arXiv:2605.04724cs.CRcs.AI2026-05中稿 · IEEE EuroS&P 2026

用音乐播放列表推断用户隐私,攻击者可精准猜出年龄、性别等敏感信息。

From Beats to Breaches:How Offensive AI Infers Sensitive User Information from Playlists

论文配图:From Beats to Breaches:How Offensive AI Infers Sensitive User Information from Playlists
图 1 · 摘自论文原文
  • 结合集合与图神经网络,从无序播放列表中提取隐私特征。
  • 在15项属性预测中,9项优于现有方法,部分准确率超80%。
  • 提出防御方案JamShield,通过添加假播放列表降低泄露风险。

人工智能的广泛应用催生了恶意用途的进攻性AI,其中用户属性推断攻击尤为突出——利用看似无害的公开数据推断敏感个人信息。本文聚焦音乐流媒体生态,研究用户公开播放列表如何被用于进攻性AI攻击。为此,我们开发了musicPIIrate工具,采用深度学习架构,融合单一数据表示与播放列表集合的结构信息,探索基于集合的方法(如Deep Sets)和建模播放列表间关系的图神经网络(GNN),并结合两者优势。该方法有效处理无序、变长集合数据,实现高精度隐私预测。实证表明,musicPIIrate在15项属性推断任务中,有9项超越基线,成功推断年龄、国家、性别等人口统计信息,以及饮酒、吸烟、运动习惯和大五人格(OCEAN)评分。为应对此威胁,我们提出轻量级防御框架JamShield,通过向账户注入虚假播放列表稀释隐私信号。分析显示,其平均使推断F1分数下降10%,具备良好防护潜力。本工作首次构建基于播放列表的进攻性AI基准,验证了集合与图结构模型的有效性,并提出可行防御策略。

原文摘要 · Abstract (English)

The pervasive integration of AI has enabled Offensive AI: the exploitation of AI for malicious ends across the cyber-kill chain. A critical manifestation is the user attribute inference attack, where AI infers sensitive Personally Identifiable Information (PII) from innocuous public data. We explore how music streaming ecosystems, where users routinely release public playlists, can be exploited for Offensive AI. To quantify this threat, we developed musicPIIrate. This novel tool leverages deep learning architectures that utilize both standalone data representations and the structural information embedded in a user's playlist collection. Our design explores set-based approaches (e.g., Deep Sets) and methodologies modeling relationships between playlists (e.g., Graph Neural Networks), which we also combine to leverage both perspectives. Our approach addresses feature extraction from unordered, variable-length set data, enabling accurate PII prediction. Empirical evaluation demonstrates that musicPIIrate achieves state-of-the-art inference accuracy. The tool successfully infers a wide array of attributes, including: Demographics (Age, Country, Gender), Habits (Alcohol, Smoke, Sport), and Personality Traits (OCEAN scores). musicPIIrate outperforms existing methods, beating baselines in 9 out of 15 attribute inference tasks. To counter this vulnerability, we propose JamShield, a lightweight defensive framework. JamShield strategically injects dummy playlists into an account to dilute the PII-carrying signal. Our analysis indicates that JamShield represents a promising defense, lowering inference F1-scores by an average of 10%. This work provides an initial Offensive-AI benchmark for playlist-based PII inference using architectures that leverage set- and graph-structured data and introduces a defense showing encouraging mitigation effects.

进攻性AI隐私泄露音乐推荐防御机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。