Practical Data Poisoning Attack against Next-Item Recommendation

Practical Data Poisoning Attack against Next-Item Recommendation
复制标题

DOI:
10.1145/3366423.3379992
复制
发表时间:
2020-04
期刊:
Proceedings of The Web Conference 2020
影响因子:
--
通讯作者:
Hengtong Zhang;Yaliang Li;Bolin Ding;Jing Gao
Hengtong Zhang;Yaliang Li;Bolin Ding;Jing Gao
中科院分区:
其他
文献类型:
--
作者:
Hengtong Zhang;Yaliang Li;Bolin Ding;Jing Gao

文献摘要

相似文献

在线推荐系统利用各种信息源向用户提供用户可能感兴趣的项目。然而,由于在线平台的开放性,推荐系统容易受到数据中毒攻击。现有的攻击方法要么基于简单的启发式规则,要么针对特定的建议方法而设计。前者的性能往往不令人满意,而后者则需要对目标系统有很强的了解。在本文中,我们专注于一个一般的下一个项目的建议设置,并提出了一个实用的中毒攻击方法命名为LOKI黑盒推荐系统。该算法利用强化学习算法训练攻击代理,生成用户行为样本,用于数据中毒。在现实推荐系统中,推荐模型的再训练成本很高,并且用户与推荐系统之间的交互频率受到限制。考虑到这些现实世界的限制,我们建议让代理与推荐模拟器而不是目标推荐系统进行交互,并利用生成的对抗样本的可转移性来毒害目标系统。我们还建议使用影响函数来有效地估计注入样本对推荐结果的影响,而无需在模拟器内重新训练模型。在两个数据集上对四种典型推荐模型进行了大量实验,实验结果表明,该方法比现有方法具有更好的攻击性能。
Online recommendation systems make use of a variety of information sources to provide users the items that users are potentially interested in. However, due to the openness of the online platform, recommendation systems are vulnerable to data poisoning attacks. Existing attack approaches are either based on simple heuristic rules or designed against specific recommendations approaches. The former often suffers unsatisfactory performance, while the latter requires strong knowledge of the target system. In this paper, we focus on a general next-item recommendation setting and propose a practical poisoning attack approach named LOKI against blackbox recommendation systems. The proposed LOKI utilizes the reinforcement learning algorithm to train the attack agent, which can be used to generate user behavior samples for data poisoning. In real-world recommendation systems, the cost of retraining recommendation models is high, and the interaction frequency between users and a recommendation system is restricted. Given these real-world restrictions, we propose to let the agent interact with a recommender simulator instead of the target recommendation system and leverage the transferability of the generated adversarial samples to poison the target system. We also propose to use the influence function to efficiently estimate the influence of injected samples on the recommendation results, without re-training the models within the simulator. Extensive experiments on two datasets against four representative recommendation models show that the proposed LOKI achieves better attacking performance than existing methods.