Fake Resume Attacks: Data Poisoning on Online Job Platforms
Michiharu Yamashita, Thanh Tran, Dongwon Lee
Abstract
While recent studies have exposed various vulnerabilities incurred from data poisoning attacks in many web services, little is known about the vulnerability on online professional job platforms (e.g., LinkedIn and Indeed). In this work, first time, we demonstrate the critical vulnerabilities found in the common Human Resources (HR) task of matching job seekers and companies on online job platforms. Capitalizing on the unrestricted format and contents of job seekers' resumes and easy creation of accounts on job platforms, we demonstrate three attack scenarios: (1) company promotion attack to increase the likelihood of target companies being recommended, (2) company demotion attack to decrease the likelihood of target companies being recommended, and (3) user promotion attack to increase the likelihood of certain users being matched to certain companies. To this end, we develop an end-to-end "fake resume" generation framework, titled FRANCIS, that induces systematic prediction errors via data poisoning. Our empirical evaluation on real-world datasets reveals that data poisoning attacks can markedly skew the results of matchmaking between job seekers and companies, regardless of underlying models, with vulnerability amplified in proportion to poisoning intensity. These findings suggest that the outputs of various services from job platforms can be potentially hacked by malicious users. Our framework is available at: https://tinyurl.com/fr-attacks . CCS CONCEPTS • Security and privacy → Web application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e4f4905b-8c10-4bb0-ba2f-6d75ca867730Cited by top-tier papers2
- CAPER: Enhancing Career Trajectory Prediction using Temporal Knowledge Graph and Ternary RelationshipYeon-Chang Lee, Jaehyun Lee, Michiharu Yamashita, Dongwon Lee et al.KDD 2025 · 3 citations
- Unmasking Fake Careers: Detecting Machine-Generated Career Trajectories via Multi-layer Heterogeneous GraphsMichiharu Yamashita, Thanh Tran, Delvin Ce Zhang, Dongwon LeeEMNLP 2025 · 1 citation
Builds on8
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning AttacksAvi Schwarzschild, Micah Goldblum, Arjun Gupta, John P. Dickerson et al.ICML 2021 · 207 citations
- Examining the Use of Online Platforms for Employment: A Survey of U.S. Job SeekersTawanna R. Dillahunt, Aarti Israni, Alex Jiahong Lu, Mingzhi Cai et al.CHI 2021 · 47 citations
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen et al.SIGIR 2023 · 46 citations
- Large-Scale Talent Flow Embedding for Company Competitive AnalysisLe Zhang, Tong Xu, Hengshu Zhu, Chuan Qin et al.WWW 2020 · 45 citations
- Attentive Heterogeneous Graph Embedding for Job Mobility PredictionLe Zhang, Ding Zhou, Hengshu Zhu, Tong Xu et al.KDD 2021 · 39 citations
Related papers
- Measuring Real-World Prompt Injection Attacks in LLM-based Resume ScreeningMohan Zhang, Yuqi Jia, Zhen Tan, Steven Jiang et al.USENIX Security 2026 · 4 citations
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 126 citations
- PORE: Provably Robust Recommender Systems against Data Poisoning AttacksJinyuan Jia, Yupei Liu, Yuepeng Hu, Neil Zhenqiang GongUSENIX Security 2023
- Reverse Attack: Black-box Attacks on Collaborative RecommendationYihe Zhang, Xu Yuan, Jin Li, Jiadong Lou et al.CCS 2021 · 24 citations
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu et al.ICDE 2020 · 83 citations
