{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T15:32:18Z","timestamp":1784820738142,"version":"3.55.0"},"reference-count":78,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2025,1,17]],"date-time":"2025-01-17T00:00:00Z","timestamp":1737072000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"ARC Discovery Early Career Researcher Award","award":["DE200101465"],"award-info":[{"award-number":["DE200101465"]}]},{"name":"ARC DP Project","award":["DP240101108"],"award-info":[{"award-number":["DP240101108"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst."],"published-print":{"date-parts":[[2025,3,31]]},"abstract":"<jats:p>Recommendation systems play a crucial role in providing web-based suggestion utilities by leveraging user behavior, preferences, and interests. In the context of privacy concerns and the proliferation of handheld devices, federated recommender systems have emerged as a promising solution. These systems allow each client to train a local model and exchange only the model updates with a central server, thus preserving data privacy. However, certain use cases necessitate the deduction of contributions from specific clients, a process known as \u201cunlearning.\u201d Existing machine unlearning methods are designed for centralized settings and do not cater to the collaborative nature of recommendation systems, thereby overlooking their unique characteristics. This article proposes CFRU, a novel federated recommendation unlearning model that enables efficient and certified removal of target clients from the global model. Instead of retraining the model, our approach rolls back and eliminates the historical updates associated with the target client. To efficiently store the learning process\u2019s historical updates, we propose sampling strategies that reduce the number of historical updates, retaining only the most significant ones. Furthermore, we analyze the potential bias introduced by the removal of target clients\u2019 updates at each training round and establish an estimation using the Lipschitz condition. Leveraging this estimation, we propose an efficient iterative scheme to accumulate the bias across all rounds, compensating for the removed updates from the global model and recovering its utility without requiring post-training steps. Extensive experiments conducted on two real-world datasets, incorporating two poison attack scenarios, have shown that our unlearning technique can achieve a model quality that is 99.3% equivalent to retraining the model from scratch while performing up to 1,000 times faster.<\/jats:p>","DOI":"10.1145\/3706419","type":"journal-article","created":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T11:53:11Z","timestamp":1733140391000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":16,"title":["Certified Unlearning for Federated Recommendation"],"prefix":"10.1145","volume":"43","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2027-5362","authenticated-orcid":false,"given":"Thanh Trung","family":"Huynh","sequence":"first","affiliation":[{"name":"Ecole Polytechnique Federale de Lausanne, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6781-9131","authenticated-orcid":false,"given":"Trong Bang","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Hanoi University of Science and Technology (HUST), Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-2564-247X","authenticated-orcid":false,"given":"Thanh Toan","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, HUTECH University, Ho Chi Minh City, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6547-7641","authenticated-orcid":false,"given":"Phi Le","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Hanoi University of Science and Technology (HUST), Hanoi, Vie"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1395-261X","authenticated-orcid":false,"given":"Hongzhi","family":"Yin","sequence":"additional","affiliation":[{"name":"School of ITEE, The University of Queensland, Saint Lucia, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9687-1315","authenticated-orcid":false,"given":"Quoc Viet Hung","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Griffith University - Gold Coast Campus, Southport, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2586-7757","authenticated-orcid":false,"given":"Thanh Tam","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Griffith University - Gold Coast Campus, Southport, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,1,17]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"37","article-title":"Distributed large-scale natural graph factorization","author":"Ahmed Amr","year":"2013","unstructured":"Amr Ahmed, Nino Shervashidze, Shravan Narayanamurthy, Vanja Josifovski, and Alexander J. Smola. 2013. Distributed large-scale natural graph factorization. In WWW, 37\u201348.","journal-title":"WWW"},{"key":"e_1_3_2_3_2","unstructured":"Muhammad Ammad-Ud-Din Elena Ivannikova Suleiman A. Khan Were Oyomno Qiang Fu Kuan Eeik Tan and Adrian Flanagan. 2019. Federated collaborative filtering for privacy-preserving personalized recommendation system. arXiv:1901.09888. Retrieved from https:\/\/arxiv.org\/abs\/1901.09888"},{"key":"e_1_3_2_4_2","unstructured":"Thomas Baumhauer Pascal Sch\u00f6ttle and Matthias Zeppelzauer. 2020. Machine unlearning: Linear filtration for logit-based classifiers. arXiv:2002.02730. Retrieved from https:\/\/arxiv.org\/abs\/2002.02730 (2020)."},{"key":"e_1_3_2_5_2","first-page":"141","article-title":"Machine unlearning","author":"Bourtoule Lucas","year":"2021","unstructured":"Lucas Bourtoule, Varun Chandrasekaran, Christopher A Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. 2021. Machine unlearning. In SP, 141\u2013159.","journal-title":"SP"},{"key":"e_1_3_2_6_2","first-page":"463","article-title":"Towards making systems forget with machine unlearning","author":"Cao Yinzhi","year":"2015","unstructured":"Yinzhi Cao and Junfeng Yang. 2015. Towards making systems forget with machine unlearning. In SP, 463\u2013480.","journal-title":"SP"},{"key":"e_1_3_2_7_2","unstructured":"Zheng Chai Yujing Chen Liang Zhao Yue Cheng and Huzefa Rangwala. 2020. FedAT: A communication-efficient federated learning method with asynchronous tiers under Non-IID data. arXiv:2010.05958. Retrieved from https:\/\/arxiv.org\/abs\/2010.05958"},{"key":"e_1_3_2_8_2","first-page":"4241","article-title":"Fast federated machine unlearning with nonlinear functional theory","author":"Che Tianshi","year":"2023","unstructured":"Tianshi Che, Yang Zhou, Zijie Zhang, Lingjuan Lyu, Ji Liu, Da Yan, Dejing Dou, and Jun Huan. 2023. Fast federated machine unlearning with nonlinear functional theory. In ICML, 4241\u20134268.","journal-title":"ICML"},{"key":"e_1_3_2_9_2","first-page":"2768","article-title":"Recommendation unlearning","author":"Chen Chong","year":"2022","unstructured":"Chong Chen, Fei Sun, Min Zhang, and Bolin Ding. 2022. Recommendation unlearning. In WWW, 2768\u20132777.","journal-title":"WWW"},{"key":"e_1_3_2_10_2","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1145\/3289600.3290982","article-title":"Social attentional memory network: Modeling aspect-and Friend-level differences in recommendation","author":"Chen Chong","year":"2019","unstructured":"Chong Chen, Min Zhang, Yiqun Liu, and Shaoping Ma. 2019. Social attentional memory network: Modeling aspect-and Friend-level differences in recommendation. In WSDM, 177\u2013185.","journal-title":"WSDM"},{"issue":"3","key":"e_1_3_2_11_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3564284","article-title":"Bias and debias in recommender system: A survey and future directions","volume":"41","author":"Chen Jiawei","year":"2023","unstructured":"Jiawei Chen, Hande Dong, Xiang Wang, Fuli Feng, Meng Wang, and Xiangnan He. 2023. Bias and debias in recommender system: A survey and future directions. ACM Transactions on Information Systems 41, 3 (2023), 1\u201339.","journal-title":"ACM Transactions on Information Systems"},{"key":"e_1_3_2_12_2","first-page":"767","article-title":"On sampling strategies for neural network-based collaborative filtering","author":"Chen Ting","year":"2017","unstructured":"Ting Chen, Yizhou Sun, Yue Shi, and Liangjie Hong. 2017. On sampling strategies for neural network-based collaborative filtering. In KDD, 767\u2013776.","journal-title":"KDD"},{"key":"e_1_3_2_13_2","first-page":"49","article-title":"Tada: Trend alignment with dual-attention multi-task recurrent neural networks for sales prediction","author":"Chen Tong","year":"2018","unstructured":"Tong Chen, Hongzhi Yin, Hongxu Chen, Lin Wu, Hao Wang, Xiaofang Zhou, and Xue Li. 2018. Tada: Trend alignment with dual-attention multi-task recurrent neural networks for sales prediction. In ICDM, 49\u201358.","journal-title":"ICDM"},{"key":"e_1_3_2_14_2","first-page":"7","article-title":"Wide & deep learning for recommender systems","author":"Cheng Heng-Tze","year":"2016","unstructured":"Heng-Tze Cheng, Levent Koc, Jeremiah Harmsen, Tal Shaked, Tushar Chandra, Hrishi Aradhye, Glen Anderson, Greg Corrado, Wei Chai, Mustafa Ispir, et al. 2016. Wide & deep learning for recommender systems. In DLRS., 7\u201310.","journal-title":"DLRS"},{"key":"e_1_3_2_15_2","first-page":"763","article-title":"Recommender systems for online video game platforms: The case of STEAM","author":"Cheuque Germ\u00e1n","year":"2019","unstructured":"Germ\u00e1n Cheuque, Jos\u00e9 Guzm\u00e1n, and Denis Parra. 2019. Recommender systems for online video game platforms: The case of STEAM. In WWW Companion, 763\u2013771.","journal-title":"WWW Companion"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2765202"},{"key":"e_1_3_2_17_2","first-page":"403","article-title":"Right to be forgotten in the age of machine learning","author":"Dang Quang-Vinh","year":"2021","unstructured":"Quang-Vinh Dang. 2021. Right to be forgotten in the age of machine learning. In ICADS, 403\u2013411.","journal-title":"ICADS"},{"key":"e_1_3_2_18_2","first-page":"1094","article-title":"Simplify and robustify negative sampling for implicit collaborative filtering","volume":"33","author":"Ding Jingtao","year":"2020","unstructured":"Jingtao Ding, Yuhan Quan, Quanming Yao, Yong Li, and Depeng Jin. 2020. Simplify and robustify negative sampling for implicit collaborative filtering. NeurIPS 33 (2020), 1094\u20131105.","journal-title":"NeurIPS"},{"key":"e_1_3_2_19_2","first-page":"11427","article-title":"Efficient and accurate estimation of lipschitz constants for deep neural networks","volume":"32","author":"Fazlyab Mahyar","year":"2019","unstructured":"Mahyar Fazlyab, Alexander Robey, Hamed Hassani, Manfred Morari, and George Pappas. 2019. Efficient and accurate estimation of lipschitz constants for deep neural networks. NeurIPS 32 (2019), 11427\u201311438.","journal-title":"NeurIPS"},{"key":"e_1_3_2_20_2","first-page":"402","article-title":"An empirical study of user behaviors on pinterest social network","volume":"1","author":"Feng Ziming","year":"2013","unstructured":"Ziming Feng, Feng Cong, Kailong Chen, and Yong Yu. 2013. An empirical study of user behaviors on pinterest social network. In WI-IAT, Vol. 1, 402\u2013409.","journal-title":"WI-IAT"},{"key":"e_1_3_2_21_2","first-page":"1","article-title":"Verifi: Towards verifiable federated unlearning","volume":"99","author":"Gao Xiangshan","year":"2024","unstructured":"Xiangshan Gao, Xingjun Ma, Jingyi Wang, Youcheng Sun, Bo Li, Shouling Ji, Peng Cheng, and Jiming Chen. 2024. Verifi: Towards verifiable federated unlearning. IEEE Transactions on Dependable and Secure Computing 99 (2024), 1\u201316.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_22_2","first-page":"3518","article-title":"Making AI forget you: Data deletion in machine learning","volume":"32","author":"Ginart Antonio","year":"2019","unstructured":"Antonio Ginart, Melody Guan, Gregory Valiant, and James Y Zou. 2019. Making AI forget you: Data deletion in machine learning. NeurIPS 32 (2019), 3518\u20133531.","journal-title":"NeurIPS"},{"key":"e_1_3_2_23_2","unstructured":"Tao Guo Song Guo Jiewei Zhang Wenchao Xu and Junxiao Wang. 2022. Efficient attribute unlearning: Towards selective removal of input attributes from feature representations. arXiv:2202.13295. Retrieved from https:\/\/arxiv.org\/abs\/2202.13295 (2022)."},{"key":"e_1_3_2_24_2","unstructured":"Anisa Halimi Swanand Kadhe Ambrish Rawat and Nathalie Baracaldo. 2022. Federated unlearning: How to efficiently erase a client in FL? arXiv:2207.05521. Retrieved from https:\/\/arxiv.org\/abs\/2207.05521"},{"key":"e_1_3_2_25_2","first-page":"8527","article-title":"Co-teaching: Robust training of deep neural networks with extremely noisy labels","volume":"31","author":"Han Bo","year":"2018","unstructured":"Bo Han, Quanming Yao, Xingrui Yu, Gang Niu, Miao Xu, Weihua Hu, Ivor Tsang, and Masashi Sugiyama. 2018. Co-teaching: Robust training of deep neural networks with extremely noisy labels. NeurIPS 31 (2018), 8527\u20138537.","journal-title":"NeurIPS"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_27_2","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In CVPR, 770\u2013778.","journal-title":"CVPR"},{"key":"e_1_3_2_28_2","first-page":"639","article-title":"Lightgcn: Simplifying and powering graph convolution network for recommendation","author":"He Xiangnan","year":"2020","unstructured":"Xiangnan He, Kuan Deng, Xiang Wang, Yan Li, Yongdong Zhang, and Meng Wang. 2020. Lightgcn: Simplifying and powering graph convolution network for recommendation. In SIGIR, 639\u2013648.","journal-title":"SIGIR"},{"key":"e_1_3_2_29_2","article-title":"Unlearnable examples: Making personal data unexploitable","author":"Huang Hanxun","year":"2021","unstructured":"Hanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey, and Yisen Wang. 2021. Unlearnable examples: Making personal data unexploitable. In ICLR.","journal-title":"ICLR"},{"key":"e_1_3_2_30_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TKDE.2021.3101840","article-title":"Network alignment with holistic embeddings","volume":"34","author":"Huynh Thanh Trung","year":"2021","unstructured":"Thanh Trung Huynh, Chi Thang Duong, Tam Thanh Nguyen, Vinh Van Tong, Abdul Sattar, Hongzhi Yin, and Quoc Viet Hung Nguyen. 2021. Network alignment with holistic embeddings. IEEE Transactions on Knowledge and Data Engineering 34 (2021), 1\u201314.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_31_2","first-page":"55","article-title":"Fast-fedul: A training-free federated unlearning with provable skew resilience","author":"Huynh Thanh Trung","year":"2024","unstructured":"Thanh Trung Huynh, Trong Bang Nguyen, Phi Le Nguyen, Thanh Tam Nguyen, Matthias Weidlich, Quoc Viet Hung Nguyen, and Karl Aberer. 2024. Fast-fedul: A training-free federated unlearning with provable skew resilience. In ECML PKDD, 55\u201372.","journal-title":"ECML PKDD"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3560486"},{"key":"e_1_3_2_33_2","first-page":"2008","article-title":"Approximate data deletion from machine learning models","author":"Izzo Zachary","year":"2021","unstructured":"Zachary Izzo, Mary Anne Smart, Kamalika Chaudhuri, and James Zou. 2021. Approximate data deletion from machine learning models. In AISTATS, 2008\u20132016.","journal-title":"AISTATS"},{"issue":"2","key":"e_1_3_2_34_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3627158","article-title":"Contrastive Self-supervised learning in recommender systems: A survey","volume":"42","author":"Jing Mengyuan","year":"2023","unstructured":"Mengyuan Jing, Yanmin Zhu, Tianzi Zang, and Ke Wang. 2023. Contrastive Self-supervised learning in recommender systems: A survey. ACM Transactions on Information Systems 42, 2 (2023), 1\u201339.","journal-title":"ACM Transactions on Information Systems"},{"key":"e_1_3_2_35_2","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1145\/3289600.3290968","article-title":"Federated online learning to rank with evolution strategies","author":"Kharitonov Eugene","year":"2019","unstructured":"Eugene Kharitonov. 2019. Federated online learning to rank with evolution strategies. In WSDM, 249\u2013257.","journal-title":"WSDM"},{"key":"e_1_3_2_36_2","first-page":"1","article-title":"Ultrare: Enhancing receraser for recommendation unlearning via error decomposition","volume":"36","author":"Li Yuyuan","year":"2024","unstructured":"Yuyuan Li, Chaochao Chen, Yizhao Zhang, Weiming Liu, Lingjuan Lyu, Xiaolin Zheng, Dan Meng, and Jun Wang. 2024. Ultrare: Enhancing receraser for recommendation unlearning via error decomposition. NeurIPS 36 (2024), 1\u201315.","journal-title":"NeurIPS"},{"key":"e_1_3_2_37_2","first-page":"984","article-title":"Making users indistinguishable: Attribute-wise unlearning in recommender systems","author":"Li Yuyuan","year":"2023","unstructured":"Yuyuan Li, Chaochao Chen, Xiaolin Zheng, Yizhao Zhang, Zhongxuan Han, Dan Meng, and Jun Wang. 2023. Making users indistinguishable: Attribute-wise unlearning in recommender systems. In MM, 984\u2013994.","journal-title":"MM"},{"key":"e_1_3_2_38_2","unstructured":"Yuyuan Li Xiaolin Zheng Chaochao Chen and Junlin Liu. 2022. Making recommender systems forget: Learning and unlearning for erasable recommendation. arXiv:2203.11491. Retrieved from https:\/\/arxiv.org\/abs\/2203.11491"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i5.16546"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.3017205"},{"issue":"2","key":"e_1_3_2_41_2","first-page":"1","article-title":"A generic federated recommendation framework via fake Marks and secret sharing","volume":"41","author":"Lin Zhaohao","year":"2022","unstructured":"Zhaohao Lin, Weike Pan, Qiang Yang, and Zhong Ming. 2022. A generic federated recommendation framework via fake Marks and secret sharing. ACM Transactions on Information Systems 41, 2 (2022), 1\u201337.","journal-title":"ACM Transactions on Information Systems"},{"key":"e_1_3_2_42_2","unstructured":"Gaoyang Liu Xiaoqiang Ma Yang Yang Chen Wang and Jiangchuan Liu. 2020. Federated unlearning. arXiv:2012.13891. Retrieved from https:\/\/arxiv.org\/abs\/2012.13891"},{"key":"e_1_3_2_43_2","first-page":"1","article-title":"Federaser: Enabling efficient client-level data removal from federated learning models","author":"Liu Gaoyang","year":"2021","unstructured":"Gaoyang Liu, Xiaoqiang Ma, Yang Yang, Chen Wang, and Jiangchuan Liu. 2021. Federaser: Enabling efficient client-level data removal from federated learning models. In IWQOS, 1\u201310.","journal-title":"IWQOS"},{"key":"e_1_3_2_44_2","first-page":"1749","article-title":"The right to be forgotten in federated learning: An efficient realization with rapid retraining","author":"Liu Yi","year":"2022","unstructured":"Yi Liu, Lei Xu, Xingliang Yuan, Cong Wang, and Bo Li. 2022. The right to be forgotten in federated learning: An efficient realization with rapid retraining. In INFOCOM, 1749\u20131758.","journal-title":"INFOCOM"},{"key":"e_1_3_2_45_2","first-page":"2635","article-title":"SDM: Sequential deep matching model for online large-scale recommender system","author":"Lv Fuyu","year":"2019","unstructured":"Fuyu Lv, Taiwei Jin, Changlong Yu, Fei Sun, Quan Lin, Keping Yang, and Wilfred Ng. 2019. SDM: Sequential deep matching model for online large-scale recommender system. In CIKM, 2635\u20132643.","journal-title":"CIKM"},{"key":"e_1_3_2_46_2","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In AISTATS, 1273\u20131282.","journal-title":"AISTATS"},{"key":"e_1_3_2_47_2","first-page":"1234","article-title":"Fedfast: Going beyond average for faster training of federated recommender systems","author":"Muhammad Khalil","year":"2020","unstructured":"Khalil Muhammad, Qinqin Wang, Diarmuid O\u2019Reilly-Morgan, Elias Tragos, Barry Smyth, Neil Hurley, James Geraci, and Aonghus Lawlor. 2020. Fedfast: Going beyond average for faster training of federated recommender systems. In KDD, 1234\u20131242.","journal-title":"KDD"},{"key":"e_1_3_2_48_2","unstructured":"Thanh Tam Nguyen Thanh Trung Huynh Zhao Ren Phi Le Nguyen Alan Wee-Chung Liew Hongzhi Yin and Quoc Viet Hung Nguyen. 2022. A survey of machine unlearning. arXiv:2209.02299. Retrieved from https:\/\/arxiv.org\/abs\/2209.02299"},{"issue":"1","key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"111101","DOI":"10.1007\/s11432-024-4123-4","article-title":"Privacy-preserving explainable AI: A survey","volume":"68","author":"Nguyen Thanh Tam","year":"2025","unstructured":"Thanh Tam Nguyen, Thanh Trung Huynh, Zhao Ren, Thanh Toan Nguyen, Phi Le Nguyen, Hongzhi Yin, and Quoc Viet Hung Nguyen. 2025. Privacy-preserving explainable AI: A survey. Science China Information Sciences 68, 1 (2025), 111101.","journal-title":"Science China Information Sciences"},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3677328","article-title":"Manipulating recommender systems: A survey of poisoning attacks and countermeasures","volume":"57","author":"Nguyen Thanh Toan","year":"2024","unstructured":"Thanh Toan Nguyen, Quoc Viet Hung Nguyen, Thanh Tam Nguyen, Thanh Trung Huynh, Thanh Thi Nguyen, Matthias Weidlich, and Hongzhi Yin. 2024. Manipulating recommender systems: A survey of poisoning attacks and countermeasures. ACM Computing Surveys 57 (2024), 1\u201339.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3567420"},{"key":"e_1_3_2_52_2","first-page":"68","article-title":"The California Consumer Privacy Act: Towards a European-style privacy regime in the United States","volume":"23","author":"Pardau Stuart L","year":"2018","unstructured":"Stuart L Pardau. 2018. The California Consumer Privacy Act: Towards a European-style privacy regime in the United States. Journal of Technology Law & Policy 23 (2018), 68.","journal-title":"Journal of Technology Law & Policy"},{"key":"e_1_3_2_53_2","first-page":"1443","article-title":"Adversarial sampling and training for semi-supervised information retrieval","author":"Park Dae Hoon","year":"2019","unstructured":"Dae Hoon Park and Yi Chang. 2019. Adversarial sampling and training for semi-supervised information retrieval. In WWW, 1443\u20131453.","journal-title":"WWW"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12362"},{"key":"e_1_3_2_55_2","unstructured":"Steffen Rendle Christoph Freudenthaler Zeno Gantner and Lars Schmidt-Thieme. 2012. BPR: Bayesian personalized ranking from implicit feedback. arXiv:1205.2618. Retrieved from https:\/\/arxiv.org\/abs\/1205.2618"},{"key":"e_1_3_2_56_2","first-page":"452","article-title":"Bayesian personalized ranking from implicit feedback","author":"Rendle Steffen","year":"2014","unstructured":"Steffen Rendle, Christoph Freudenthaler, Zeno Gantner, and Lars Schmidt-Thieme. 2014. Bayesian personalized ranking from implicit feedback. In UAI, 452\u2013461.","journal-title":"UAI"},{"key":"e_1_3_2_57_2","first-page":"2643","article-title":"Fedrecattack: Model poisoning attack to federated recommendation","author":"Rong Dazhong","year":"2022","unstructured":"Dazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen, Jianhai Chen, and Qinming He. 2022. Fedrecattack: Model poisoning attack to federated recommendation. In ICDE, 2643\u20132655.","journal-title":"ICDE"},{"key":"e_1_3_2_58_2","unstructured":"Anit Kumar Sahu Tian Li Maziar Sanjabi Manzil Zaheer Ameet Talwalkar and Virginia Smith. 2018. On the convergence of federated optimization in heterogeneous networks. arXiv:1812.06127. Retrieved from https:\/\/arxiv.org\/abs\/1812.06127"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.121165"},{"key":"e_1_3_2_60_2","unstructured":"Zehua Sun Yonghui Xu Yong Liu Wei He Yali Jiang Fangzhao Wu and Lizhen Cui. 2022. A survey on federated recommendation systems. arXiv:2301.00767. Retrieved from https:\/\/arxiv.org\/abs\/2301.00767"},{"key":"e_1_3_2_61_2","unstructured":"Yue Tan Guodong Long Lu Liu Tianyi Zhou and Jing Jiang. 2021. FedProto: Federated prototype learning over heterogeneous devices. arXiv:2105.00243. Retrieved from https:\/\/arxiv.org\/abs\/2105.00243"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1098\/rsta.2018.0083"},{"key":"e_1_3_2_63_2","first-page":"707","article-title":"Neural cleanse: Identifying and mitigating backdoor attacks in neural networks","author":"Wang Bolun","year":"2019","unstructured":"Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2019. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In SP, 707\u2013723.","journal-title":"SP"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2021.3106104"},{"key":"e_1_3_2_65_2","first-page":"2467","article-title":"Neural memory streaming recommender networks with adversarial training","author":"Wang Qinyong","year":"2018","unstructured":"Qinyong Wang, Hongzhi Yin, Zhiting Hu, Defu Lian, Hao Wang, and Zi Huang. 2018. Neural memory streaming recommender networks with adversarial training. In KDD, 2467\u20132475.","journal-title":"KDD"},{"key":"e_1_3_2_66_2","first-page":"4644","article-title":"Graph learning based recommender systems: A review","author":"Wang Shoujin","year":"2021","unstructured":"Shoujin Wang, Liang Hu, Yan Wang, Xiangnan He, Quan Z. Sheng, Mehmet A. Orgun, Longbing Cao, Francesco Ricci, and Philip S. Yu. 2021. Graph learning based recommender systems: A review. In IJCAI, 4644\u20134652.","journal-title":"IJCAI"},{"key":"e_1_3_2_67_2","first-page":"3425","article-title":"Sequential\/Session-based recommendations: Challenges, approaches, applications and opportunities","author":"Wang Shoujin","year":"2022","unstructured":"Shoujin Wang, Qi Zhang, Liang Hu, Xiuzhen Zhang, Yan Wang, and Charu Aggarwal. 2022. Sequential\/Session-based recommendations: Challenges, approaches, applications and opportunities. In SIGIR, 3425\u20133428.","journal-title":"SIGIR"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/3547333"},{"key":"e_1_3_2_69_2","first-page":"25","article-title":"A theoretical analysis of NDCG type ranking measures","author":"Wang Yining","year":"2013","unstructured":"Yining Wang, Liwei Wang, Yuanzhi Li, Di He, and Tie-Yan Liu. 2013. A theoretical analysis of NDCG type ranking measures. In PMLR, 25\u201354.","journal-title":"PMLR"},{"key":"e_1_3_2_70_2","unstructured":"Chuhan Wu Fangzhao Wu Yang Cao Yongfeng Huang and Xing Xie. 2021. Fedgnn: Federated graph neural network for privacy-preserving recommendation. arXiv:2102.04925. Retrieved from https:\/\/arxiv.org\/abs\/2102.04925"},{"key":"e_1_3_2_71_2","first-page":"4164","article-title":"FedAttack: Effective and Covert poisoning attack on federated recommendation via Hard sampling","author":"Wu Chuhan","year":"2022","unstructured":"Chuhan Wu, Fangzhao Wu, Tao Qi, Yongfeng Huang, and Xing Xie. 2022. FedAttack: Effective and Covert poisoning attack on federated recommendation via Hard sampling. In KDD, 4164\u20134172.","journal-title":"KDD"},{"key":"e_1_3_2_72_2","unstructured":"Chen Wu Sencun Zhu and Prasenjit Mitra. 2022. Federated Unlearning with Knowledge Distillation. arXiv:2201.09441. Retrieved from https:\/\/arxiv.org\/abs\/2201.09441"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCCN.2021.3084406"},{"key":"e_1_3_2_74_2","first-page":"1690","article-title":"Manipulating federated recommender systems: Poisoning with synthetic users and its countermeasures","author":"Yuan Wei","year":"2023","unstructured":"Wei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen, and Hongzhi Yin. 2023. Manipulating federated recommender systems: Poisoning with synthetic users and its countermeasures. In SIGIR, 1690\u20131699.","journal-title":"SIGIR"},{"key":"e_1_3_2_75_2","first-page":"1053","article-title":"Interaction-level membership inference attack against federated recommender systems","author":"Yuan Wei","year":"2023","unstructured":"Wei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui, Tieke He, and Hongzhi Yin. 2023. Interaction-level membership inference attack against federated recommender systems. In WWW, 1053\u20131062.","journal-title":"WWW"},{"key":"e_1_3_2_76_2","first-page":"393","article-title":"Federated unlearning for on-device recommendation","author":"Yuan Wei","year":"2023","unstructured":"Wei Yuan, Hongzhi Yin, Fangzhao Wu, Shijie Zhang, Tieke He, and Hao Wang. 2023c. Federated unlearning for on-device recommendation. In WSDM, 393\u2013401.","journal-title":"WSDM"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548455"},{"key":"e_1_3_2_78_2","first-page":"1415","article-title":"Pipattack: Poisoning federated recommender systems for manipulating item promotion","author":"Zhang Shijie","year":"2022","unstructured":"Shijie Zhang, Hongzhi Yin, Tong Chen, Zi Huang, Quoc Viet Hung Nguyen, and Lizhen Cui. 2022. Pipattack: Poisoning federated recommender systems for manipulating item promotion. In WSDM, 1415\u20131423.","journal-title":"WSDM"},{"key":"e_1_3_2_79_2","first-page":"689","article-title":"Gcn-based user representation learning for unifying robust recommendation and fraudster detection","author":"Zhang Shijie","year":"2020","unstructured":"Shijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Nguyen Hung, Zi Huang, and Lizhen Cui. 2020. Gcn-based user representation learning for unifying robust recommendation and fraudster detection. In SIGIR, 689\u2013698.","journal-title":"SIGIR"}],"container-title":["ACM Transactions on Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3706419","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3706419","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:04Z","timestamp":1750295884000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3706419"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,17]]},"references-count":78,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,3,31]]}},"alternative-id":["10.1145\/3706419"],"URL":"https:\/\/doi.org\/10.1145\/3706419","relation":{},"ISSN":["1046-8188","1558-2868"],"issn-type":[{"value":"1046-8188","type":"print"},{"value":"1558-2868","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,17]]},"assertion":[{"value":"2024-04-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-22","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-01-17","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}