Practical Cross-System Shilling Attacks with Limited Access to Data
Meifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao, Hui Li
Abstract
In shilling attacks, an adversarial party injects a few fake user profiles into a Recommender System (RS) so that the target item can be promoted or demoted. Although much effort has been devoted to developing shilling attack methods, we find that existing approaches are still far from practical. In this paper, we analyze the properties a practical shilling attack method should have and propose a new concept of Cross-system Attack. With the idea of Cross-system Attack, we design a Practical Cross-system Shilling Attack (PC-Attack) framework that requires little information about the victim RS model and the target RS data for conducting attacks. PC-Attack is trained to capture graph topology knowledge from public RS data in a self-supervised manner. Then, it is fine-tuned on a small portion of target data that is easy to access to construct fake profiles. Extensive experiments have demonstrated the superiority of PC-Attack over state-of-the-art baselines. Our implementation of PC-Attack is available at https://github.com/KDEGroup/PC-Attack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext faee4aa0-7364-4527-8a9c-4f8ffe7ca9ccCited by top-tier papers2
- DrunkAgent: Stealthy Memory Corruption in LLM-Powered Recommender AgentsShiyi Yang, Zhibo Hu, Xinshu Li, Chen Wang et al.WWW 2026 · 6 citations
- From Zero to Hero: Cross-modal-enhanced Adversarial Item Promotion Attack against Multimodal Recommender SystemsMengyu Yao, Ziqi Zhang, Yifeng Cai, Junlin Liu et al.USENIX Security 2026
Builds on6
- LightGCN: Simplifying and Powering Graph Convolution Network for RecommendationXiangnan He, Kuan Deng, Xiang Wang, Yan Li et al.SIGIR 2020 · 4,448 citations
- GCC: Graph Contrastive Coding for Graph Neural Network Pre-TrainingJiezhong Qiu, Qibin Chen, Yuxiao Dong, Jing Zhang et al.KDD 2020 · 755 citations
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 126 citations
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu et al.ICDE 2020 · 83 citations
- Attacking Black-box Recommendations via Copying Cross-domain User ProfilesWenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma et al.ICDE 2021 · 75 citations
Related papers
- Trust-GRS: A Trustworthy Training Framework for Graph Neural Network Based Recommender Systems Against Shilling AttacksLingyu Mu, Zhengxiao Liu, Zhitong Zhu, Zheng LinAAAI 2025 · 6 citations
- Shilling Black-box Review-based Recommender Systems through Fake Review GenerationHung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai et al.KDD 2023 · 15 citations
- How Dataset Characteristics Affect the Robustness of Collaborative Recommendation ModelsYashar Deldjoo, Tommaso Di Noia, Eugenio Di Sciascio, Felice Antonio MerraSIGIR 2020 · 50 citations
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen et al.SIGIR 2020 · 163 citations
- Anti-FakeU: Defending Shilling Attacks on Graph Neural Network based Recommender ModelXiaoyu You, Chi Li, Daizong Ding, Mi Zhang et al.WWW 2023 · 11 citations
