systems according to claim 1, characterized in that, The process of determining the target user's behaviorally similar neighbor set includes: Based on the set of items that the target user has interacted with in the first recommendation domain and the second recommendation domain, calculate the behavioral similarity between any two users; A preset number of users with the highest behavioral similarity scores are selected to form the target user's behavioral similarity neighbor set.
7. The privacy assessment and defense method for cross-domain recommendation systems according to claim 6, characterized in that, The formula for calculating the behavioral similarity is: in, and users respectively and users A collection of all interacted items; The target neighbor sampled from the set of behaviorally similar neighbors is: a neighbor node is randomly sampled uniformly from the set of behaviorally similar neighbors as the target neighbor.
8. The privacy assessment and defense method for cross-domain recommendation systems according to claim 1, characterized in that, The representation proximity constraint is used to minimize the sum of the distances between the embedded representation of the target user and the embedded representations of the target neighbors in the first recommendation domain and the second recommendation domain; The preset trigger condition is a comparison indicator function based on the current training round and the preset warm-up period, so as to control the representation to close the constraint only when the current training round is greater than the preset warm-up period.
9. A privacy assessment and defense system for a cross-domain recommendation system, characterized in that, include: The data acquisition module is used to acquire the interaction data of the target user in the first recommendation domain and the second recommendation domain; The risk assessment module is used to extract the cross-domain invariant representation and domain-specific representation of the target user based on the interaction data through a multi-view decoupling model, and to fuse the cross-domain invariant representation and the domain-specific representation to construct attack features in order to assess the risk of cross-domain identity re-identification. A neighbor building module is used to determine a set of behaviorally similar neighbors of the target user based on the interaction data. The constraint optimization module is used to activate the representation merging constraint in response to the satisfaction of a preset trigger condition during the parameter update of the cross-domain recommendation model. The representation merging constraint is used to reduce the distance between the embedded representation of the target user and the embedded representation of the target neighbor sampled from the set of behaviorally similar neighbors. The recommendation generation module is used to generate cross-domain recommendation results based on the updated cross-domain recommendation model.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 8.