arXiv:2509.22855cs.LGcs.AI2025-09

提出无需观察的攻击方法,能高效操纵在线排序算法。

Observation-Free Attacks on Online Learning to Rank

  • 设计新型无观测攻击框架,仅需少量操作即可操控推荐结果。
  • 理论证明两种策略只需O(log T)次攻击即可达成目标,且导致线性损失。
  • 适用于研究推荐系统安全性的研究人员,尤其关注对抗攻击者。

在线学习排序(OLTR)在信息检索和机器学习系统中扮演关键角色,广泛应用于搜索引擎和内容推荐系统。然而,尽管其广泛应用,现有对OLTR算法在协同对抗攻击下的脆弱性仍缺乏深入理解。本文提出一种新型攻击框架,针对几种常用的OLTR算法进行攻击。该框架旨在使特定目标项在前T - o(T)轮中持续出现在前K位推荐列表中,同时引发学习算法的线性遗憾。我们提出了两种新攻击策略:CascadeOFA用于CascadeUCB1,PBMOFA用于PBM-UCB。理论分析表明,两种策略均只需O(log T)次操作即可成功。此外,我们在真实数据集上进行了实验验证,补充了实证结果。

原文摘要 · Abstract (English)

Online learning to rank (OLTR) plays a critical role in information retrieval and machine learning systems, with a wide range of applications in search engines and content recommenders. However, despite their extensive adoption, the susceptibility of OLTR algorithms to coordinated adversarial attacks remains poorly understood. In this work, we present a novel framework for attacking some of the widely used OLTR algorithms. Our framework is designed to promote a set of target items so that they appear in the list of top-K recommendations for T - o(T) rounds, while simultaneously inducing linear regret in the learning algorithm. We propose two novel attack strategies: CascadeOFA for CascadeUCB1 and PBMOFA for PBM-UCB . We provide theoretical guarantees showing that both strategies require only O(log T) manipulations to succeed. Additionally, we supplement our theoretical analysis with empirical results on real-world data.

在线排序对抗攻击推荐系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。