arXiv:2505.13528cs.IRcs.AI2025-05被引 4

用大模型模拟假用户,低成本高隐蔽地攻击推荐系统。

LLM-Based User Simulation for Low-Knowledge Shilling Attacks on Recommender Systems

  • 用大模型生成逼真评分和评论,模拟真实用户行为。
  • 在多个数据集上比现有方法更有效且更难被发现。
  • 适合研究推荐系统安全或大模型滥用的学者参考。

推荐系统正面临洗白攻击的威胁,攻击者通过注入虚假用户档案操纵系统输出。传统攻击依赖简单规则,需访问系统内部数据,且忽略文本评论的操纵潜力。本文提出Agent4SR框架,利用大语言模型(LLM)驱动的智能体,仅凭有限知识即可通过评分与评论生成实施高影响力攻击。Agent4SR通过协调对抗性交互、选择商品、分配评分并撰写评论,保持行为合理性。其设计包含目标型账号构建、混合记忆检索及评论攻击策略——将目标商品特征传播至无关评论中以放大操纵效果。在多个数据集与推荐架构上的实验表明,Agent4SR在有效性和隐蔽性上均优于现有低知识基线。研究揭示了由大模型驱动智能体引发的新威胁类型,凸显现代推荐系统亟需加强防御。

原文摘要 · Abstract (English)

Recommender systems (RS) are increasingly vulnerable to shilling attacks, where adversaries inject fake user profiles to manipulate system outputs. Traditional attack strategies often rely on simplistic heuristics, require access to internal RS data, and overlook the manipulation potential of textual reviews. In this work, we introduce Agent4SR, a novel framework that leverages Large Language Model (LLM)-based agents to perform low-knowledge, high-impact shilling attacks through both rating and review generation. Agent4SR simulates realistic user behavior by orchestrating adversarial interactions, selecting items, assigning ratings, and crafting reviews, while maintaining behavioral plausibility. Our design includes targeted profile construction, hybrid memory retrieval, and a review attack strategy that propagates target item features across unrelated reviews to amplify manipulation. Extensive experiments on multiple datasets and RS architectures demonstrate that Agent4SR outperforms existing low-knowledge baselines in both effectiveness and stealth. Our findings reveal a new class of emergent threats posed by LLM-driven agents, underscoring the urgent need for enhanced defenses in modern recommender systems.

推荐系统大模型攻击洗白攻击智能体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。