Lune

USENIX Security2023Top-tier venue

PORE: Provably Robust Recommender Systems against Data Poisoning Attacks

Jinyuan Jia, Yupei Liu, Yuepeng Hu, Neil Zhenqiang Gong

2023Year
6Top-tier citations

Abstract

Data poisoning attacks spoof a recommender system to make arbitrary, attacker-desired recommendations via injecting fake users with carefully crafted rating scores into the recommender system. We envision a cat-and-mouse game for such data poisoning attacks and their defenses, i.e., new defenses are designed to defend against existing attacks and new attacks are designed to break them. To prevent such a cat-and-mouse game, we propose PORE, the first framework to build provably robust recommender systems in this work. PORE can transform any existing recommender system to be provably robust against any untargeted data poisoning attacks, which aim to reduce the overall performance of a recommender system. Suppose PORE recommends top-NN items to a user when there is no attack. We prove that PORE still recommends at least rr of the NN items to the user under any data poisoning attack, where rr is a function of the number of fake users in the attack. Moreover, we design an efficient algorithm to compute rr for each user. We empirically evaluate PORE on popular benchmark datasets.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext f9aaf47a-b362-4cd7-9102-55306cb2c592

Cited by top-tier papers6

Ask how each one uses it

Builds on9

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines