Stealthy Attack on Large Language Model based Recommendation
Jinghao Zhang, Yuting Liu, Qiang Liu, Shu Wu, Guibing Guo, Liang Wang
摘要
Recently, the powerful large language models (LLMs) have been instrumental in propelling the progress of recommender systems (RS). However, while these systems have flourished, their susceptibility to security threats has been largely overlooked. In this work, we reveal that the introduction of LLMs into recommendation models presents new security vulnerabilities due to their emphasis on the textual content of items. We demonstrate that attackers can significantly boost an item's exposure by merely altering its textual content during the testing phase, without requiring direct interference with the model's training process. Additionally, the attack is notably stealthy, as it does not affect the overall recommendation performance and the modifications to the text are subtle, making it difficult for users and platforms to detect. Our comprehensive experiments across four mainstream LLM-based recommendation models demonstrate the superior efficacy and stealthiness of our approach. Our work unveils a significant security gap in LLM-based recommendation systems and paves the way for future research on protecting these systems. 1
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Modality-Balanced Learning for Multimedia RecommendationJinghao Zhang, Guofan Liu, Qiang Liu, Shu Wu 等ACM MM 2024 · 被引用 21 次
- CoRA: Collaborative Information Perception by Large Language Model's Weights for RecommendationYuting Liu, Jinghao Zhang, Yizhou Dang, Yuliang Liang 等AAAI 2025 · 被引用 15 次
- Are LLMs Reliable Rankers? Rank Manipulation via Two-Stage Token OptimizationTiancheng Xing, Jerry Li, Yixuan Du, Xiyang HuACL 2026 · 被引用 8 次
- DrunkAgent: Stealthy Memory Corruption in LLM-Powered Recommender AgentsShiyi Yang, Zhibo Hu, Xinshu Li, Chen Wang 等WWW 2026 · 被引用 6 次
- ID-Free Not Risk-Free: LLM-Powered Agents Unveil Risks in ID-Free Recommender SystemsZongwei Wang, Min Gao, Junliang Yu, Xinyi Gao 等SIGIR 2025 · 被引用 4 次
它引用的顶会 Paper13
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and EntailmentDi Jin, Zhijing Jin, Joey Tianyi Zhou, Peter SzolovitsAAAI 2020 · 被引用 1,333 次
- BERT-ATTACK: Adversarial Attack Against BERT Using BERTLinyang Li, Ruotian Ma, Qipeng Guo, Xiangyang Xue 等EMNLP 2020 · 被引用 529 次
- MIND: A Large-scale Dataset for News RecommendationFangzhao Wu, Ying Qiao, Jiun-Hung Chen, Chuhan Wu 等ACL 2020 · 被引用 454 次
- Causal Intervention for Leveraging Popularity Bias in RecommendationYang Zhang, Fuli Feng, Xiangnan He, Tianxin Wei 等SIGIR 2021 · 被引用 431 次
- Mining Latent Structures for Multimedia RecommendationJinghao Zhang, Yanqiao Zhu, Qiang Liu, Shu Wu 等ACM MM 2021 · 被引用 350 次
相关 Paper
- Prompt-Unknown Promotion Attacks against LLM-based Sequential Recommender SystemsYuchuan Zhao, Tong Chen, Junliang Yu, Zongwei Wang 等SIGIR 2026
- CheatAgent: Attacking LLM-Empowered Recommender Systems via LLM AgentLiang-Bo Ning, Shijie Wang, Wenqi Fan, Qing Li 等KDD 2024 · 被引用 11 次
- From Zero to Hero: Cross-modal-enhanced Adversarial Item Promotion Attack against Multimodal Recommender SystemsMengyu Yao, Ziqi Zhang, Yifeng Cai, Junlin Liu 等USENIX Security 2026
- LoRec: Combating Poisons with Large Language Model for Robust Sequential RecommendationKaike Zhang, Qi Cao, Yunfan Wu, Fei Sun 等SIGIR 2024 · 被引用 13 次
- ``Someone Hid It!'': Query-Agnostic Black-Box Attacks on LLM-Based RetrievalJiate Li, Defu Cao, Li Li, Wei Yang 等ICML 2026 · 被引用 4 次
