arXiv:2602.10633cs.IR2026-02被引 1

通过认知分布与行为一致性提升黑盒推荐系统攻击效果

A Cognitive Distribution and Behavior-Consistent Framework for Black-Box Attacks on Recommender Systems

  • 用认知分布建模排名位置偏倚,实现更精准的推荐结构提取
  • 生成兼具语义一致性和统计隐蔽性的对抗序列,成功率显著提升
  • 适合研究推荐系统安全与对抗攻击的学者参考

随着序列化推荐系统在电商等领域的广泛应用,其黑盒接口引发安全担忧:模型易受信息提取与后续对抗操纵。现有黑盒提取攻击多依赖硬标签或成对学习,忽视排序位置的重要性,导致知识传递不完整。此外,纯梯度生成的对抗序列缺乏真实用户行为的语义一致性,易被检测。为此,本文提出双增强攻击框架:首先,基于首因效应与位置偏倚,引入认知分布驱动的提取机制,将离散排序映射为具有位置感知衰减的连续值分布,实现从顺序对齐到认知分布对齐的升级;其次,设计行为感知的噪声物品生成策略,联合优化协同信号与梯度信号,确保语义连贯性与统计隐蔽性,有效提升目标物品排名。多数据集实验证明,该方法在攻击成功率和逃避率上均显著优于现有方法,验证了融合认知建模与行为一致性对安全推荐系统的价值。

原文摘要 · Abstract (English)

With the growing deployment of sequential recommender systems in e-commerce and other fields, their black-box interfaces raise security concerns: models are vulnerable to extraction and subsequent adversarial manipulation. Existing black-box extraction attacks primarily rely on hard labels or pairwise learning, often ignoring the importance of ranking positions, which results in incomplete knowledge transfer. Moreover, adversarial sequences generated via pure gradient methods lack semantic consistency with real user behavior, making them easily detectable. To overcome these limitations, this paper proposes a dual-enhanced attack framework. First, drawing on primacy effects and position bias, we introduce a cognitive distribution-driven extraction mechanism that maps discrete rankings into continuous value distributions with position-aware decay, thereby advancing from order alignment to cognitive distribution alignment. Second, we design a behavior-aware noisy item generation strategy that jointly optimizes collaborative signals and gradient signals. This ensures both semantic coherence and statistical stealth while effectively promoting target item rankings. Extensive experiments on multiple datasets demonstrate that our approach significantly outperforms existing methods in both attack success rate and evasion rate, validating the value of integrating cognitive modeling and behavioral consistency for secure recommender systems.

推荐系统对抗攻击认知建模行为一致性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。