PORE: Provably Robust Recommender Systems against Data Poisoning Attacks

PORE: Provably Robust Recommender Systems against Data Poisoning Attacks
复制标题

DOI:
10.48550/arxiv.2303.14601
复制
发表时间:
2023-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Jinyuan Jia;Yupei Liu;Yuepeng Hu;N. Gong
Jinyuan Jia;Yupei Liu;Yuepeng Hu;N. Gong
中科院分区:
其他
文献类型:
--
作者:
Jinyuan Jia;Yupei Liu;Yuepeng Hu;N. Gong

文献摘要

相似文献

数据中毒攻击欺骗推荐系统,通过向推荐系统中注入具有精心制作的评级分数的虚假用户来做出任意的攻击者期望的推荐。我们设想一个猫捉老鼠的游戏,这种数据中毒攻击和他们的防御,即,新的防御被设计来防御现有的攻击,而新的攻击被设计来打破它们。为了防止这样的猫捉老鼠的游戏,我们提出了PORE,第一个框架,以建立可证明的强大的推荐系统在这项工作中。PORE可以改变任何现有的推荐系统,以证明对任何非目标的数据中毒攻击,其目的是降低推荐系统的整体性能是强大的。假设PORE在没有攻击的情况下向用户推荐前$N$个项目。我们证明了在任何数据中毒攻击下,PORE仍然向用户推荐$N$个项目中的至少$r$个,其中$r$是攻击中虚假用户数量的函数。此外,我们设计了一个有效的算法来计算每个用户的$r$。我们在流行的基准数据集上对PORE进行了经验评估。
Data poisoning attacks spoof a recommender system to make arbitrary, attacker-desired recommendations via injecting fake users with carefully crafted rating scores into the recommender system. We envision a cat-and-mouse game for such data poisoning attacks and their defenses, i.e., new defenses are designed to defend against existing attacks and new attacks are designed to break them. To prevent such a cat-and-mouse game, we propose PORE, the first framework to build provably robust recommender systems in this work. PORE can transform any existing recommender system to be provably robust against any untargeted data poisoning attacks, which aim to reduce the overall performance of a recommender system. Suppose PORE recommends top-$N$ items to a user when there is no attack. We prove that PORE still recommends at least $r$ of the $N$ items to the user under any data poisoning attack, where $r$ is a function of the number of fake users in the attack. Moreover, we design an efficient algorithm to compute $r$ for each user. We empirically evaluate PORE on popular benchmark datasets.