LLM代理可暗中攻击无ID推荐系统,诱导推送低质内容
ID-Free Not Risk-Free: LLM-Powered Agents Unveil Risks in ID-Free Recommender Systems
- 用LLM模拟热门商品特征,生成欺骗性描述
- 通过多代理协作迭代优化推广文本,隐蔽攻击黑箱系统
- 提出检测方法识别恶意文本,适合安全与推荐研究者
近期无ID推荐系统在缓解冷启动问题上取得进展,但其对恶意攻击的脆弱性尚未被充分研究。本文揭示了一项关键却被忽视的风险:基于大语言模型(LLM)的智能体可在黑盒环境下,策略性地攻击无ID推荐系统,隐蔽地推动低质量商品。该攻击采用一种新颖的重写式欺骗策略,即通过模拟热门商品特征,合成具有误导性的文本描述。攻击机制包含两个核心组件:(1) 流行度提取模块,用于捕捉热门商品的关键特征;(2) 多智能体协作机制,通过独立思考与团队讨论实现推广文本的迭代优化。为应对这一风险,我们进一步提出一种检测方法,可识别由上述攻击生成的可疑文本。本工作旨在强调提升无ID推荐系统安全性的紧迫性。
原文摘要 · Abstract (English)
Recent advances in ID-free recommender systems have attracted significant attention for effectively addressing the cold start problem. However, their vulnerability to malicious attacks remains largely unexplored. In this paper, we unveil a critical yet overlooked risk: LLM-powered agents can be strategically deployed to attack ID-free recommenders, stealthily promoting low-quality items in black-box settings. This attack exploits a novel rewriting-based deception strategy, where malicious agents synthesize deceptive textual descriptions by simulating the characteristics of popular items. To achieve this, the attack mechanism integrates two primary components: (1) a popularity extraction component that captures essential characteristics of popular items and (2) a multi-agent collaboration mechanism that enables iterative refinement of promotional textual descriptions through independent thinking and team discussion. To counter this risk, we further introduce a detection method to identify suspicious text generated by our discovered attack. By unveiling this risk, our work aims to underscore the urgent need to enhance the security of ID-free recommender systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。