arXiv:2511.09392cs.LGcs.AI2025-11AAAI

通过分层强化学习,实现隐蔽的序列推荐污染攻击

Potent but Stealthy: Rethink Profile Pollution against Sequential Recommendation via Bi-level Constrained Reinforcement Paradigm

  • 采用双层优化与多奖励机制,精准操控用户行为模式
  • 在不触发明显分布变化的前提下,成功诱导目标推荐结果
  • 适合研究推荐系统安全性的研究人员使用

序列推荐系统通过用户交互序列捕捉动态意图,易受对抗攻击。现有攻击多依赖大规模数据投毒或伪造账号,实用性差。本文聚焦于隐蔽的用户画像污染攻击(Profile Pollution Attack),即通过篡改部分用户交互记录,诱导目标误推荐。以往方法存在两个局限:一是过度依赖序列长度影响,难以精细扰动物品转移;二是整体修改导致可检测的分布偏移。为此,我们提出受约束的强化驱动攻击CREAT,融合双层优化框架与多奖励强化学习,在攻击效果与隐蔽性间取得平衡。首先设计模式均衡奖励策略,结合模式反转奖励以破坏关键模式,并通过不平衡最优传输最小化可检测分布偏移。其次采用受约束的组相对强化学习,通过动态屏障约束和共享经验回放实现逐步扰动,以最小可检测性完成定向污染。大量实验验证了CREAT的有效性。

原文摘要 · Abstract (English)

Sequential Recommenders, which exploit dynamic user intents through interaction sequences, is vulnerable to adversarial attacks. While existing attacks primarily rely on data poisoning, they require large-scale user access or fake profiles thus lacking practicality. In this paper, we focus on the Profile Pollution Attack that subtly contaminates partial user interactions to induce targeted mispredictions. Previous PPA methods suffer from two limitations, i.e., i) over-reliance on sequence horizon impact restricts fine-grained perturbations on item transitions, and ii) holistic modifications cause detectable distribution shifts. To address these challenges, we propose a constrained reinforcement driven attack CREAT that synergizes a bi-level optimization framework with multi-reward reinforcement learning to balance adversarial efficacy and stealthiness. We first develop a Pattern Balanced Rewarding Policy, which integrates pattern inversion rewards to invert critical patterns and distribution consistency rewards to minimize detectable shifts via unbalanced co-optimal transport. Then we employ a Constrained Group Relative Reinforcement Learning paradigm, enabling step-wise perturbations through dynamic barrier constraints and group-shared experience replay, achieving targeted pollution with minimal detectability. Extensive experiments demonstrate the effectiveness of CREAT.

推荐系统对抗攻击强化学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。