Adversarial Neural Collaborative Filtering with Embedding Dimension Correlations

ABSTRACT Recently, convolutional neural networks (CNNs) have achieved excellent performance for the recommendation system by extracting deep features and building collaborative filtering models. However, CNNs have been verified susceptible to adversarial examples. This is because adversarial samples are subtle non-random disturbances, which indicates that machine learning models produce incorrect outputs. Therefore, we propose a novel model of Adversarial Neural Collaborative Filtering with Embedding Dimension Correlations, named ANCF in short, to address the adversarial problem of CNN-based recommendation system. In particular, the proposed ANCF model adopts the matrix factorization to train the adversarial personalized ranking in the prediction layer. This is because matrix factorization supposes that the linear interaction of the latent factors, which are captured between the user and the item, can describe the observable feedback, thus the proposed ANCF model can learn more complicated representation of their latent factors to improve the performance of recommendation. In addition, the ANCF model utilizes the outer product instead of the inner product or concatenation to learn explicitly pairwise embedding dimensional correlations and obtain the interaction map from which CNNs can utilize its strengths to learn high-order correlations. As a result, the proposed ANCF model can improve the robustness performance by the adversarial personalized ranking, and obtain more information by encoding correlations between different embedding layers. Experimental results carried out on three public datasets demonstrate that the ANCF model outperforms other existing recommendation models.


INTRODUCTION
Since recommendation systems (RS) can alleviate information overload and provide an effective solution for users' information search, they are widely adopted in web applications such as E-business, social software, and so on. Generally, the collaborative filtering (CF) approaches are one of crucial methods among various recommendation technologies because of their capabilities of both higher efficiency and accuracy.
In particular, matrix factorization (MF) method is one of the most popular CF approaches since the vectors in the MF can represent latent features of each user and item. Moreover, the inner products of latent features vectors can approximate the user-item interaction well, and are powerful for catching the low-rank structure of sparse data of the interaction between user and item, however, its concision and linearity limit the representation of the predictive function [1,2]. Recently, a growing number of attempts have been made to address the issues, including two main groups: One improves the model itself to learn user and item representations via deep neural networks (DNNs); the other enhances the learning strategy, e.g. Bayesian Personalized Ranking (BPR) [3], learned MF in pairwise ranking perspective [4], etc.
However, DNNs-based approaches have been verified susceptible to adversarial examples recently. This is because adversarial samples are subtle non-random disturbances, which indicates that machine learning (ML) models produce incorrect outputs. A large number of studies have reported the failure of ML-based RS models against adversarial attacks. To improve the robustness, Goodfellow et al. [5] and Moosavi-Dezfooli et al. [6] developed adversarial training approaches that can correctly classify the dynamically generated adversarial examples. Inspired by adversarial learning, He et al. [7] designed the Adversarial Personalized Ranking (APR) to replace the traditional BPR [3], but the effect is neglect, especially in top recommendation with a small k value.
To highlight the importance of modeling dimensional correlations and improve on the performance of the robustness for the RS, we present a novel CF-based model with the adversarial training, named Adversarial Neural Collaborative Filtering with Embedding Dimension Correlations, ANCF in short. In particular, the proposed ANCF model adopts the matrix factorization to train the adversarial personalized ranking in the prediction layer. This is because matrix factorization supposes that the linear interaction of the latent factors,which are captured between the user and the item, can describe the observable feedback, so the ANCF can learn a much more complicated representation of latent factors to improve the performance of recommendation. In addition, ANCF utilizes the outer product instead of the inner product or concatenation to learn pairwise embedding dimensional correlations explicitly, and obtain the interaction map from which CNNs can utilize its strengths to learn high-order correlations. Therefore, the proposed ANCF model can improve the robustness performance by the adversarial personalized ranking, and obtain more information by encoding correlations between different embedding layers. Experimental results from three public datasets demonstrate that the ANCF model outperforms other existing recommendation models.
The contribution of the proposed model is described as follows: • The proposed model learns high-order correlations from feature map E via CNN. • The proposed model can solve the adversarial problems via an adversarial matrix factorization.

RELATED RESEARCH WORK
The paper focuses on the CNN-based CF and adversarial training. Therefore, we introduce their latest developments and applications in the RS in this section.

CNN-based Collaborative Filtering
With the development of DNNs in the area of RS, neural collaborative filtering (NCF) has recently become the most popular framework among the DNN-based CF approaches [8]. This is because NCF utilizes DNNs to improve either the user and item representation learning or the predictive function much better [9,10,11,12,13,14]. However, there is still a problem to be addressed in these NCF models recently. That is the correlations of the embedding dimensions resulted from the predictive function. Generally,traditional NCF models often utilize a multi-layer perceptron (MLP) based on the concatenation or the element-wise product of embedding between the user and the item [8,14]. Afterward, Du et al. presented a model named ConvNCF to learn the high-order correlations of the embedding dimensions by utilizing CNNs-based model via the outer product [15].
Inspired by the ConvNCF model [15], this paper adopts matrix factorization trained with APR (i.e., Adversarial Matrix Factorization, AMF) to solve the adversarial problem via a different way.

Adversarial Recommendation Systems
Adversarial machine learning (AML) focuses on the learning algorithms resisting adversarial attacks and studying benefits and drawbacks of attackers to support appropriate solutions [16,17]. In recent years, many works have pointed out the failure of machine learning recommendation models. Therefore, He et al. [7] proposed an adversarial learning framework for recommendation at first. The proposed adversarial personalized ranking (APR) model checked both the robustness to adversarial perturbations of users and embedded items of BPR-MF [3]. Afterward, Anelli et al. [16] researched iterative perturbation technologies and proved the ineffectiveness of the APR in protecting the RS from attacks.
Generally, adversarial training involves appending adversarial samples, generated by particular attack models such as FGSM [5] or BIM [17], into the training process. According to reports, both in RS [18,19] and ML [20], this kind of training process results in the robustness against adversary samples, and achieves better performance of generalization against clean samples.
Afterward, AML has been utilized to create fresh generative models, known as generative adversarial networks (GANs). According to different applications, GAN-based models could improve the negative sampling for the learning sequencing objective function [21,22], predict missing scores [23,24] by using time [24,25], and auxiliary information fitting synthesizers, or enhance training datasets [26,27]. However, we here focus on the Adversarial Matrix Factorization (AMF) instead of GAN due to its computation consumption [28].

PROPOSED MODEL
We propose a novel neural network approach named Adversarial Convolutional Neural CF with Embedding Correlations (ANCF), inspired by the work of [15]. This paper selects CNN as the fundamental neural structure due to three advantages as follows.
• CNN can deal with the feature map well due to its presence as a 2D matrix; • The sub-region of the feature map has a dimensional relationship represented by CNN; • CNN can capture the correlations of features both locally and globally. As shown in Figure 1, the ANCF framework consists of four components as follows: • The first layer is the embedding and input layer, which contains two embedding functions: f U (u) and f I (i). It produces two vectors (of size 64) which represents user u and item i respectively. • The second layer is interaction map layer, which computes the pairwise correlations of the vector after the embedding and input layer by the Interaction Map E fed to the ConvNCF Layers.
• The third layer is ConvNCF Layers including six convolutional layers, following a tower structure with 32 feature maps in each CNN Layer and outputting a tensor in the last CNN layer.
• The last prediction layer obtains prediction yû i trained with the APR to output the final result.

Layer of Input and Embedding
Given a user u and an item i and their features, we first encode their features by one-hot encoding and get their embedding f U (u) and f I (i) via the equation 1: where, • v U u : the feature vector of user u; • v I i : the feature vector for item i; • P ∈R M × K : the embedding matrix for user features; • Q ∈R N × K : the embedding matrix for item features; • M: the number of user features; • K: the embedding size; • N: the number of item features.

Layer of the Interaction Map
Although recent works have shown the superiority of inner-product over complex neural networks (CNNs, MLPs), in terms of efficiency and effectiveness, and the applying outer product with CNNs has more time complexity, we replace the inner product with the outer product, to construct interaction map of the user and the item embedding. This is because the advantages of outer product are reflected in the following four aspects: • It does not have the disadvantage of element product only considering the diagonal elements of the interaction map; • It can obtain more information by encoding correlations among various embedding vectors; • It is more effective than the connection operation merely preserving the original information of the embedding vector and does not model any other correlation.
The interaction map layer allows the two embedding vectors (f U (u), f I (i)) to do outer product to get the interaction map E, shown in the following equation 2: where the (k 1 , k 2 ) -th element in E is: Obviously, all correlations of the pairwise embedding dimension are encoded in E.

Neural Collaborative Filtering
Neural collaborative filtering is a set of CF models based on the DNNs, in which side information is defined as user u s and item i s , the scoring function is shown as the equation 3: , , where, • function f (⋅) is the multi-layer perceptron; • h is the parameters of the network.
Recently, multi-layer perceptron (MLP) has been extensively investigated in the NCF tasks. This is because many existing RS models are linear methods in essence. However, MLP can improve recommendation performance via adding nonlinear transformations and interpreting them into neural extensions [8]. Despite MLP's success, there are still some shortcomings. MLP is easy to overfit and needs more computing resources due to many parameters. For explicit feedback, the whole network can be trained with weighted square loss. And for the implicit feedback, the whole network can be trained with weighted binary crossentropy loss. Equation 4 is the definition of the cross-entropy loss.

ConvNCF
Based on the NCF, we designed a ConvNCF layer which sets up 32 kernel for each convolution layer and generates a feature map c. A 2D matrix E lc represents a feature map c in the convolutional layer l, and its size is the half of its previous layer l -1 since the stride is 2. For layer l, a 3D tensor E l represented all feature maps together. There are 2 × 2 sizes with no padding of convolutional kernels.
Given the interaction map E of the input, we can obtain the feature maps from each layer in the equation 5 as follows: 1 1 , , 1 32 ReLU b e t l + + + × × • e x, y , the entry in the interaction map;

Adversarial Neural Collaborative Filtering with Embedding Dimension Correlations
• E xs:xe, ys:ye , the entries in the adjacent sub-region; • sub-region,all the basic correlations between f U (u) xs:xe and f I (i) ys:ye ; • b l + 1 , the bias term for layer l + 1, T 1 = [t 1 a,b,c ] 2×2×32 , where l = 0 is a 3D tensor; According to the equation 5, this feature e 1 x, y is the compound correlation of the four items in the interaction graph E, presented as [e 2x,2y; e 2x,2y+1 ; e 2x+1,2y ; e 2x+1,2y+1 ]. T herefore, e 1 x, y is a feature of combined correlation of E 2x:2x+1,2y:2y+1 , namely second-order correlation. As a result, E 1 consists of second-order correlation. The rest can be done in the sam e manner. E 2 consists of 4-order correlation.
We can conclude that only all the entries of the lower feature map can be covered by the entries of the higher feature map. Thus, correlations among all dimensions can be encoded by an entry of the last hidden layer. Based on the 2D interaction map E, high-order correlations of the embedding dimensions can be learned by the ConvNCF Layers both locally and globally according to stacking multiple convolutional layers.

Prediction Layer
Different from [15], this paper adopts matrix factorization trained with APR (i.e., Adversarial Matrix Factorization, AMF) in the prediction layer to solve the adversarial problem. The AMF approach is illustrated in Figure 2.

Adversarial Personal Ranking
Bayesian Personalized Ranking (BPR) overcomes the challenge that pairwise approaches ca nnot explicitly model the ranking information among items with stochastic gradient descent (SGD) [3]. Normally, BPR objective function is denoted in equation 6: where, • the s(·) is sigmoid function; • l H is the regularization parameter of the model; • D is the set of pairwise training instances;  u I + , the set of items that user u has interacted before;  I, the whole item set. However, BPR model is weak and vulnerable to certain perturbations, when added small perturbations on its parameters. Thus, an adversarial personalized ranking (APR) has been presented to address the adversarial interference via the objective function optimization [7]. Formally, the objective function of the adversarial personalized ranking defined as equation 7: where, • ∆ adv , the adversarial perturbations aiming to maximize the BPR object function; • ∆, the disturbance on model parameters; • e ≥ 0 decides the strength of the disturbance; • Ĥ , the present parameters of model; • H, aims to minimize the objective function.
The adversarial term L BPR (D|H + ∆ adv ) controlled by l is denoted as a regularization for stabilizing the function in the BPR. -e and lare two hyper-parameters in BPR. A training instance (u, i, j) is minimized by the local objective function as equation 8, and H is updated by the SGD rule in the equation 9: where g refers to the learning rate.
While models trained with APR are robust to adversarial perturbations, they might not be appropriate approaches for personalized ranking due to their weak effectiveness.

Adversarial Matrix Factorization
Give a pair (u, i), the predictive function of AMF is defined in equation 10: where, • v, a trainable weight vector in the prediction layer; • Δ u ∈ R K , the perturbation vector for user u; • Δ i ∈ R K , the perturbation vector for item i.
We utilize the mini-batch training to get updating rules for parameters in AMF. Firstly, given the mini batch (of size S) extracts training instances S as D'. Based on the mini batch D', the parameters are trained. The APR objective function for AMF is defined in equation 11: where l APR ((u, i, j)|H) has been defined in the equation 8. Likewise, the updating rule for H is defined in equation 12: Iterate over the above two steps until the AMF converges or performance begins to degrade.
Formally, the objective function for ANCF can be defined in equation 13: ( ) where l * are the hyper-parameters of the regularization, H U is the parameters in f U (·), H l is the parameters in f T (·), H ConvNCF is the parameters in ConvNCF and v for the prediction layer.

Datasets and Evaluation Protocols
This paper conducts experiments on three datasets including Yelp, Pinterest and Ml-1M. In the dataset, the latest user interaction is set up as the test set, the training set is set up as the remaining user interactions. After the model is trained, the next phrase is to obtain a personalized ranking list for the user via sorting the items in the training set that have no interaction with the user.
To study the performance of Top-k recommendation, this paper truncates the sorted list at position k ∈ {5, 10, 20}. Evaluation ranking lists in the paper consists of Hit Rate (HR@k), Normalized Discounted Cumulative Gain (NDCG@k) and Mean Reicprocal Rank (MRR@k). HR@k is a metric based on recalls measuring whether or not the test item is in the Top-k list. NDCG@k presents the ranking order, the higher the ranking item, the higher the calculated NDCG value. MRR@k is a statistic measure by producing a list of possible items to a sample of queries. For these three indicators, the larger the value, the better the personalized ranking list generated, and the better the recommendation effect. To eliminate the influence of stochastic oscillations, this paper reports the average score of last 10 epochs on convergence.

Baselines and Effectiveness Evaluation
All experiments are conducted under tensorflow-1.12 and python-2.7. To justify the proposed approach effectiveness, this paper compares the proposed approach with other approaches as follows: • MF-BPR [3]: This approach optimizes MF with BPR, which is a competitive CF-based approach • AMF [7]: Adversarial training is added to MF-BPR, which is also a part of the proposed approach.
• FISM [29]: Compared with MF which only embeds the user ID, this model integrates the history of interaction with the user to represent the user embedding.
• SVD++ [30]: CF model based on the MF and FISM for the user embedding.
• MLP [8]: an NCF model that concatenates the user embedding and the item embedding without encoding the embedding dimensional correlations.
• JRL [14]: It is an NCF model that improves the performance of GMF [8] by adding hidden layers.
• NeuMF [8]: It is an advanced recommendation model that integrates GMF and MLP to learn user-item interaction information.
As shown in Table 1 and Table 2, the proposed approach ANCF achieves the best resu lts based on three metrics on Yelp. On the datasets of the Pinterest and Ml-1M, ANCF has a remarkable performance. However, on the metric MRR@k, it seems that ANCF is unable to enhance the performance well.

The Effectiveness of Adversarial Learning
To ensure the good performance during the adversarial training, this paper pre-trained MF-BPR for 500 epochs (close to complete convergence), and then trained MF-APR (AMF); for comparison, this paper continues to complete the training of MF-BPR, so that the training epoch of the two is the same.
Under the condition of Top-k@10, all the diagrams in Figure 3 reflect that training MF with APR has achieved good results after 500 training epochs, while using BPR the outcome is not pleasing. It even declined slightly (in Pinterest and Ml-1M).

The Effectiveness of CNN
It can be seen from Figure 4 that under the condition of Top-k, k ∈{1, 2, …, 100}, both HR@k [31] and NDCG@k [32] have been improved, but they are still at a low level, especially the metric NDCG@k; This is because AMF cannot learn enough information.

Adversarial Neural Collaborative Filtering with Embedding Dimension Correlations
To address this problem, this paper utilized ANCF for training. The outer product layer in ANCF can explicitly encode the dimensional relationship between embeddings, and CNN can also handle feature maps well.

Figure 5. ANCF and AMF Training Curves
Unde r the condition of Top-k@10, AMF is utilized to be pre-trained 1500 epochs, and then ConvNCF is utilized to be trained 1500 epochs to learn high-dimensional information. As shown in Figure 5, the ANCF proposed in this paper has achieved remarkable results on all datasets. In the Yelp, using ANCF, HR@10 and NDCG@10 almost increased to 0.6524 and 0.4187 respectively; in the Pinterest, HR@10 and NDCG@10 are as high as 0.7600 and 0.4764, respectively; in the Ml-1M, HR@10 and NDCG@10 reach to around 0.6596 and 0.3591, respectively.

CONCLUSIONS
We present a novel ANCF model, which can obtain both the potential dimensional information among embeddings via the outer product and the preference information via multiple convolutional layers. Particularly, through the proposed adversarial training, ANCF can improve the overall robustness performance.
Experimental results demonstrated the flexibility and necessity of proposed schemes as follows: • it is significant to utilize both adversarial training and calculation of potential dimensional information in the CF model.
• the ANCF performance is much better than the existing advanced models in the context of Top-k item recommendation.
Our future work will focus on the attention mechanisms via the graph neural networks for the RS. In addition, we will look at the negative sampling mechanism in BPR and APR; The existing content-based recommendation model may also be utilized in the design of embedding vectors.

ACKNOWLEDGMENTS
This work is supported by National Natural Science Foundation of China (61902116).

AUTHOR CONTRIBUTION STATEMENT
Yi Gao (E-mail: 2856939182@qq.com, ORCID: 0000-0003-2645-2227): has participated sufficiently in the work to take public responsibility for the content, including participation in the coding, the experiment and analysis, writing the manuscript. Jianxia Chen (E-mail: 1607447166@qq.com, ORCID: 0000-0001-6662-1895): has participated sufficiently in the work to take public responsibility for the content, including participation in the model design, problem analysis, writing and revision of the manuscript.
Liang Xiao (E-mail: 48453626@qq.com, ORCID: 0000-0002-1564-2466): has participated sufficiently in the work to take public responsibility for the content, including participation in the model design and revision of the manuscript.

Adversarial Neural Collaborative Filtering with Embedding Dimension Correlations
Hongyang Wang (E-mail: 1586748352@qq.com, ORCID: 0000-0002-8202-6655): has participated sufficiently in the work to take public responsibility for the content, including participation in the part of the experiment of recommend system.
Liwei Pan (E-mail: 1547475261@qq.com, ORCID: 0000-0003-2645-2227): has participated sufficiently in the work to take public responsibility for the content, including participation in the part of the experiment of deep learning.
Xuan Wen (E-mail: 1595159972@qq.com, ORCID: 0000-0001-9278-2377): has participated sufficiently in the work to take public responsibility for the content, including participation in the revision of the experiment in the manuscript.
Zhiwei Ye (E-mail: 27454010@qq.com, ORCID: 0000-0001-6668-4634): has participated sufficiently in the work to take public responsibility for the content, including participation in the revision of the manuscript.
Xinyun Wu (E-mail: 67144659@qq.com, ORCID: 0000-0002-7525-0114): has participated sufficiently in the work to take public responsibility for the content, including participation in the revision of the manuscript.