Understanding and Improving Adversarial Collaborative Filtering for Robust Recommendation
Kaike Zhang, Qi Cao, Yunfan Wu, Fei Sun, Huawei Shen, Xueqi Cheng
Abstract
Adversarial Collaborative Filtering (ACF), which typically applies adversarial perturbations at user and item embeddings through adversarial training, is widely recognized as an effective strategy for enhancing the robustness of Collaborative Filtering (CF) recommender systems against poisoning attacks. Besides, numerous studies have empirically shown that ACF can also improve recommendation performance compared to traditional CF. Despite these empirical successes, the theoretical understanding of ACF's effectiveness in terms of both performance and robustness remains unclear. To bridge this gap, in this paper, we first theoretically show that ACF can achieve a lower recommendation error compared to traditional CF with the same training epochs in both clean and poisoned data contexts. Furthermore, by establishing bounds for reductions in recommendation error during ACF's optimization process, we find that applying personalized magnitudes of perturbation for different users based on their embedding scales can further improve ACF's effectiveness. Building on these theoretical understandings, we propose Personalized Magnitude Adversarial Collaborative Filtering (PamaCF). Extensive experiments demonstrate that PamaCF effectively defends against various types of poisoning attacks while significantly enhancing recommendation performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0f920db-0d7f-46ab-bc77-38a4e526090fCited by top-tier papers2
- Personalized Denoising Implicit Feedback for Robust Recommender SystemKaike Zhang, Qi Cao, Yunfan Wu, Fei Sun et al.WWW 2025 · 12 citations
- GoalRank: Group-Relative Optimization for a Large Ranking ModelKaike Zhang, Xiaobei Wang, Shuchang Liu, HailanYang et al.ICLR 2026 · 2 citations
Builds on14
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- MIND: A Large-scale Dataset for News RecommendationFangzhao Wu, Ying Qiao, Jiun-Hung Chen, Chuhan Wu et al.ACL 2020 · 454 citations
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen et al.SIGIR 2020 · 163 citations
- Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat ModelsNaman Deep Singh, Francesco Croce, Matthias HeinNeurIPS 2023 · 119 citations
- Learning to Denoise Unreliable Interactions for Graph Collaborative FilteringChangxin Tian, Yuexiang Xie, Yaliang Li, Nan Yang et al.SIGIR 2022 · 109 citations
Related papers
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning TrainingChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu et al.SIGIR 2021 · 47 citations
- Not One Less: Exploring Interplay between User Profiles and Items in Untargeted Attacks against Federated RecommendationYurong Hao, Xihui Chen, Xiaoting Lyu, Jiqiang Liu et al.CCS 2024 · 4 citations
- How Dataset Characteristics Affect the Robustness of Collaborative Recommendation ModelsYashar Deldjoo, Tommaso Di Noia, Eugenio Di Sciascio, Felice Antonio MerraSIGIR 2020 · 50 citations
- Preventing the Popular Item Embedding Based Attack in Federated RecommendationsJun Zhang, Huan Li, Dazhong Rong, Yan Zhao et al.ICDE 2024 · 7 citations
- Reverse Attack: Black-box Attacks on Collaborative RecommendationYihe Zhang, Xu Yuan, Jin Li, Jiadong Lou et al.CCS 2021 · 24 citations
