arXiv:2507.07436cs.IR2025-07被引 6

图对比学习会暴露推荐系统漏洞,导致被恶意推广攻击更易得手。

When Graph Contrastive Learning Backfires: Spectral Vulnerability and Defense in Recommendation

  • 发现图对比学习的谱平滑效应会扩大目标商品暴露风险。
  • 提出攻击方法CLeR,验证GCL模型对定向推广攻击更敏感。
  • 设计SIM框架抑制异常曝光,提升防御能力且不损害性能。

图对比学习(GCL)在增强推荐系统鲁棒性和泛化能力方面展现出巨大潜力,尤其能利用大规模未标记数据提升表征学习效果。然而,本文揭示了一个意外缺陷:集成GCL反而增加了推荐系统对定向推广攻击的脆弱性。通过理论分析与实证验证,我们发现根源在于对比优化引发的谱平滑效应,该效应使物品嵌入在表示空间中分散,无意间放大了目标项的暴露程度。基于此,我们提出双层优化攻击方法CLeaR,主动增强谱平滑性,系统性评估GCL推荐模型的脆弱性。为此,我们进一步提出SIM框架——一种谱不规则性抑制机制,可在不牺牲模型性能的前提下精准检测并压制目标项。在多个基准数据集上的大量实验表明,相较于现有攻击方法,采用GCL的推荐模型在CLeaR评估下表现出更高敏感性;而SIM能有效缓解此类漏洞。

原文摘要 · Abstract (English)

Graph Contrastive Learning (GCL) has demonstrated substantial promise in enhancing the robustness and generalization of recommender systems, particularly by enabling models to leverage large-scale unlabeled data for improved representation learning. However, in this paper, we reveal an unexpected vulnerability: the integration of GCL inadvertently increases the susceptibility of a recommender to targeted promotion attacks. Through both theoretical investigation and empirical validation, we identify the root cause as the spectral smoothing effect induced by contrastive optimization, which disperses item embeddings across the representation space and unintentionally enhances the exposure of target items. Building on this insight, we introduce CLeaR, a bi-level optimization attack method that deliberately amplifies spectral smoothness, enabling a systematic investigation of the susceptibility of GCL-based recommendation models to targeted promotion attacks. Our findings highlight the urgent need for robust countermeasures; in response, we further propose SIM, a spectral irregularity mitigation framework designed to accurately detect and suppress targeted items without compromising model performance. Extensive experiments on multiple benchmark datasets demonstrate that, compared to existing targeted promotion attacks, GCL-based recommendation models exhibit greater susceptibility when evaluated with CLeaR, while SIM effectively mitigates these vulnerabilities.

推荐系统图学习安全防御对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。