Private Recommendation Factor Model Data Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing recommender systems fail to effectively obfuscate user engagement histories, leaving them vulnerable to discovery by unauthorized entities, even when differential privacy methods are employed during the learning phase.
Innovation Solution
The method involves using a processor to receive user ratings, estimate a user weight vector in a factor model, generate a rating vector through alternating minimization, and send it to the client device while deleting the original ratings, thereby enhancing user privacy by not retaining the ratings used for model development.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If differential privacy methods are employed during the learning phase, then user privacy is improved, but the engagement history remains vulnerable to discovery by unauthorized entities
Solution Approach 1:
The patent extracts and deletes the original user ratings data after using it to train the factor model. By removing the raw engagement history from the server's memory, the system eliminates the primary data source that could be exploited by unauthorized entities, while still maintaining the privacy benefits of differential privacy during the training phase.
Solution Approach 2:
The patent introduces a factor model as an intermediary between the user's engagement history and the recommendations. This intermediate representation captures user preferences without storing the actual engagement data, creating a layer of abstraction that prevents direct access to sensitive user information while enabling personalized recommendations.
2Measurement precision
If raw user ratings are retained on the server for model training, then recommendation accuracy is improved, but the risk of data exposure increases
Solution Approach 1:
The patent treats the raw user ratings as temporary, disposable data that is used only for training the factor model and then immediately deleted. This approach allows the system to benefit from having access to the data during training while eliminating the long-term storage risk associated with retaining sensitive user information on the server.
Solution Approach 2:
The patent discards the original ratings data after extracting the necessary information to train the factor model. The system recovers the essential user preference patterns through the factor model without retaining the original data, achieving a separation between the functional need for user information and the security requirement to delete it.
3Productivity
If the server stores user engagement history for personalized recommendations, then recommendation quality is improved, but user privacy is compromised
Solution Approach 1:
The patent creates a conceptual copy of user preferences through the factor model rather than storing the actual engagement history. This copy captures the essential patterns needed for personalized recommendations while being fundamentally different from the original data, allowing the server to provide quality recommendations without holding sensitive user information.
Solution Approach 2:
The patent transforms the data from its original form (raw ratings) into a different parameter space (factor model representations). This transformation changes the nature of the stored data from sensitive user interactions to abstracted preference vectors that enable recommendations while being less susceptible to direct exploitation.
Data Source
AI summary
Methods and systems for recommending content to a client device operated by a user include receiving a set of ratings for each of a first set of content items by a user from a client device for use in a factor model. The set of ratings is not maintained in the server for longer than necessary to calculate a rating vector and/or to update a matrix factor defined by the rank of the factor model and a total number of content items eligible for ranking.


