USENIX Security2023Top-tier venue
PORE: Provably Robust Recommender Systems against Data Poisoning Attacks
Jinyuan Jia, Yupei Liu, Yuepeng Hu, Neil Zhenqiang Gong
Abstract
Data poisoning attacks spoof a recommender system to make arbitrary, attacker-desired recommendations via injecting fake users with carefully crafted rating scores into the recommender system. We envision a cat-and-mouse game for such data poisoning attacks and their defenses, i.e., new defenses are designed to defend against existing attacks and new attacks are designed to break them. To prevent such a cat-and-mouse game, we propose PORE, the first framework to build provably robust recommender systems in this work. PORE can transform any existing recommender system to be provably robust against any untargeted data poisoning attacks, which aim to reduce the overall performance of a recommender system. Suppose PORE recommends top- items to a user when there is no attack. We prove that PORE still recommends at least of the items to the user under any data poisoning attack, where is a function of the number of fake users in the attack. Moreover, we design an efficient algorithm to compute for each user. We empirically evaluate PORE on popular benchmark datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f9aaf47a-b362-4cd7-9102-55306cb2c592Cited by top-tier papers6
- Node-aware Bi-smoothing: Certified Robustness against Graph Injection AttacksYuni Lai, Yulin Zhu, Bailin Pan, Kai ZhouS&P 2024 · 11 citations
- FCert: Certifiably Robust Few-Shot Classification in the Era of Foundation ModelsYanting Wang, Wei Zou, Jinyuan JiaS&P 2024 · 4 citations
- Collective Certified Robustness against Graph Injection AttacksYuni Lai, Bailin Pan, Kaihuang Chen, Yancheng Yuan et al.ICML 2024 · 4 citations
- EmoRAG: Evaluating RAG Robustness to Symbolic PerturbationsXinyun Zhou, Xinfeng Li, Yinan Peng, Ming Xu et al.KDD 2026 · 2 citations
- PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language ModelsWei Zou, Runpeng Geng, Binghui Wang, Jinyuan JiaUSENIX Security 2025
Builds on9
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- Intrinsic Certified Robustness of Bagging against Data Poisoning AttacksJinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongAAAI 2021 · 155 citations
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 126 citations
- Certified Robustness of Nearest Neighbors against Data Poisoning and Backdoor AttacksJinyuan Jia, Yupei Liu, Xiaoyu Cao, Neil Zhenqiang GongAAAI 2022 · 90 citations
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu et al.ICDE 2020 · 83 citations
Related papers
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning TrainingChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu et al.SIGIR 2021 · 47 citations
- Data Poisoning Attacks to Deep Learning Based Recommender SystemsHai Huang, Jiaming Mu, Neil Zhenqiang Gong, Qi Li et al.NDSS 2021
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 32 citations
- Data Poisoning Attack against Recommender System Using Incomplete and Perturbed DataHengtong Zhang, Changxin Tian, Yaliang Li, Lu Su et al.KDD 2021 · 51 citations
- Triple Adversarial Learning for Influence based Poisoning Attack in Recommender SystemsChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu et al.KDD 2021 · 53 citations
