arXiv:2506.08401cs.AI2025-06IJCAI被引 4

仅用一个假用户节点,隐蔽提升目标商品曝光率

Single-Node Trigger Backdoor Attacks in Graph-Based Recommendation Systems

  • 仅插入一个伪造用户节点作为触发器
  • 99%目标用户看到目标商品曝光率超50%
  • 对系统整体性能影响小于5%,适合隐蔽攻击研究

图推荐系统因其能有效捕捉用户与物品间的复杂交互而广受关注。然而,面对攻击时也存在脆弱性。现有洗钱攻击通常通过注入大量虚假节点和边来操纵推荐结果,但面临隐蔽性差、破坏性强的问题。为此,本文提出一种新型图后门攻击方法,旨在以隐蔽方式提升目标物品对目标用户的曝光度,且不影响其他无关节点。我们设计了一个单节点触发器生成器,仅通过插入一个伪造用户节点,即可有效使多个目标物品暴露给目标用户。同时,引入目标节点与无关节点间的约束条件,降低虚假节点对推荐系统性能的影响。实验结果显示,在99%的目标用户中,目标物品曝光率不低于50%,而对系统性能的影响控制在约5%以内。

原文摘要 · Abstract (English)

Graph recommendation systems have been widely studied due to their ability to effectively capture the complex interactions between users and items. However, these systems also exhibit certain vulnerabilities when faced with attacks. The prevailing shilling attack methods typically manipulate recommendation results by injecting a large number of fake nodes and edges. However, such attack strategies face two primary challenges: low stealth and high destructiveness. To address these challenges, this paper proposes a novel graph backdoor attack method that aims to enhance the exposure of target items to the target user in a covert manner, without affecting other unrelated nodes. Specifically, we design a single-node trigger generator, which can effectively expose multiple target items to the target user by inserting only one fake user node. Additionally, we introduce constraint conditions between the target nodes and irrelevant nodes to mitigate the impact of fake nodes on the recommendation system's performance. Experimental results show that the exposure of the target items reaches no less than 50% in 99% of the target users, while the impact on the recommendation system's performance is controlled within approximately 5%.

图神经网络推荐系统后门攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。