arXiv:2607.15114cs.IRcs.SI2026-07

提出新框架CoSimRec,量化推荐系统中协同内容的渗透效果。

CoSimRec: Measuring Coordinated-Content Penetration in Recommender Feedback Loops

论文配图:CoSimRec: Measuring Coordinated-Content Penetration in Recommender Feedback Loops
图 1 · 摘自论文原文
  • 构建闭环仿真环境,模拟账号协同与推荐反馈动态
  • 发现热门和敏感排序策略下渗透率最高达0.4702
  • 适合研究推荐系统鲁棒性与内容操纵的学者

推荐系统决定哪些内容触达用户,因此需评估协同行为是否能突破发起账号的范围获得更广曝光。现有鲁棒性评估多关注静态目标排名变化,无法捕捉协同互动、推荐机制与用户响应在反馈环中的演化过程。我们提出CoSimRec——一种离线代理式评估框架,可建模协同账号、动态排名、受控非机器人响应及排名干预,在共享闭环过程中进行仿真。CoSimRec引入算法渗透率(APR)指标族:曝光APR为首要评估指标,行为APR为响应模型条件下的敏感度度量,均可与匹配的无攻击基线对比。我们在MIND、MovieLens和LastFM数据集上,使用随机、流行度驱动、反馈敏感、MF、BPR-MF和BPR-LightGCN六种推荐器进行评估。在风险盲主协议中,随机控制组未显示显著正向渗透;而流行度驱动和反馈敏感排序在所有六种主-从设置中均产生正APR提升,最高达0.4702(在LastFM上)。九目标的MovieLens 1M LightGCN压力测试显示,在三个目标流行度层级中,25%注入比例下平均APR提升为正值,而无填充资料的配置始终接近零。在这些受控条件下,协同输入成功进入非机器人推荐位,证明了从有组织活动到受众级可见性的计算路径存在。

原文摘要 · Abstract (English)

Recommender systems shape which content reaches users, making it important to measure whether coordinated activity gains visibility beyond the accounts that initiate it. Existing robustness evaluations largely focus on static target-rank changes and do not capture how coordinated interactions, recommendation, and user response evolve within a feedback loop. We propose CoSimRec, an offline agent-based evaluation framework that models coordinated accounts, dynamic ranking, controlled non-bot responses, and ranking interventions in a shared closed-loop process. CoSimRec introduces the Algorithmic Penetration Rate (APR) metric family: exposure APR is the primary endpoint, while behavior APR is a response-model-conditional sensitivity measure; both can be compared with matched no-attack baselines. We evaluate CoSimRec on MIND, MovieLens, and LastFM with random, popularity-based, feedback-sensitive, MF, BPR-MF, and BPR-LightGCN recommenders. In a risk-blind primary protocol, random controls show no statistically supported positive penetration, whereas popularity-based and feedback-sensitive ranking produce positive APR-Lift in all six master-worker settings, reaching 0.4702 on LastFM. A nine-target MovieLens 1M LightGCN stress test shows positive mean APR-Lift around 25\% injection in all three target-popularity strata, while no-filler profiles remain near zero. Under these controlled conditions, coordinated inputs reach non-bot recommendation slots, providing evidence of a computational pathway from organized activity to audience-level visibility.

推荐系统协同攻击反馈循环评估框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。