arXiv:2412.10850cs.LGstat.ML2024-12被引 1

通过重加权用户相似边,提升协同过滤对抗攻击的鲁棒性。

Defending Collaborative Filtering Recommenders via Adversarial Robustness Based Edge Reweighting

  • 基于谱鲁棒性评估为用户边分配脆弱度评分
  • 通过重加权削弱易受攻击边的影响,提升推荐准确性
  • 对各类注入攻击有显著防御效果,适合安全推荐系统

基于用户的协同过滤(CF)依赖用户-用户相似性图,易受画像注入(洗票)攻击,攻击者通过操纵邻域关系来推高或打压目标物品。本文提出一种基于对抗鲁棒性的边重加权防御方法:首先通过谱对抗鲁棒性评估为每个用户及用户边分配非鲁棒性分数,量化边对对抗扰动的敏感程度;随后在预测阶段重加权相似度,抑制非鲁棒边的影响。大量实验表明,该方法能有效防御多种攻击类型。

原文摘要 · Abstract (English)

User based collaborative filtering (CF) relies on a user and user similarity graph, making it vulnerable to profile injection (shilling) attacks that manipulate neighborhood relations to promote (push) or demote (nuke) target items. In this work, we propose an adversarial robustness based edge reweighting defense for CF. We first assign each user and user edge a non robustness score via spectral adversarial robustness evaluation, which quantifies the edge sensitivity to adversarial perturbations. We then attenuate the influence of non robust edges by reweighting similarities during prediction. Extensive experiments demonstrate that the proposed method effectively defends against various types of attacks.

协同过滤对抗鲁棒性推荐系统安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。