Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning Training
Chenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu, Enhong Chen, Senchao Yuan
摘要
Recent studies have shown that recommender systems are vulnerable, and it is easy for attackers to inject well-designed malicious profiles into the system, leading to biased recommendations. We cannot deny these data's rationality, making it imperative to establish a robust recommender system. Adversarial training has been extensively studied for robust recommendations. However, traditional adversarial training adds small perturbations to the parameters (inputs), which do not comply with the poisoning mechanism in the recommender system. Thus for the practical models that are very good at learning existing data, it does not perform well. To address the above limitations, we propose adversarial poisoning training (APT). It simulates the poisoning process by injecting fake users (ERM users) who are dedicated to minimizing empirical risk to build a robust system. Besides, to generate ERM users, we explore an approximation approach to estimate each fake user's influence on the empirical risk. Although the strategy of "fighting fire with fire" seems counterintuitive, we theoretically prove that the proposed APT can boost the upper bound of poisoning robustness. Also, we deliver the first theoretical proof that adversarial training holds a positive effect on enhancing recommendation robustness. Through extensive experiments with five poisoning attacks on four real-world datasets, the results show that the robustness improvement of APT significantly outperforms baselines. It is worth mentioning that APT also improves model generalization in most cases.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 被引用 32 次
- Revisiting Injective Attacks on Recommender SystemsHaoyang Li, Shimin Di, Lei ChenNeurIPS 2022 · 被引用 26 次
- Mirror Gradient: Towards Robust Multimodal Recommender Systems via Exploring Flat Local MinimaShanshan Zhong, Zhongzhan Huang, Daifeng Li, Wushao Wen 等WWW 2024 · 被引用 24 次
- LoRec: Combating Poisons with Large Language Model for Robust Sequential RecommendationKaike Zhang, Qi Cao, Yunfan Wu, Fei Sun 等SIGIR 2024 · 被引用 13 次
- Uplift Modeling for Target User Attacks on Recommender SystemsWenjie Wang, Changsheng Wang, Fuli Feng, Wentao Shi 等WWW 2024 · 被引用 11 次
它引用的顶会 Paper10
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu 等ICML 2020 · 被引用 452 次
- Geography-Aware Sequential Location RecommendationDefu Lian, Yongji Wu, Yong Ge, Xing Xie 等KDD 2020 · 被引用 244 次
- GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster DetectionShijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Hung Nguyen 等SIGIR 2020 · 被引用 163 次
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 被引用 126 次
- Personalized Ranking with Importance SamplingDefu Lian, Qi Liu, Enhong ChenWWW 2020 · 被引用 98 次
相关 Paper
- PORE: Provably Robust Recommender Systems against Data Poisoning AttacksJinyuan Jia, Yupei Liu, Yuepeng Hu, Neil Zhenqiang GongUSENIX Security 2023
- Triple Adversarial Learning for Influence based Poisoning Attack in Recommender SystemsChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu 等KDD 2021 · 被引用 53 次
- Understanding and Improving Adversarial Collaborative Filtering for Robust RecommendationKaike Zhang, Qi Cao, Yunfan Wu, Fei Sun 等NeurIPS 2024 · 被引用 11 次
- Robust Recommendation with Adversarial Gaussian Data AugmentationZhenlei Wang, Xu ChenWWW 2023 · 被引用 9 次
- Data Poisoning Attack against Recommender System Using Incomplete and Perturbed DataHengtong Zhang, Changxin Tian, Yaliang Li, Lu Su 等KDD 2021 · 被引用 51 次
