Triple Adversarial Learning for Influence based Poisoning Attack in Recommender Systems
Chenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu, Enhong Chen
Abstract
As an important means to solve information overload, recommender systems have been widely applied in many fields, such as e-commerce and advertising. However, recent studies have shown that recommender systems are vulnerable to poisoning attacks; that is, injecting a group of carefully designed user profiles into the recommender system can severely affect recommendation quality. Despite the development from shilling attacks to optimization-based attacks, the imperceptibility and harmfulness of the generated data in most attacks are arduous to balance. To this end, we propose a triple adversarial learning for influence based poisoning attack (TrialAttack), a flexible end-to-end poisoning framework to generate non-notable and harmful user profiles. Specifically, given the input noise, TrialAttack directly generates malicious users through triple adversarial learning of the generator, discriminator, and influence module. Besides, to provide reliable influence for TrialAttack training, we explore a new approximation approach for estimating each fake user's influence. Through theoretical analysis, we prove that the distribution characterized by TrialAttack approximates to the rating distribution of real users under the premise of performing an efficient attack. This property allows the injected users to attack in an unremarkable way. Experiments on three real-world datasets show that TrialAttack's attack performance outperforms state-of-the-art attacks, and the generated fake profiles are more difficult to detect compared to baselines.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get ddf6ca33-bac9-4d2f-9be0-925b7d38e3beCited by top-tier papers12
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Knowledge-enhanced Black-box Attacks for RecommendationsJingfan Chen, Wenqi Fan, Guanghui Zhu, Xiangyu Zhao et al.KDD 2022 · 44 citations
- Revisiting Injective Attacks on Recommender SystemsHaoyang Li, Shimin Di, Lei ChenNeurIPS 2022 · 26 citations
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin et al.KDD 2024 · 16 citations
- Shilling Black-box Review-based Recommender Systems through Fake Review GenerationHung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai et al.KDD 2023 · 15 citations
Related papers
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning TrainingChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu et al.SIGIR 2021 · 47 citations
- Data Poisoning Attack against Recommender System Using Incomplete and Perturbed DataHengtong Zhang, Changxin Tian, Yaliang Li, Lu Su et al.KDD 2021 · 51 citations
- Attacking Black-box Recommendations via Copying Cross-domain User ProfilesWenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma et al.ICDE 2021 · 75 citations
- Practical Cross-System Shilling Attacks with Limited Access to DataMeifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao et al.AAAI 2023 · 12 citations
- Reverse Attack: Black-box Attacks on Collaborative RecommendationYihe Zhang, Xu Yuan, Jin Li, Jiadong Lou et al.CCS 2021 · 24 citations
