Triple Adversarial Learning for Influence based Poisoning Attack in Recommender Systems
Chenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu, Enhong Chen
摘要
As an important means to solve information overload, recommender systems have been widely applied in many fields, such as e-commerce and advertising. However, recent studies have shown that recommender systems are vulnerable to poisoning attacks; that is, injecting a group of carefully designed user profiles into the recommender system can severely affect recommendation quality. Despite the development from shilling attacks to optimization-based attacks, the imperceptibility and harmfulness of the generated data in most attacks are arduous to balance. To this end, we propose a triple adversarial learning for influence based poisoning attack (TrialAttack), a flexible end-to-end poisoning framework to generate non-notable and harmful user profiles. Specifically, given the input noise, TrialAttack directly generates malicious users through triple adversarial learning of the generator, discriminator, and influence module. Besides, to provide reliable influence for TrialAttack training, we explore a new approximation approach for estimating each fake user's influence. Through theoretical analysis, we prove that the distribution characterized by TrialAttack approximates to the rating distribution of real users under the premise of performing an efficient attack. This property allows the injected users to attack in an unremarkable way. Experiments on three real-world datasets show that TrialAttack's attack performance outperforms state-of-the-art attacks, and the generated fake profiles are more difficult to detect compared to baselines.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper12
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu 等AAAI 2023 · 被引用 73 次
- Knowledge-enhanced Black-box Attacks for RecommendationsJingfan Chen, Wenqi Fan, Guanghui Zhu, Xiangyu Zhao 等KDD 2022 · 被引用 44 次
- Revisiting Injective Attacks on Recommender SystemsHaoyang Li, Shimin Di, Lei ChenNeurIPS 2022 · 被引用 26 次
- Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning AttacksZongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin 等KDD 2024 · 被引用 16 次
- Shilling Black-box Review-based Recommender Systems through Fake Review GenerationHung-Yun Chiang, Yi-Syuan Chen, Yun-Zhu Song, Hong-Han Shuai 等KDD 2023 · 被引用 15 次
相关 Paper
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning TrainingChenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu 等SIGIR 2021 · 被引用 47 次
- Data Poisoning Attack against Recommender System Using Incomplete and Perturbed DataHengtong Zhang, Changxin Tian, Yaliang Li, Lu Su 等KDD 2021 · 被引用 51 次
- Attacking Black-box Recommendations via Copying Cross-domain User ProfilesWenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma 等ICDE 2021 · 被引用 75 次
- Practical Cross-System Shilling Attacks with Limited Access to DataMeifang Zeng, Ke Li, Bingchuan Jiang, Liujuan Cao 等AAAI 2023 · 被引用 12 次
- Reverse Attack: Black-box Attacks on Collaborative RecommendationYihe Zhang, Xu Yuan, Jin Li, Jiadong Lou 等CCS 2021 · 被引用 24 次
