Anti-FakeU: Defending Shilling Attacks on Graph Neural Network based Recommender Model
Xiaoyu You, Chi Li, Daizong Ding, Mi Zhang, Fuli Feng, Xudong Pan, Min Yang
Abstract
Graph neural network (GNN) based recommendation models are observed to be more vulnerable against carefully-designed malicious records injected into the system, i.e., shilling attacks, which manipulate the recommendation to common users and therefore impair user trust. In this paper, we for the first time conduct a systematic study on the vulnerability of GNN based recommendation model against the shilling attack. With the aid of theoretical analysis, we attribute the root cause of the vulnerability to its neighborhood aggregation mechanism, which could make the negative impact of attacks propagate rapidly in the system. To restore the robustness of GNN based recommendation model, the key factor lies in detecting malicious records in the system and preventing the propagation of misinformation. To this end, we construct a user-user graph to capture the patterns of malicious behaviors and design a novel GNN based detector to identify fake users. Furthermore, we develop a data augmentation strategy and a joint learning paradigm to train the recommender model and the proposed detector. Extensive experiments on benchmark datasets validate the enhanced robustness of the proposed method in resisting various types of shilling attacks and identifying fake users, e.g., our proposed method fully mitigating the impact of popularity attacks on target items up to , and improving the accuracy of detecting fake users on the Gowalla dataset by .
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 06befa5f-1eb7-4567-b771-e621d84b12e8Cited by top-tier papers3
- Uplift Modeling for Target User Attacks on Recommender SystemsWenjie Wang, Changsheng Wang, Fuli Feng, Wentao Shi et al.WWW 2024 · 11 citations
- Unveiling the Threat of Fraud Gangs to Graph Neural Networks: Multi-Target Graph Injection Attacks Against GNN-Based Fraud DetectorsJinhyeok Choi, Heehyeon Kim, Joyce Jiyoung WhangAAAI 2025 · 6 citations
- Trust-GRS: A Trustworthy Training Framework for Graph Neural Network Based Recommender Systems Against Shilling AttacksLingyu Mu, Zhengxiao Liu, Zhitong Zhu, Zheng LinAAAI 2025 · 6 citations
Related papers
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen et al.SIGIR 2020 · 163 citations
- How Dataset Characteristics Affect the Robustness of Collaborative Recommendation ModelsYashar Deldjoo, Tommaso Di Noia, Eugenio Di Sciascio, Felice Antonio MerraSIGIR 2020 · 50 citations
- Practical Cross-System Shilling Attacks with Limited Access to DataMeifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao et al.AAAI 2023 · 12 citations
- RSA-CR: Resisting Shilling Attacks in Citation Recommendation via Dumbbell Inductive LearningXiyue Gao, Yukai Liu, Zhuoqi Ma, Xiaotian Qiao et al.AAAI 2026
- Shilling Black-box Review-based Recommender Systems through Fake Review GenerationHung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai et al.KDD 2023 · 15 citations
