Knowledge-enhanced Black-box Attacks for Recommendations
Jingfan Chen, Wenqi Fan, Guanghui Zhu, Xiangyu Zhao, Chunfeng Yuan, Qing Li, Yihua Huang
摘要
Recent studies have shown that deep neural networks-based recommender systems are vulnerable to adversarial attacks, where attackers can inject carefully crafted fake user profiles (i.e., a set of items that fake users have interacted with) into a target recommender system to achieve malicious purposes, such as promote or demote a set of target items. Due to the security and privacy concerns, it is more practical to perform adversarial attacks under the black-box setting, where the architecture/parameters and training data of target systems cannot be easily accessed by attackers. However, generating high-quality fake user profiles under black-box setting is rather challenging with limited resources to target systems. To address this challenge, in this work, we introduce a novel strategy by leveraging items' attribute information (i.e., items' knowledge graph), which can be publicly accessible and provide rich auxiliary knowledge to enhance the generation of fake user profiles. More specifically, we propose a knowledge graph-enhanced black-box attacking framework (KGAttack) to effectively learn attacking policies through deep reinforcement learning techniques, in which knowledge graph is seamlessly integrated into hierarchical policy networks to generate fake user profiles for performing adversarial black-box attacks. Comprehensive experiments on various real-world datasets demonstrate the effectiveness of the proposed attacking framework under the black-box setting.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- IMF: Interactive Multimodal Fusion Model for Link PredictionXinhang Li, Xiangyu Zhao, Jiaxing Xu, Yong Zhang 等WWW 2023 · 被引用 113 次
- Fairly Adaptive Negative Sampling for RecommendationsXiao Chen, Wenqi Fan, Jingfan Chen, Haochen Liu 等WWW 2023 · 被引用 64 次
- Sequential Recommendation for Optimizing Both Immediate Feedback and Long-term RetentionZiru Liu, Shuchang Liu, Zijian Zhang, Qingpeng Cai 等SIGIR 2024 · 被引用 23 次
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin 等KDD 2024 · 被引用 16 次
- Shilling Black-box Review-based Recommender Systems through Fake Review GenerationHung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai 等KDD 2023 · 被引用 15 次
它引用的顶会 Paper5
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu 等ICDE 2020 · 被引用 83 次
- Attacking Black-box Recommendations via Copying Cross-domain User ProfilesWenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma 等ICDE 2021 · 被引用 75 次
- Triple Adversarial Learning for Influence based Poisoning Attack in Recommender SystemsChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu 等KDD 2021 · 被引用 53 次
- Jointly Attacking Graph Neural Network and its ExplanationsWenqi Fan, Han Xu, Wei Jin, Xiaorui Liu 等ICDE 2023 · 被引用 23 次
- Data Poisoning Attacks to Deep Learning Based Recommender SystemsHai Huang, Jiaming Mu, Neil Zhenqiang Gong, Qi Li 等NDSS 2021
相关 Paper
- Practical Cross-System Shilling Attacks with Limited Access to DataMeifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao 等AAAI 2023 · 被引用 12 次
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 被引用 32 次
- Let Graph Be the Go Board: Gradient-Free Node Injection Attack for Graph Neural Networks via Reinforcement LearningMingxuan Ju, Yujie Fan, Chuxu Zhang, Yanfang YeAAAI 2023 · 被引用 48 次
- Graph Adversarial Attack via RewiringYao Ma, Suhang Wang, Tyler Derr, Lingfei Wu 等KDD 2021 · 被引用 62 次
- Alleviating Spurious Correlations in Knowledge-aware Recommendations through Counterfactual GeneratorShanlei Mu, Yaliang Li, Wayne Xin Zhao, Jingyuan Wang 等SIGIR 2022 · 被引用 23 次
