arXiv:2606.29064cs.IRcs.AI2026-06

提出一种结构感知的公平性攻击方法,可放大推荐系统对用户的不公平歧视。

Fairness Attacks on Recommender Systems

论文配图:Fairness Attacks on Recommender Systems
图 1 · 摘自论文原文
  • 基于图结构和RNN建模虚假交互,生成具有序列依赖的恶意数据。
  • 在4种推荐模型、2个真实数据集上验证,显著加剧了系统的不公平性。
  • 适用于研究推荐系统公平性脆弱性的安全与伦理研究人员。

推荐系统中的不公平问题因其重大的社会与伦理影响日益受到关注。尽管已有研究证明了对推荐系统性能的攻击(如提升/降级攻击)的有效性,但针对推荐系统公平性的攻击研究仍较为匮乏。为此,我们提出一种基于结构感知强化学习的新型公平性攻击方法,旨在加剧目标推荐系统的不公平性。首先,采用基于图的结构编码器建模生成的虚假用户-物品交互与原始交互之间的结构依赖关系;其次,利用循环神经网络建模注入虚假物品的序列依赖性。基于学习到的结构感知和序列感知的虚假用户与物品表示,项目选择策略可有侧重地决定下一个注入的虚假项目。考虑到目标推荐系统可能采用公平性感知训练并利用性别等敏感属性信息,我们进一步设计了性别选择策略,用于确定整个虚假用户档案的性别。项目选择与性别选择策略在所提方法中联合学习。在四种目标推荐模型和两个真实世界数据集上的实验结果表明,该攻击方法能有效加剧推荐系统的不公平性。

原文摘要 · Abstract (English)

The unfairness of recommender systems has become a topic of concern due to its significant social and ethical implications. Although existing works have shown the effectiveness of attacks on the performance of recommender systems (e.g., promotion and demotion attack), the study of fairness attacks on recommender systems remains largely under-explored. To this end, we propose a novel structure-aware reinforcement learning-based fairness attack method designed to exacerbate the unfairness of target recommender systems. Specifically, we first employ a graph-based structure encoder to model the structural dependencies among the generated fake user-item interactions and the original user-item interactions. Then, we model the sequential dependency of the injected fake items using a recurrent neural network. Based on the learned structure-aware and sequence-aware representations of the fake user and item, the item selection policy attentively decides the next injected fake item. Since the target recommender system may employ fairness-aware training and leverage the user's sensitive attribute information, such as gender, we further designed a gender selection policy to decide the gender of the entire fake user profile. Both the item selection and gender selection policy are learned jointly in our proposed method. Finally, experimental results on four types of target recommendation models and two real-world datasets demonstrate the effectiveness of the proposed attack method in exacerbating the unfairness of recommender systems.

推荐系统公平性对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。