Diversity-aware Dual-promotion Poisoning Attack on Sequential Recommendation
Yuchuan Zhao, Tong Chen, Junliang Yu, Kai Zheng, Lizhen Cui, Hongzhi Yin
Abstract
Sequential recommender systems (SRSs) excel in capturing users' dynamic interests, thus playing a key role in various industrial applications. The popularity of SRSs has also driven emerging research on their security aspects, where data poisoning attack for targeted item promotion is a typical example. Existing attack mechanisms primarily focus on increasing the ranks of target items in the recommendation list by injecting carefully crafted interactions (i.e., poisoning sequences), which comes at the cost of demoting users' real preferences. Consequently, noticeable recommendation accuracy drops are observed, restricting the stealthiness of the attack. Additionally, the generated poisoning sequences are prone to substantial repetition of target items, which is a result of the unitary objective of boosting their overall exposure and lack of effective diversity regularizations. Such homogeneity not only compromises the authenticity of these sequences, but also limits the attack effectiveness, as it ignores the opportunity to establish sequential dependencies between the target and many more items in the SRS. To address the issues outlined, we propose a Diversity-aware Dual-promotion Sequential Poisoning attack method named DDSP for SRSs. Specifically, by theoretically revealing the conflict between recommendation and existing attack objectives, we design a revamped attack objective that promotes the target item while maintaining the relevance of preferred items in a user's ranking list. We further develop a diversity-aware, auto-regressive poisoning sequence generator, where a re-ranking method is in place to sequentially pick the optimal items by integrating diversity constraints. By attacking two representative SRSs on three real-world datasets, comprehensive experimental results demonstrate that DDSP outperforms state-of-the-art attack methods in attack effectiveness. Moreover, DDSP achieves the strongest stealthiness with its lowest impact on recommendation accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Prompt-Unknown Promotion Attacks against LLM-based Sequential Recommender SystemsYuchuan Zhao, Tong Chen, Junliang Yu, Zongwei Wang et al.SIGIR 2026
- ProMax: Exploring the Potential of LLM-derived Profiles with Distribution Shaping for Recommender SystemsYi Zhang, Yiwen Zhang, Kai Zheng, Tong Chen et al.SIGIR 2026
Builds on17
- Contrastive Learning for Sequential RecommendationXu Xie, Fei Sun, Zhaoyang Liu, Shiwen Wu et al.ICDE 2022 · 674 citations
- Intent Contrastive Learning for Sequential RecommendationYongjun Chen, Zhiwei Liu, Jia Li, Julian J. McAuley et al.WWW 2022 · 429 citations
- Model-Agnostic Counterfactual Reasoning for Eliminating Popularity Bias in Recommender SystemTianxin Wei, Fuli Feng, Jiawei Chen, Ziwei Wu et al.KDD 2021 · 246 citations
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 126 citations
- FedRecAttack: Model Poisoning Attack to Federated RecommendationDazhong Rong, Shuai Ye, Ruoyan Zhao, Hon Ning Yuen et al.ICDE 2022 · 76 citations
Related papers
- Poisoning Self-supervised Learning Based Sequential RecommendationsYanling Wang, Yuchen Liu, Qian Wang, Cong Wang et al.SIGIR 2023 · 16 citations
- Revisiting Injective Attacks on Recommender SystemsHaoyang Li, Shimin Di, Lei ChenNeurIPS 2022 · 26 citations
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu et al.ICDE 2020 · 83 citations
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin et al.KDD 2024 · 16 citations
- Unleashing the Potential of Diffusion Models Towards Diversified Sequential RecommendationsZhuo Cai, Shoujin Wang, Victor W. Chu, Usman Naseem et al.SIGIR 2025 · 7 citations
