paper-with-me

홈 › Papers

Diversity-aware Dual-promotion Poisoning Attack on Sequential Recommendation

2025-04-09 · Yuchuan Zhao, Tong Chen, Junliang Yu, Kai Zheng, Lizhen Cui, Hongzhi Yin

Sequential recommender systems (SRSs) excel in capturing users' dynamic interests, thus playing a key role in various industrial applications. The popularity of SRSs has also driven emerging research on their security aspects, where data poisoning attack for targeted item promotion is a typical example. Existing attack mechanisms primarily focus on increasing the ranks of target items in the recommendation list by injecting carefully crafted interactions (i.e., poisoning sequences), which comes at the cost of demoting users' real preferences. Consequently, noticeable recommendation accuracy drops are observed, restricting the stealthiness of the attack. Additionally, the generated poisoning sequences are prone to substantial repetition of target items, which is a result of the unitary objective of boosting their overall exposure and lack of effective diversity regularizations. Such homogeneity not only compromises the authenticity of these sequences, but also limits the attack effectiveness, as it ignores the opportunity to establish sequential dependencies between the target and many more items in the SRS. To address the issues outlined, we propose a Diversity-aware Dual-promotion Sequential Poisoning attack method named DDSP for SRSs. Specifically, by theoretically revealing the conflict between recommendation and existing attack objectives, we design a revamped attack objective that promotes the target item while maintaining the relevance of preferred items in a user's ranking list. We further develop a diversity-aware, auto-regressive poisoning sequence generator, where a re-ranking method is in place to sequentially pick the optimal items by integrating diversity constraints.

📄 PDF Abstract BibTeX arXiv:2504.06586

Code (0)

등록된 구현이 없습니다.

Tasks

Data PoisoningDiversityRecommendation SystemsRe-RankingSequential Recommendation

Methods 이 논문이 사용한 방법론

DDSP 설명 없음
SRS Sticker Response Selector, or SRS, is a model for multi-turn dialog that automatically selects a sticker response. SRS first employs a convolutional based sticker image…
Focus 설명 없음

Similar Papers 제목 키워드 기반

MAWSEO: Adversarial Wiki Search Poisoning for Illicit Online Promotion

2023-04-22 · Zilong Lin, Zhengyi Li, Xiaojing Liao, XiaoFeng Wang 외

As a prominent instance of vandalism edits, Wiki search poisoning for illicit promotion is a cybercrime in which the adversary aims at editing Wiki articles to promote illicit businesses through Wiki search results of re…

Articles

Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning Attacks

2023-11-30 · Zongwei Wang, Junliang Yu, Min Gao, Hongzhi Yin 외

Contrastive learning (CL) has recently gained prominence in the domain of recommender systems due to its great ability to enhance recommendation accuracy and improve model robustness. Despite its advantages, this paper i…

Contrastive LearningRecommendation Systems

Band Together: Untargeted Adversarial Training with Multimodal Coordination against Evasion-based Promotion Attacks

2026-05-07 · Guanmeng Xian, Ning Yang, Philip S. Yu arxiv

Multimodal recommender systems exploit visual and textual signals to alleviate data sparsity, but this also makes them more vulnerable to evasion-based promotion attacks. Existing defenses are largely limited to single-m…

When Experience Becomes Instruction: Trajectory Poisoning in Self-Evolving Agent Skill Systems

2026-08-06 · Jialuo Chen, Lingqi Jiang, Xinhao Deng, Xiaohu Du 외 arxiv

Self-evolving skill (SES) systems distill agent trajectories into persistent skills, allowing untrusted experience to become trusted instruction. We introduce PoisonedEvolution, a trajectory-poisoning attack on this prom…

Spattack: Subgroup Poisoning Attacks on Federated Recommender Systems

2025-07-07 · Bo Yan, Yurong Hao, Dingqi Liu, Huabin Sun 외 arxiv

Federated recommender systems (FedRec) have emerged as a promising approach to provide personalized recommendations while protecting user privacy. However, recent studies have shown their vulnerability to poisoning attac…

Contrastive Learning