Sparse Adaptive Momentum Attack Against Federated Recommender Systems and Its Countermeasures
Zhongliang Zhang, Yilei Hong, Zhao Huang, Qilei Li, Xin ZhangABSTRACT
Federated Recommendation Systems (FRS) have emerged as a promising privacy‐preserving paradigm for personalised services. However, their decentralised nature exposes them to untargeted poisoning attacks that aim to degrade system utility. Existing attacks often prove suboptimal as they fail to account for three fundamental characteristics of FRS: dynamics (evolving representation trajectories), sparsity (inherent sparsity of parameter updates) and robustness (self‐corrective mechanism of training). In this paper, we propose the Sparse Adaptive Momentum Attack (SAMA), which hijacks FRS optimisation dynamics by functioning as a malicious accelerator. SAMA integrates momentum‐aligned trajectory tracking, critical item selection and closed‐loop adaptive strength control to inject precisely calibrated perturbations into high‐velocity embeddings. Extensive experiments on two real‐world datasets demonstrate that SAMA consistently outperforms seven state‐of‐the‐art attack baselines, inducing severe performance collapse. Specifically, on the Steam dataset with a 7% malicious ratio, SAMA reduces HR@10 and NDCG@10 by 99.4% and 99.6%, respectively. Under a lower malicious ratio of 3%, the attack still results in a 64.5% reduction in HR@10. Furthermore, SAMA proves its potency by effectively evading three mainstream robust aggregation defences including Trimmed Mean, Krum and Multi‐Krum. To counter this sophisticated threat, we further introduce InertiaDamp, a direction‐aware defence mechanism that suppresses abnormal parameter acceleration by quantifying evolutionary inertia. Experimental results validate that InertiaDamp not only effectively neutralises SAMA but also enhances the global model's convergence stability and final recommendation utility.