Topic-oriented Adversarial Attacks against Black-box Neural Ranking Models
Yu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke, Wei Chen, Yixing Fan, Xueqi Cheng
Abstract
Neural ranking models (NRMs) have attracted considerable attention in information retrieval. Unfortunately, NRMs may inherit the adversarial vulnerabilities of general neural networks, which might be leveraged by black-hat search engine optimization practitioners. Recently, adversarial attacks against NRMs have been explored in the paired attack setting, generating an adversarial perturbation to a target document for a specific query. In this paper, we focus on a more general type of perturbation and introduce the topic-oriented adversarial ranking attack task against NRMs, which aims to find an imperceptible perturbation that can promote a target document in ranking for a group of queries with the same topic. We define both static and dynamic settings for the task and focus on decision-based black-box attacks. We propose a novel framework to improve topic-oriented attack performance based on a surrogate ranking model. The attack problem is formalized as a Markov decision process (MDP) and addressed using reinforcement learning. Specifically, a topic-oriented reward function guides the policy to find a successful adversarial example that can be promoted in rankings to as many queries as possible in a group. Experimental results demonstrate that the proposed framework can significantly outperform existing attack strategies, and we conclude by re-iterating that there exist potential risks for applying NRMs in the real world.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d5ffad12-93ed-4a65-b908-571f4a7b9d47Cited by top-tier papers9
- Are Large Language Models Good at Utility Judgments?Hengran Zhang, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke et al.SIGIR 2024 · 20 citations
- Hawkes-Enhanced Spatial-Temporal Hypergraph Contrastive Learning Based on Criminal CorrelationsKe Liang, Sihang Zhou, Meng Liu, Yue Liu et al.AAAI 2024 · 19 citations
- Multi-granular Adversarial Attacks against Black-box Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke et al.SIGIR 2024 · 17 citations
- Perturbation-Invariant Adversarial Training for Neural Ranking Models: Improving the Effectiveness-Robustness Trade-OffYu-An Liu, Ruqing Zhang, Mingkun Zhang, Wei Chen et al.AAAI 2024 · 17 citations
- Attack-in-the-Chain: Bootstrapping Large Language Models for Attacks Against Black-Box Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke et al.AAAI 2025 · 11 citations
Builds on6
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and EntailmentDi Jin, Zhijing Jin, Joey Tianyi Zhou, Peter SzolovitsAAAI 2020 · 1,333 citations
- A Reinforced Generation of Adversarial Examples for Neural Machine TranslationWei Zou, Shujian Huang, Jun Xie, Xinyu Dai et al.ACL 2020 · 66 citations
- Order-Disorder: Imitation Adversarial Attacks for Black-box Neural Ranking ModelsJiawei Liu, Yangyang Kang, Di Tang, Kaisong Song et al.CCS 2022 · 22 citations
- DAIR: A Query-Efficient Decision-based Attack on Image Retrieval SystemsMingyang Chen, Junda Lu, Yi Wang, Jianbin Qin et al.SIGIR 2021 · 20 citations
- Ranking-Incentivized Quality Preserving Content ModificationGregory Goren, Oren Kurland, Moshe Tennenholtz, Fiana RaiberSIGIR 2020 · 12 citations
Related papers
- Stop Hardening Everything: A Training-Free Neuron-Level Defense for Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Hongru Song, Jiafeng Guo et al.ACL 2026
- Unsupervised Corpus Poisoning Attacks in Continuous Space for Dense RetrievalYongkang Li, Panagiotis Eustratiadis, Simon Lupart, Evangelos KanoulasSIGIR 2025 · 3 citations
- ``Someone Hid It!'': Query-Agnostic Black-Box Attacks on LLM-Based RetrievalJiate Li, Defu Cao, Li Li, Wei Yang et al.ICML 2026 · 4 citations
- Practical Relative Order Attack in Deep RankingMo Zhou, Le Wang, Zhenxing Niu, Qilin Zhang et al.ICCV 2021 · 19 citations
- Topic-FlipRAG: Topic-Orientated Adversarial Opinion Manipulation Attacks to Retrieval-Augmented Generation ModelsYuyang Gong, Zhuo Chen, Jiawei Liu, Miaokun Chen et al.USENIX Security 2025
