arXiv:2604.22170cs.LGcs.IR2026-04被引 1

通过寻找最坏情况模型,提升推荐系统投毒攻击的迁移效果。

Sharpness-Aware Poisoning: Enhancing Transferability of Injective Attacks on Recommender Systems

论文配图:Sharpness-Aware Poisoning: Enhancing Transferability of Injective Attacks on Recommender Systems
图 1 · 摘自论文原文
  • 利用尖锐度感知机制寻找最坏情况的受害者模型,针对性优化投毒数据。
  • 在三个真实数据集上,攻击迁移率显著提升,对模型结构变化更鲁棒。
  • 适合研究推荐系统安全、对抗攻击的学者和工程师参考。

推荐系统易受注入式攻击,攻击者通过注入少量虚假用户资料,推动目标物品曝光以获取不正当利益(如经济或政治优势)。由于攻击者缺乏对目标推荐系统中部署模型的了解,现有方法通常采用固定替代模型来模拟潜在受害者模型。然而,我们指出,假设‘为替代模型生成的污染数据可有效攻击其他受害者模型’是理想化的。当替代模型与受害者模型存在显著结构差异时,攻击迁移性必然下降。直观上,若能识别最坏情况的受害者模型,并迭代优化针对该模型的污染效果,则生成的污染数据将更易迁移到其他模型。但因受害者模型空间庞大,准确识别最坏情况模型极具挑战。为此,本文提出一种新攻击方法——尖锐度感知投毒(SharpAP)。其采用尖锐度感知最小化原则,寻找近似最坏情况的受害者模型,并专门优化针对该模型的污染数据。该攻击被建模为一个三重极小-极大-极小优化问题。通过将SharpAP融入迭代攻击过程,本方法可生成更鲁棒的污染数据,降低对模型结构变化的敏感性,缓解对替代模型的过拟合。在三个真实世界数据集上的全面实验表明,SharpAP能显著提升攻击迁移能力。

原文摘要 · Abstract (English)

Recommender Systems~(RS) have been shown to be vulnerable to injective attacks, where attackers inject limited fake user profiles to promote the exposure of target items to real users for unethical gains (e.g., economic or political advantages). Since attackers typically lack knowledge of the victim model deployed in the target RS, existing methods resort to using a fixed surrogate model to mimic the potential victim model. Despite considerable progress, we argue that the assumption that \textit{poisoned data generated for the surrogate model can be used to attack other victim models} is wishful. When there are significant structural discrepancies between the surrogate and victim models, the attack transferability inevitably suffers. Intuitively, if we can identify the worst-case victim model and iteratively optimize the poisoning effect specifically against it, then the generated poisoned data would be better transferred to other victim models. However, exactly identifying the worst-case victim model during the attack process is challenging due to the large space of victim models. To this end, in this work, we propose a novel attack method called Sharpness-Aware Poisoning (\textit{SharpAP}). Specifically, it employs the sharpness-aware minimization principle to seek the approximately worst-case victim model and optimizes the poisoned data specifically for this worst-case model. The poisoning attack with SharpAP is formulated as a min-max-min tri-level optimization problem. By integrating SharpAP into the iterative process for attacks, our method can generate more robust poisoned data which is less sensitive to the shift of model structure, mitigating the overfitting to the surrogate model. Comprehensive experimental comparisons on three real-world datasets demonstrate that \name~can significantly enhance the attack transferability.

推荐系统对抗攻击投毒攻击迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。