用扩散模型生成难检测的虚假用户,精准操控推荐结果。
Controllable and Stealthy Shilling Attacks via Dispersive Latent Diffusion
- 在对齐嵌入空间中用条件扩散模型生成可控假用户。
- 相比已有攻击,目标物品推广效果更强且更难被发现。
- 适合研究推荐系统安全或防御机制的人阅读。
推荐系统依赖用户贡献数据,易受洗白攻击影响,即通过注入虚假用户操纵项目排名。现有攻击模型难以同时实现强推广效果与真实行为以规避检测,导致威胁被低估。本文提出DLDA,一种基于扩散的攻击框架,在预对齐的协同嵌入空间中,利用条件潜在扩散过程迭代生成具有精确目标项目控制的虚假用户画像。为逃避检测,引入分散正则化机制,提升生成行为模式的多样性与真实性。在三个真实数据集和五种主流推荐模型上的实验表明,相比以往攻击,DLDA在持续更强的目标项目推广的同时更难被识别。结果表明,现代推荐系统比以往认为的更为脆弱,亟需更鲁棒的防御策略。
原文摘要 · Abstract (English)
Recommender systems (RSs) are now fundamental to various online platforms, but their dependence on user-contributed data leaves them vulnerable to shilling attacks that can manipulate item rankings by injecting fake users. Although widely studied, most existing attack models fail to meet two critical objectives simultaneously: achieving strong adversarial promotion of target items while maintaining realistic behavior to evade detection. As a result, the true severity of shilling threats that manage to reconcile the two objectives remains underappreciated. To expose this overlooked vulnerability, we present DLDA, a diffusion-based attack framework that can generate highly effective yet indistinguishable fake users by enabling fine-grained control over target promotion. Specifically, DLDA operates in a pre-aligned collaborative embedding space, where it employs a conditional latent diffusion process to iteratively synthesize fake user profiles with precise target item control. To evade detection, DLDA introduces a dispersive regularization mechanism that promotes variability and realism in generated behavioral patterns. Extensive experiments on three real-world datasets and five popular RS models demonstrate that, compared to prior attacks, DLDA consistently achieves stronger item promotion while remaining harder to detect. These results highlight that modern RSs are more vulnerable than previously recognized, underscoring the urgent need for more robust defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。