arXiv:2605.06238cs.LGcs.AI2026-05

多模态推荐系统对抗逃逸式推广攻击,提升防御鲁棒性。

Band Together: Untargeted Adversarial Training with Multimodal Coordination against Evasion-based Promotion Attacks

论文配图:Band Together: Untargeted Adversarial Training with Multimodal Coordination against Evasion-based Promotion Attacks
图 1 · 摘自论文原文
  • 统一处理所有商品为潜在目标,跨模态协同优化扰动方向。
  • 在多个数据集上显著提升对抗攻击下的推荐准确率,最高达17.3%。
  • 适合关注推荐系统安全、多模态防御的研究者与工程师。

多模态推荐系统利用视觉与文本信号缓解数据稀疏问题,但也更容易受到逃逸式推广攻击。现有防御方法多局限于单模态,且主要针对投毒攻击,对逃逸攻击研究不足。本文首次发现,在多用户推广场景下存在跨模态梯度不匹配现象:因不同用户群体主导,视觉与文本扰动优化方向不一致,削弱攻击效果,导致鲁棒训练低估最坏风险。为此,提出无目标对抗训练与多模态协同机制(UAT-MC),通过梯度对齐显式纠正不匹配,实现跨模态扰动同步,最大化对抗强度以增强训练鲁棒性。大量实验表明,UAT-MC在多种数据集上显著提升对推广攻击的防御能力,同时保持合理的推荐性能,优于现有方法。代码已开源。

原文摘要 · Abstract (English)

Multimodal recommender systems exploit visual and textual signals to alleviate data sparsity, but this also makes them more vulnerable to evasion-based promotion attacks. Existing defenses are largely limited to single-modal settings and mainly focus on poisoning-based threats, leaving evasion-based threats underexplored. In this work, we first identify a cross-modal gradient mismatch under the multi-user promotion setting, where visual and textual perturbations are optimized in inconsistent directions due to the dominance of distinct user groups. This phenomenon dilutes the attack effectiveness and leads robust training to underestimate worst-case risks. To address this issue, we propose Untargeted Adversarial Training with Multimodal Coordination (UAT-MC). UAT-MC tackles the challenge of unknown targeted items in evasion-based attacks (as opposed to poisoning-based attacks) by treating all items as potential targets, and introduces a gradient alignment mechanism to explicitly correct this mismatch. This design ensures synchronized perturbations across modalities, thereby maximizing adversarial strength for robust training. Extensive experiments demonstrate that UAT-MC significantly improves robustness against promotion attacks while maintaining acceptable recommendation performance under the defense-accuracy trade-off. Code is available at https://github.com/gmXian/UAT-MC.

推荐系统对抗防御多模态安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。