Shilling Black-box Review-based Recommender Systems through Fake Review Generation
Hung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai, Jason S. Chang
Abstract
Review-Based Recommender Systems (RBRS) have attracted increasing research interest due to their ability to alleviate wellknown cold-start problems. RBRS utilizes reviews to construct the user and items representations. However, in this paper, we argue that such a reliance on reviews may instead expose systems to the risk of being shilled. To explore this possibility, in this paper, we propose the first generation-based model for shilling attacks against RBRSs. Specifically, we learn a fake review generator through reinforcement learning, which maliciously promotes items by forcing prediction shifts after adding generated reviews to the system. By introducing the auxiliary rewards to increase text fluency and diversity with the aid of pre-trained language models and aspect predictors, the generated reviews can be effective for shilling with high fidelity. Experimental results demonstrate that the proposed framework can successfully attack three different kinds of RBRSs on the Amazon corpus with three domains and Yelp corpus. Furthermore, human studies also show that the generated reviews are fluent and informative. Finally, equipped with Attack Review Generators (ARGs), RBRSs with adversarial training are much more robust to malicious reviews. CCS CONCEPTS • Information systems → Recommender systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3053fe94-0c2e-47f9-a2ee-604db1710b0cCited by top-tier papers1
Ask how each one uses itBuilds on16
- TextBugger: Generating Adversarial Text Against Real-world ApplicationsJinfeng Li, Shouling Ji, Tianyu Du, Bo Li et al.NDSS 2019 · 876 citations
- A Review-aware Graph Contrastive Learning Framework for RecommendationJie Shuai, Kun Zhang, Le Wu, Peijie Sun et al.SIGIR 2022 · 170 citations
- Context-aware Scene Graph Generation with Seq2Seq TransformersYichao Lu, Himanshu Rai, Jason Chang, Boris Knyazev et al.ICCV 2021 · 93 citations
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu et al.ICDE 2020 · 83 citations
- Asymmetrical Hierarchical Networks with Attentive Interactions for Interpretable Review-Based RecommendationXin Dong, Jingchao Ni, Wei Cheng, Zhengzhang Chen et al.AAAI 2020 · 62 citations
Related papers
- Practical Cross-System Shilling Attacks with Limited Access to DataMeifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao et al.AAAI 2023 · 12 citations
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen et al.SIGIR 2020 · 163 citations
- Trust-GRS: A Trustworthy Training Framework for Graph Neural Network Based Recommender Systems Against Shilling AttacksLingyu Mu, Zhengxiao Liu, Zhitong Zhu, Zheng LinAAAI 2025 · 6 citations
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning TrainingChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu et al.SIGIR 2021 · 47 citations
- How Dataset Characteristics Affect the Robustness of Collaborative Recommendation ModelsYashar Deldjoo, Tommaso Di Noia, Eugenio Di Sciascio, Felice Antonio MerraSIGIR 2020 · 50 citations
