Trustworthy Recommender Systems: Robustness and Privacy Perspectives

Publication Type:
Thesis
Issue Date:
2026
Full metadata record
Trustworthy recommender systems are essential for providing personalised, reliable, and secure services in the face of increasing data complexity and stringent privacy regulations. While traditional systems rely on high-quality user-item interactions, real- world scenarios often involve "low-quality" input data, e.g., characterised by limited feedback and corruption, and rising demands for data sovereignty through "right to be forgotten" mandates. This thesis addresses these critical challenges by proposing a comprehensive framework for building trustworthy recommender systems that ensure reliability under data adversity and privacy-preserving requirements. The first half of this research focuses on improving reliability when training data is imperfect. We first address the cold-start and limited-feedback problem by investigating a setting in which only browsing histories are available, without explicit acquisition signals (e.g., purchases or ratings). We propose the Partial Acquisition Recommender System (PARS), which draws an analogy to partial label learning to extract reliable preferences from ambiguous sequences. We then address rating flip noise, a prevalent issue in which interaction history is corrupted. By modelling the noise generation process through a noise transition matrix, we develop a statistically consistent algorithm that enables the system to remain robust against corrupted ratings, significantly outperforming traditional models that assume noise-free data. The second half of the thesis shifts toward privacy preservation through machine unlearning. As users increasingly demand the removal of their sensitive information, retraining models from scratch becomes computationally prohibitive. We introduce a novel targeted label noise injection method that allows for the efficient removal of specific client data without accessing the remaining training set, a critical requirement when data is unavailable due to expiration or storage limits. This approach also encourages the model to lose confidence in "to-be-forgotten" sequences by moving them across the decision boundary with minimal impact on overall recommendation accuracy. We further extend this framework to robust sequential unlearning, ensuring that the "right to be forgotten" is upheld even in complex sequential architectures without sacrificing generalisation performance. Through extensive empirical evaluations on real-world benchmarks, this thesis demonstrates that trustworthy recommender systems can be achieved by balancing predictive power with data integrity and user privacy. By mitigating the risks of system bias, noise, and privacy leaks, this research contributes to the long-term viability and ethical deployment of recommendation technologies across diverse digital domains.
Please use this identifier to cite or link to this item: