A Smart Privacy-Preserving Learning Method by Fake Gradients to Protect Users Items in Recommender Systems
Guixun Luo,
Zhiyuan Zhang,
Zhenjiang Zhang,
Yun Liu,
Lifu Wang
Affiliations
Guixun Luo
School of Computer and Information Technology, Beijing Jiaotong University, Beijing 100044, China
Zhiyuan Zhang
School of Electronic and Information Engineering, Key Laboratory of Communication and Information Systems, Beijing Municipal Commission of Education, Beijing Jiaotong University, Beijing 100044, China
Zhenjiang Zhang
School of Software Engineering, Beijing Jiaotong University, Beijing 100044, China
Yun Liu
School of Electronic and Information Engineering, Key Laboratory of Communication and Information Systems, Beijing Municipal Commission of Education, Beijing Jiaotong University, Beijing 100044, China
Lifu Wang
School of Electronic and Information Engineering, Key Laboratory of Communication and Information Systems, Beijing Municipal Commission of Education, Beijing Jiaotong University, Beijing 100044, China
In this paper, we study the problem of protecting privacy in recommender systems. We focus on protecting the items rated by users and propose a novel privacy-preserving matrix factorization algorithm. In our algorithm, the user will submit a fake gradient to make the central server not able to distinguish which items are selected by the user. We make the Kullback–Leibler distance between the real and fake gradient distributions to be small thus hard to be distinguished. Using theories and experiments, we show that our algorithm can be reduced to a time-delay SGD, which can be proved to have a good convergence so that the accuracy will not decline. Our algorithm achieves a good tradeoff between the privacy and accuracy.