Fake Resume Attacks: Data Poisoning on Online Job Platforms
Michiharu Yamashita, Thanh Tran, Dongwon Lee
摘要
While recent studies have exposed various vulnerabilities incurred from data poisoning attacks in many web services, little is known about the vulnerability on online professional job platforms (e.g., LinkedIn and Indeed). In this work, first time, we demonstrate the critical vulnerabilities found in the common Human Resources (HR) task of matching job seekers and companies on online job platforms. Capitalizing on the unrestricted format and contents of job seekers' resumes and easy creation of accounts on job platforms, we demonstrate three attack scenarios: (1) company promotion attack to increase the likelihood of target companies being recommended, (2) company demotion attack to decrease the likelihood of target companies being recommended, and (3) user promotion attack to increase the likelihood of certain users being matched to certain companies. To this end, we develop an end-to-end "fake resume" generation framework, titled FRANCIS, that induces systematic prediction errors via data poisoning. Our empirical evaluation on real-world datasets reveals that data poisoning attacks can markedly skew the results of matchmaking between job seekers and companies, regardless of underlying models, with vulnerability amplified in proportion to poisoning intensity. These findings suggest that the outputs of various services from job platforms can be potentially hacked by malicious users. Our framework is available at: https://tinyurl.com/fr-attacks . CCS CONCEPTS • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- CAPER: Enhancing Career Trajectory Prediction using Temporal Knowledge Graph and Ternary RelationshipYeon-Chang Lee, Jaehyun Lee, Michiharu Yamashita, Dongwon Lee 等KDD 2025 · 被引用 3 次
- Unmasking Fake Careers: Detecting Machine-Generated Career Trajectories via Multi-layer Heterogeneous GraphsMichiharu Yamashita, Thanh Tran, Delvin Ce Zhang, Dongwon LeeEMNLP 2025 · 被引用 1 次
它引用的顶会 Paper8
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning AttacksAvi Schwarzschild, Micah Goldblum, Arjun Gupta, John P. Dickerson 等ICML 2021 · 被引用 207 次
- Examining the Use of Online Platforms for Employment: A Survey of U.S. Job SeekersTawanna R. Dillahunt, Aarti Israni, Alex Jiahong Lu, Mingzhi Cai 等CHI 2021 · 被引用 47 次
- Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its CountermeasuresWei Yuan, Quoc Viet Hung Nguyen, Tieke He, Liang Chen 等SIGIR 2023 · 被引用 46 次
- Large-Scale Talent Flow Embedding for Company Competitive AnalysisLe Zhang, Tong Xu, Hengshu Zhu, Chuan Qin 等WWW 2020 · 被引用 45 次
- Attentive Heterogeneous Graph Embedding for Job Mobility PredictionLe Zhang, Ding Zhou, Hengshu Zhu, Tong Xu 等KDD 2021 · 被引用 39 次
相关 Paper
- Measuring Real-World Prompt Injection Attacks in LLM-based Resume ScreeningMohan Zhang, Yuqi Jia, Zhen Tan, Steven Jiang 等USENIX Security 2026 · 被引用 4 次
- Fake Co-visitation Injection Attacks to Recommender SystemsGuolei Yang, Neil Zhenqiang Gong, Ying CaiNDSS 2017 · 被引用 126 次
- PORE: Provably Robust Recommender Systems against Data Poisoning AttacksJinyuan Jia, Yupei Liu, Yuepeng Hu, Neil Zhenqiang GongUSENIX Security 2023
- Reverse Attack: Black-box Attacks on Collaborative RecommendationYihe Zhang, Xu Yuan, Jin Li, Jiadong Lou 等CCS 2021 · 被引用 24 次
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu 等ICDE 2020 · 被引用 83 次
