{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T15:41:56Z","timestamp":1783525316295,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the Luxembourg National Research Fund","award":["C21\/IS\/16281848"],"award-info":[{"award-number":["C21\/IS\/16281848"]}]},{"name":"the Systematic Major Project of China State Railway Group Corporation Limited","award":["P2023W002"],"award-info":[{"award-number":["P2023W002"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3670365","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"2889-2903","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated Recommendation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9370-7958","authenticated-orcid":false,"given":"Yurong","family":"Hao","sequence":"first","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8131-5092","authenticated-orcid":false,"given":"Xihui","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Luxembourg, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0732-0261","authenticated-orcid":false,"given":"Xiaoting","family":"Lyu","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1147-4327","authenticated-orcid":false,"given":"Jiqiang","family":"Liu","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-8424-9418","authenticated-orcid":false,"given":"Yongsheng","family":"Zhu","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University &amp; China Academy of Railway Sciences Corporation Limited, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1319-1224","authenticated-orcid":false,"given":"Zhiguo","family":"Wan","sequence":"additional","affiliation":[{"name":"Zhejiang Lab, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2818-4433","authenticated-orcid":false,"given":"Sjouke","family":"Mauw","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Luxembourg, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5974-1589","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Kuan Eeik Tan, and Adrian Flanagan","author":"Ammad-Ud-Din Muhammad","year":"2019","unstructured":"Muhammad Ammad-Ud-Din, Elena Ivannikova, Suleiman A Khan, Were Oyomno, Qiang Fu, Kuan Eeik Tan, and Adrian Flanagan. 2019. Federated collaborative filtering for privacy-preserving personalized recommendation system. arXiv preprint arXiv:1901.09888 (2019)."},{"key":"e_1_3_2_1_2_1","volume-title":"the 2019 Neural Information Processing Systems","volume":"32","author":"Baruch Gilad","year":"2019","unstructured":"Gilad Baruch, Moran Baruch, and Yoav Goldberg. 2019. A Little Is Enough: Circumventing Defenses For Distributed Learning. In the 2019 Neural Information Processing Systems, Vol. 32. Curran Associates, Inc., 8632--8642."},{"key":"e_1_3_2_1_3_1","volume-title":"the 2017 Neural Information Processing Systems","volume":"30","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In the 2017 Neural Information Processing Systems, Vol. 30. Curran Associates, Inc., 119--129."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_3_2_1_5_1","volume-title":"the 2023 IEEE Symposium on Security and Privacy. IEEE Computer Society, 326--343","author":"Cao Xiaoyu","year":"2022","unstructured":"Xiaoyu Cao, Jinyuan Jia, Zaixi Zhang, and Neil Zhenqiang Gong. 2022. FedRecover: Recovering from Poisoning Attacks in Federated Learning using Historical Information. In the 2023 IEEE Symposium on Security and Privacy. IEEE Computer Society, 326--343."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.3014880"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219617.3219655"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3569452"},{"key":"e_1_3_2_1_9_1","volume-title":"International colloquium on automata, languages, and programming","author":"Dwork Cynthia","unstructured":"Cynthia Dwork. 2006. Differential privacy. In International colloquium on automata, languages, and programming. Springer, 1--12."},{"key":"e_1_3_2_1_10_1","volume-title":"the 29th USENIX Security Symposium. USENIX Association, 1605--1622","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local Model Poisoning Attacks to Byzantine-Robust Federated Learning. In the 29th USENIX Security Symposium. USENIX Association, 1605--1622."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3568022"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"e_1_3_2_1_13_1","volume-title":"Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning. In the 2018 IEEE Symposium on Security and Privacy. IEEE Computer Society, 19--35","author":"Jagielski Matthew","year":"2018","unstructured":"Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li. 2018. Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning. In the 2018 IEEE Symposium on Security and Privacy. IEEE Computer Society, 19--35."},{"key":"e_1_3_2_1_14_1","volume-title":"the 2016 NIPS Workshop on Private Multi-Party Machine Learning.","author":"Konevcn\u1ef3 Jakub","year":"2016","unstructured":"Jakub Konevcn\u1ef3, H Brendan McMahan, Felix X Yu, Peter Richt\u00e1rik, Ananda Theertha Suresh, and Dave Bacon. 2016. Federated learning: Strategies for improving communication efficiency. In the 2016 NIPS Workshop on Private Multi-Party Machine Learning."},{"key":"e_1_3_2_1_15_1","volume-title":"the 2023 IEEE Symposium on Security and Privacy. IEEE Computer Society","author":"Qingqing Ye Haoyang LI","year":"2023","unstructured":"Haoyang LI, Qingqing Ye, Haibo Hu, Jin Li, Leixia Wang, Chengfang Fang, and Jie Shi. 2023. 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated Learning. In the 2023 IEEE Symposium on Security and Privacy. IEEE Computer Society, 1893--1907."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i5.16546"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.3017205"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3501815"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1982.1056489"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i7.26083"},{"key":"e_1_3_2_1_22_1","volume-title":"the 20th International Conference on Artificial Intelligence and Statistics (Machine Learning Research","volume":"1282","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In the 20th International Conference on Artificial Intelligence and Statistics (Machine Learning Research, Vol. 54). PMLR, 1273--1282."},{"key":"e_1_3_2_1_23_1","volume-title":"Exploiting Unintended Feature Leakage in Collaborative Learning. In the 2019 IEEE Symposium on Security and Privacy. IEEE, 691--706","author":"Melis Luca","year":"2019","unstructured":"Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting Unintended Feature Leakage in Collaborative Learning. In the 2019 IEEE Symposium on Security and Privacy. IEEE, 691--706."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.108441"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/306"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00243"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"e_1_3_2_1_28_1","volume-title":"Generalized Transferability for Evasion and Poisoning Attacks. In the 27th USENIX Security Symposium. USENIX Association, 1299--1316","author":"Suciu Octavian","year":"2018","unstructured":"Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daum\u00e9 III, and Tudor Dumitras. 2018. When Does Machine Learning FAIL? Generalized Transferability for Evasion and Poisoning Attacks. In the 27th USENIX Security Symposium. USENIX Association, 1299--1316."},{"key":"e_1_3_2_1_29_1","volume-title":"Data Poisoning Attacks Against Federated Learning Systems. In the 25th European Symposium on Research in Computer Security (Lecture Notes in Computer Science","volume":"501","author":"Tolpegin Vale","year":"2020","unstructured":"Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. 2020. Data Poisoning Attacks Against Federated Learning Systems. In the 25th European Symposium on Research in Computer Security (Lecture Notes in Computer Science, Vol. 12308). Springer, 480--501."},{"key":"e_1_3_2_1_30_1","volume-title":"Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris S. Papailiopoulos.","author":"Wang Hongyi","year":"2020","unstructured":"Hongyi Wang, Kartik Sreenivasan, Shashank Rajput andHarit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris S. Papailiopoulos. 2020. Attack of the Tails: Yes, You Really Can Backdoor Federated Learning. In the 2020 Neural Information Processing Systems, Vol. 33. Curran Associates, Inc., 16070--16084."},{"key":"e_1_3_2_1_31_1","volume-title":"FedGNN: Federated Graph Neural Network for Privacy-Preserving Recommendation. In the 2021 ICML Workshop on Federated Learning for User Privacy and Data Confidentiality. PMLR.","author":"Wu Chuhan","year":"2021","unstructured":"Chuhan Wu, Fangzhao Wu, Yang Cao, Yongfeng Huang, and Xing Xie. 2021. FedGNN: Federated Graph Neural Network for Privacy-Preserving Recommendation. In the 2021 ICML Workshop on Federated Learning for User Privacy and Data Confidentiality. PMLR."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539119"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58568-6_8"},{"key":"e_1_3_2_1_34_1","volume-title":"Practical and Secure Federated Recommendation with Personalized Mask. In the 2022 IJCAI workshop on Trustworthy Federated Learning (Lecture Notes in Computer Science","volume":"45","author":"Yang Liu","year":"2022","unstructured":"Liu Yang, Junxue Zhang, Di Chai, Leye Wang, Kun Guo, Kai Chen, and Qiang Yang. 2022. Practical and Secure Federated Recommendation with Personalized Mask. In the 2022 IJCAI workshop on Trustworthy Federated Learning (Lecture Notes in Computer Science, Vol. 13448). Springer, 33--45."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_2_1_36_1","volume-title":"the 35th International Conference on Machine Learning (Machine Learning Research","volume":"5659","author":"Yin Dong","unstructured":"Dong Yin, Yudong Chen, Kannan Ramchandran, and Peter L. Bartlett. 2018. Byzantine-robust distributed learning: towards optimal statistical rates. In the 35th International Conference on Machine Learning (Machine Learning Research, Vol. 80). PMLR, 5650--5659."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25611"},{"key":"e_1_3_2_1_38_1","volume-title":"Tieke He, Liang Chen, and Hongzhi Yin.","author":"Yuan Wei","year":"2023","unstructured":"Wei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen, and Hongzhi Yin. 2023. Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its Countermeasures. In the 46th International ACM SIGIR Conference on Research and Development in Information Retrieval. ACM, 1690--1699."},{"key":"e_1_3_2_1_39_1","volume-title":"Interaction-level Membership Inference Attack Against Federated Recommender Systems. In the 2023 ACM Web Conference. ACM, 1053--1062","author":"Yuan Wei","year":"2023","unstructured":"Wei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui, Tieke He, and Hongzhi Yin. 2023. Interaction-level Membership Inference Attack Against Federated Recommender Systems. In the 2023 ACM Web Conference. ACM, 1053--1062."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3498386"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670365","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3670365","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:53:36Z","timestamp":1755842016000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670365"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":40,"alternative-id":["10.1145\/3658644.3670365","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3670365","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}