arXiv:2508.15252cs.CRcs.CL2025-08综述被引 4

用检索增强生成假评论,让攻击推荐系统更隐蔽有效

Retrieval-Augmented Review Generation for Poisoning Recommender Systems

  • 用多模态大模型的上下文学习能力生成高质量假评论
  • 在多个真实数据集上达到当前最佳攻击效果
  • 适合研究推荐系统安全与对抗攻击的学者

近期研究表明,推荐系统极易受到数据投毒攻击,攻击者通过注入精心设计的虚假用户资料(包括伪造评分)来操纵推荐结果。由于实际中存在安全与隐私限制,攻击者对目标系统了解有限,需生成具备跨黑盒系统迁移能力的假资料,且保持隐蔽性。然而,在资源受限条件下生成高质量、高隐蔽性的假资料极具挑战。现有方法尝试引入虚假文本评论以增强资料,但评论质量差导致攻击效果和隐蔽性下降。为此,本文提出利用多模态基础模型的上下文学习(ICL)能力提升评论质量,引入演示检索算法与文本风格迁移策略增强原始ICL。我们构建了名为RAGAN的新型实用攻击框架,通过越狱生成器与指令代理、守护代理协同优化,提升攻击的迁移性与隐蔽性。在多个真实世界数据集上的全面实验表明,RAGAN实现了当前最优的投毒攻击性能。

原文摘要 · Abstract (English)

Recent studies have shown that recommender systems (RSs) are highly vulnerable to data poisoning attacks, where malicious actors inject fake user profiles, including a group of well-designed fake ratings, to manipulate recommendations. Due to security and privacy constraints in practice, attackers typically possess limited knowledge of the victim system and thus need to craft profiles that have transferability across black-box RSs. To maximize the attack impact, the profiles often remains imperceptible. However, generating such high-quality profiles with the restricted resources is challenging. Some works suggest incorporating fake textual reviews to strengthen the profiles; yet, the poor quality of the reviews largely undermines the attack effectiveness and imperceptibility under the practical setting. To tackle the above challenges, in this paper, we propose to enhance the quality of the review text by harnessing in-context learning (ICL) capabilities of multimodal foundation models. To this end, we introduce a demonstration retrieval algorithm and a text style transfer strategy to augment the navie ICL. Specifically, we propose a novel practical attack framework named RAGAN to generate high-quality fake user profiles, which can gain insights into the robustness of RSs. The profiles are generated by a jailbreaker and collaboratively optimized on an instructional agent and a guardian to improve the attack transferability and imperceptibility. Comprehensive experiments on various real-world datasets demonstrate that RAGAN achieves the state-of-the-art poisoning attack performance.

推荐系统投毒攻击文本生成安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。