Uplift Modeling for Target User Attacks on Recommender Systems
Wenjie Wang, Changsheng Wang, Fuli Feng, Wentao Shi, Daizong Ding, Tat-Seng Chua
Abstract
Recommender systems are vulnerable to injective attacks, which inject limited fake users into the platforms to manipulate the exposure of target items to all users. In this work, we identify that conventional injective attackers overlook the fact that each item has its unique potential audience, and meanwhile, the attack difficulty across different users varies. Blindly attacking all users will result in a waste of fake user budgets and inferior attack performance. To address these issues, we focus on an under-explored attack task called target user attacks, aiming at promoting target items to a particular user group. In addition, we formulate the varying attack difficulty as heterogeneous treatment effects through a causal lens and propose an Uplift-guided Budget Allocation (UBA) framework. UBA estimates the treatment effect on each target user and optimizes the allocation of fake user budgets to maximize the attack performance. Theoretical and empirical analysis demonstrates the rationality of treatment effect estimation methods of UBA. By instantiating UBA on multiple attackers, we conduct extensive experiments on three datasets under various settings with different target items, target users, fake user budgets, victim models, and defense models, validating the effectiveness and robustness of UBA. CCS CONCEPTS • Information systems → Recommender systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3a83d170-4672-4f22-9c33-23e5d1cd75afCited by top-tier papers1
Ask how each one uses itBuilds on19
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 126 citations
- Graph Embedding for Recommendation against Attribute Inference AttacksShijie Zhang, Hongzhi Yin, Tong Chen, Zi Huang et al.WWW 2021 · 109 citations
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu et al.ICDE 2020 · 83 citations
- Attacking Black-box Recommendations via Copying Cross-domain User ProfilesWenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma et al.ICDE 2021 · 75 citations
Related papers
- Revisiting Injective Attacks on Recommender SystemsHaoyang Li, Shimin Di, Lei ChenNeurIPS 2022 · 26 citations
- Who Should Be Given Incentives? Counterfactual Optimal Treatment Regimes Learning for RecommendationHaoxuan Li, Chunyuan Zheng, Peng Wu, Kun Kuang et al.KDD 2023 · 15 citations
- Practical Cross-System Shilling Attacks with Limited Access to DataMeifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao et al.AAAI 2023 · 12 citations
- LBCF: A Large-Scale Budget-Constrained Causal Forest AlgorithmMeng Ai, Biao Li, Heyang Gong, Qingwei Yu et al.WWW 2022 · 27 citations
- Treatment Effect Estimation for User Interest Exploration on Recommender SystemsJiaju Chen, Wenjie Wang, Chongming Gao, Peng Wu et al.SIGIR 2024 · 8 citations
