Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning Attacks
Zongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin, Bin Cui, Shazia Sadiq
Abstract
Contrastive learning (CL) has recently gained prominence in the domain of recommender systems due to its great ability to enhance recommendation accuracy and improve model robustness. Despite its advantages, this paper identifies a vulnerability of CL-based recommender systems that they are more susceptible to poisoning attacks aiming to promote individual items. Our analysis indicates that this vulnerability is attributed to the uniform spread of representations caused by the InfoNCE loss. Furthermore, theoretical and empirical evidence shows that optimizing this loss favors smooth spectral values of representations. This finding suggests that attackers could facilitate this optimization process of CL by encouraging a more uniform distribution of spectral values, thereby enhancing the degree of representation dispersion. With these insights, we attempt to reveal a potential poisoning attack against CL-based recommender systems, which encompasses a dual-objective framework: one that induces a smoother spectral value distribution to amplify the InfoNCE loss's inherent dispersion effect, named dispersion promotion; and the other that directly elevates the visibility of target items, named rank promotion. We validate the threats of our attack model through extensive experimentation on four datasets. By shedding light on these vulnerabilities, our goal is to advance the development of more robust CL-based recommender systems. The code is available at https://github.com/CoderWZW/ARLib . CCS CONCEPTS • Information systems → Recommender systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Diversity-aware Dual-promotion Poisoning Attack on Sequential RecommendationYuchuan Zhao, Tong Chen, Junliang Yu, Kai Zheng et al.SIGIR 2025 · 6 citations
- Trust-GRS: A Trustworthy Training Framework for Graph Neural Network Based Recommender Systems Against Shilling AttacksLingyu Mu, Zhengxiao Liu, Zhitong Zhu, Zheng LinAAAI 2025 · 6 citations
- ID-Free Not Risk-Free: LLM-Powered Agents Unveil Risks in ID-Free Recommender SystemsZongwei Wang, Min Gao, Junliang Yu, Xinyi Gao et al.SIGIR 2025 · 4 citations
- Prompt-Induced Linguistic Fingerprints for LLM-Generated Fake News DetectionChi Wang, Min Gao, Zongwei Wang, Junwei Yin et al.WWW 2026 · 3 citations
- Relational Database Distillation: From Structured Tables to Condensed Graph DataXinyi Gao, Jingxi Zhang, Lijian Chen, Tong Chen et al.WWW 2026 · 2 citations
Builds on24
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- Supervised Contrastive LearningPrannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna et al.NeurIPS 2020 · 7,049 citations
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen et al.NeurIPS 2020 · 3,042 citations
- Understanding Contrastive Representation Learning through Alignment and Uniformity on the HypersphereTongzhou Wang, Phillip IsolaICML 2020 · 2,360 citations
Related papers
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Indiscriminate Poisoning Attacks on Unsupervised Contrastive LearningHao He, Kaiwen Zha, Dina KatabiICLR 2023 · 4 citations
- Spattack: Subgroup Poisoning Attacks on Federated Recommender SystemsBo Yan, Yurong Hao, Dingqi Liu, Huabin Sun et al.WWW 2026
- Empowering Collaborative Filtering with Principled Adversarial Contrastive LossAn Zhang, Leheng Sheng, Zhibo Cai, Xiang Wang et al.NeurIPS 2023 · 56 citations
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 32 citations
