提升推荐系统攻击隐蔽性,同时保持用户偏好真实性和推荐多样性。
Diversity-aware Dual-promotion Poisoning Attack on Sequential Recommendation
- 设计双目标攻击策略,兼顾目标项推广与用户偏好保留。
- 生成序列中目标项重复率降低,推荐列表多样性显著提升。
- 适合研究推荐系统安全、对抗攻击的学者与工程师参考。
序列推荐系统(SRS)在捕捉用户动态兴趣方面表现优异,广泛应用于工业场景。其安全性研究日益受到关注,其中针对特定项目推广的数据投毒攻击是典型问题。现有方法通过注入精心构造的交互行为(即投毒序列)来提升目标项排名,但会显著降低推荐准确性,影响攻击隐蔽性。此外,生成的投毒序列存在大量目标项重复,源于单一提升曝光的目标和缺乏有效的多样性约束。这种同质性不仅削弱序列真实性,还限制了攻击效果,因忽略了目标项与其他项目间的序列依赖关系。为此,本文提出一种多样性感知的双促进投毒攻击方法DDSP。通过揭示推荐目标与现有攻击目标之间的冲突,设计新攻击目标,在促进目标项的同时保持用户偏好项的相关性。进一步开发了具备多样性约束的自回归投毒序列生成器,采用重排序机制逐项选择最优候选,实现更真实的序列生成。
原文摘要 · Abstract (English)
Sequential recommender systems (SRSs) excel in capturing users' dynamic interests, thus playing a key role in various industrial applications. The popularity of SRSs has also driven emerging research on their security aspects, where data poisoning attack for targeted item promotion is a typical example. Existing attack mechanisms primarily focus on increasing the ranks of target items in the recommendation list by injecting carefully crafted interactions (i.e., poisoning sequences), which comes at the cost of demoting users' real preferences. Consequently, noticeable recommendation accuracy drops are observed, restricting the stealthiness of the attack. Additionally, the generated poisoning sequences are prone to substantial repetition of target items, which is a result of the unitary objective of boosting their overall exposure and lack of effective diversity regularizations. Such homogeneity not only compromises the authenticity of these sequences, but also limits the attack effectiveness, as it ignores the opportunity to establish sequential dependencies between the target and many more items in the SRS. To address the issues outlined, we propose a Diversity-aware Dual-promotion Sequential Poisoning attack method named DDSP for SRSs. Specifically, by theoretically revealing the conflict between recommendation and existing attack objectives, we design a revamped attack objective that promotes the target item while maintaining the relevance of preferred items in a user's ranking list. We further develop a diversity-aware, auto-regressive poisoning sequence generator, where a re-ranking method is in place to sequentially pick the optimal items by integrating diversity constraints.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。