用少量文本修改就能悄悄操控推荐系统排序,隐蔽性强。
Stealthy LLM-Driven Data Poisoning Attacks Against Embedding-Based Retrieval-Augmented Recommender Systems
- 通过微调商品描述中的少量词,实现精准操控。
- 在MovieLens上实验显示,小改动即能显著改变推荐排名。
- 适合关注推荐系统安全与内容可信度的研究者。
我们系统研究了基于检索增强的推荐系统(RAG-based)中的服务商端数据投毒攻击。仅修改商品描述中少量标记符——例如添加情感关键词或借用语义相关项的短语——攻击者即可显著提升或压制目标项目。我们在令牌编辑和语义相似性约束下形式化此类攻击,并在推广(长尾项目)和抑制(头部项目)场景中评估其有效性。在MovieLens数据集上的实验表明,使用两个大型语言模型(LLM)检索模块时,即使细微的攻击也能改变最终排名与项目曝光,且能规避简单检测。结果凸显了RAG管道对小规模元数据重写的高度脆弱性,强调需加强文本一致性验证与来源追踪以抵御隐蔽的提供商侧投毒。
原文摘要 · Abstract (English)
We present a systematic study of provider-side data poisoning in retrieval-augmented recommender systems (RAG-based). By modifying only a small fraction of tokens within item descriptions -- for instance, adding emotional keywords or borrowing phrases from semantically related items -- an attacker can significantly promote or demote targeted items. We formalize these attacks under token-edit and semantic-similarity constraints, and we examine their effectiveness in both promotion (long-tail items) and demotion (short-head items) scenarios. Our experiments on MovieLens, using two large language model (LLM) retrieval modules, show that even subtle attacks shift final rankings and item exposures while eluding naive detection. The results underscore the vulnerability of RAG-based pipelines to small-scale metadata rewrites and emphasize the need for robust textual consistency checks and provenance tracking to thwart stealthy provider-side poisoning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。