Adversarial Item Promotion: Vulnerabilities at the Core of Top-N Recommenders that Use Images to Address Cold Start
Zhuoran Liu, Martha A. Larson
摘要
E-commerce platforms provide their customers with ranked lists of recommended items matching the customers’ preferences. Merchants on e-commerce platforms would like their items to appear as high as possible in the top-N of these ranked lists. In this paper, we demonstrate how unscrupulous merchants can create item images that artificially promote their products, improving their rankings. Recommender systems that use images to address the cold start problem are vulnerable to this security risk. We describe a new type of attack, Adversarial Item Promotion (AIP), that strikes directly at the core of Top-N recommenders: the ranking mechanism itself. Existing work on adversarial images in recommender systems investigates the implications of conventional attacks, which target deep learning classifiers. In contrast, our AIP attacks are embedding attacks that seek to push features representations in a way that fools the ranker (not a classifier) and directly leads to item promotion. We introduce three AIP attacks insider attack, expert attack, and semantic attack, which are defined with respect to three successively more realistic attack models. Our experiments evaluate the danger of these attacks when mounted against three representative visually-aware recommender algorithms in a framework that uses images to address cold start. We also evaluate potential defenses, including adversarial training and find that common, currently-existing, techniques do not eliminate the danger of AIP attacks. In sum, we show that using images to address cold start opens recommender systems to potential threats with clear practical implications.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- When Federated Recommendation Meets Cold-Start Problem: Separating Item Attributes and User InteractionsChunxu Zhang, Guodong Long, Tianyi Zhou, Zijian Zhang 等WWW 2024 · 被引用 36 次
- Enhancing Adversarial Robustness of Multi-modal Recommendation via Modality BalancingYu Shang, Chen Gao, Jiansheng Chen, Depeng Jin 等ACM MM 2023 · 被引用 9 次
- DrunkAgent: Stealthy Memory Corruption in LLM-Powered Recommender AgentsShiyi Yang, Zhibo Hu, Xinshu Li, Chen Wang 等WWW 2026 · 被引用 6 次
- From Zero to Hero: Cross-modal-enhanced Adversarial Item Promotion Attack against Multimodal Recommender SystemsMengyu Yao, Ziqi Zhang, Yifeng Cai, Junlin Liu 等USENIX Security 2026
- VENOMREC: Cross-Modal Interactive Poisoning for Targeted Promotion in Multimodal LLM Recommender SystemsGuowei Guan, Yurong Hao, Jiaming Zhang, Tiantong Wu 等ICML 2026
它引用的顶会 Paper5
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 被引用 1,633 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Semantic Adversarial Attacks: Parametric Transformations That Fool Deep ClassifiersAmeya Joshi, Amitangshu Mukherjee, Soumik Sarkar, Chinmay HegdeICCV 2019 · 被引用 114 次
- Intriguing Properties of Adversarial Training at ScaleCihang Xie, Alan L. YuilleICLR 2020 · 被引用 66 次
- Towards Large Yet Imperceptible Adversarial Image Perturbations With Perceptual Color DistanceZhengyu Zhao, Zhuoran Liu, Martha A. LarsonCVPR 2020
相关 Paper
- A Study of Defensive Methods to Protect Visual Recommendation Against Adversarial Manipulation of ImagesVito Walter Anelli, Yashar Deldjoo, Tommaso Di Noia, Daniele Malitesta 等SIGIR 2021 · 被引用 30 次
- Shilling Black-box Review-based Recommender Systems through Fake Review GenerationHung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai 等KDD 2023 · 被引用 15 次
- Practical Relative Order Attack in Deep RankingMo Zhou, Le Wang, Zhenxing Niu, Qilin Zhang 等ICCV 2021 · 被引用 19 次
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 被引用 126 次
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning TrainingChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu 等SIGIR 2021 · 被引用 47 次
