Adversarial Attacks for Black-Box Recommender Systems via Copying Transferable Cross-Domain User Profiles

Adversarial Attacks for Black-Box Recommender Systems via Copying Transferable Cross-Domain User Profiles
复制标题

DOI:
10.1109/tkde.2023.3272652
复制
发表时间:
2023-12
影响因子:
8.9
通讯作者:
Wenqi Fan;Xiangyu Zhao;Qing Li;Tyler Derr;Yao Ma;Hui Liu;Jianping Wang;Jiliang Tang
Wenqi Fan;Xiangyu Zhao;Qing Li;Tyler Derr;Yao Ma;Hui Liu;Jianping Wang;Jiliang Tang
中科院分区:
计算机科学2区
文献类型:
--
作者:
Wenqi Fan;Xiangyu Zhao;Qing Li;Tyler Derr;Yao Ma;Hui Liu;Jianping Wang;Jiliang Tang

文献摘要

相似文献

推荐系统被广泛应用于数据驱动的决策中,在许多面向用户的在线服务中,如电子商务(如亚马逊、淘宝等)和社交媒体网站(如Facebook、Twitter),其为用户提供个性化服务的能力得到了认可。最近的研究表明,基于深度神经网络的推荐系统非常容易受到对抗性攻击,攻击者可以将精心制作的虚假用户配置文件(即,虚假用户与之交互的一组物品)注入目标推荐系统,以提升或降低一组目标物品。在本文中,我们介绍了一种新的策略,通过复制跨域用户配置文件来获取“假”用户配置文件,其中开发了基于强化学习的黑箱攻击框架(CopyAttack+),以有效地从源域选择跨域用户配置文件来攻击目标系统。此外,我们提出在源域训练一个模拟对抗性黑盒攻击的局部代理系统,以提供可转移的信号,增强目标黑盒推荐系统的攻击策略。在三个真实数据集上进行了全面的实验,以证明所提出的攻击框架的有效性。
As widely used in data-driven decision-making, recommender systems have been recognized for their capabilities to provide users with personalized services in many user-oriented online services, such as E-commerce (e.g., Amazon, Taobao, etc.) and Social Media sites (e.g., Facebook and Twitter). Recent works have shown that deep neural networks-based recommender systems are highly vulnerable to adversarial attacks, where adversaries can inject carefully crafted fake user profiles (i.e., a set of items that fake users have interacted with) into a target recommender system to promote or demote a set of target items. Instead of generating users with fake profiles from scratch, in this article, we introduce a novel strategy to obtain “fake” user profiles via copying cross-domain user profiles, where a reinforcement learning based black-box attacking framework (CopyAttack+) is developed to effectively and efficiently select cross-domain user profiles from the source domain to attack the target system. Moreover, we propose to train a local surrogate system for mimicking adversarial black-box attacks in the source domain, so as to provide transferable signals with the purpose of enhancing the attacking strategy in the target black-box recommender system. Comprehensive experiments on three real-world datasets are conducted to demonstrate the effectiveness of the proposed attacking framework.