Poisoning Attacks to Graph-Based Recommender Systems
arXiv:1809.04127 · doi:10.1145/3274694.3274706
Abstract
Recommender system is an important component of many web services to help users locate items that match their interests. Several studies showed that recommender systems are vulnerable to poisoning attacks, in which an attacker injects fake data to a given system such that the system makes recommendations as the attacker desires. However, these poisoning attacks are either agnostic to recommendation algorithms or optimized to recommender systems that are not graph-based. Like association-rule-based and matrix-factorization-based recommender systems, graph-based recommender system is also deployed in practice, e.g., eBay, Huawei App Store. However, how to design optimized poisoning attacks for graph-based recommender systems is still an open problem. In this work, we perform a systematic study on poisoning attacks to graph-based recommender systems. Due to limited resources and to avoid detection, we assume the number of fake users that can be injected into the system is bounded. The key challenge is how to assign rating scores to the fake users such that the target item is recommended to as many normal users as possible. To address the challenge, we formulate the poisoning attacks as an optimization problem, solving which determines the rating scores for the fake users. We also propose techniques to solve the optimization problem. We evaluate our attacks and compare them with existing attacks under white-box (recommendation algorithm and its parameters are known), gray-box (recommendation algorithm is known but its parameters are unknown), and black-box (recommendation algorithm is unknown) settings using two real-world datasets. Our results show that our attack is effective and outperforms existing attacks for graph-based recommender systems. For instance, when 1% fake users are injected, our attack can make a target item recommended to 580 times more normal users in certain scenarios.
34th Annual Computer Security Applications Conference (ACSAC), 2018; Due to the limitation "The abstract field cannot be longer than 1,920 characters", the abstract appearing here is slightly shorter than that in the PDF file
References in corpus (5)
- Graph Convolutional Neural Networks for Web-Scale Recommender Systems
- Neural Collaborative Filtering
- Data Poisoning Attacks on Factorization-Based Collaborative Filtering
- Supervised Random Walks: Predicting and Recommending Links in Social Networks
- AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine Learning
Cited by in corpus (42)
- Adversarial Attack and Defense on Graph Data: A Survey
- Local Model Poisoning Attacks to Byzantine-Robust Federated Learning
- Data Poisoning Attacks to Deep Learning Based Recommender Systems
- Blockchain-based Recommender Systems: Applications, Challenges and Future Opportunities
- Attacking Recommender Systems with Augmented User Profiles
- FedRecAttack: Model Poisoning Attack to Federated Recommendation
- Revisiting Adversarially Learned Injection Attacks Against Recommender Systems
- Shilling Black-box Recommender Systems by Learning to Generate Fake User Profiles
- POTs: Protective Optimization Technologies
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks
- Data Poisoning Attacks Against Federated Learning Systems
- Knowledge-enhanced Black-box Attacks for Recommendations
- Poisoning Deep Learning Based Recommender Model in Federated Learning Scenarios
- Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching
- FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping
- Towards a Robust and Trustworthy Machine Learning System Development: An Engineering Perspective
- Rank List Sensitivity of Recommender Systems to Interaction Perturbations
- Turning Federated Learning Systems Into Covert Channels
- Projective Ranking-based GNN Evasion Attacks
- Turning Privacy-preserving Mechanisms against Federated Learning
- Attacking Graph-based Classification via Manipulating the Graph Structure
- Poisoning Attacks to Local Differential Privacy Protocols for Key-Value Data
- Robust Basket Recommendation via Noise-tolerated Graph Contrastive Learning
- Defending against Machine Learning based Inference Attacks via Adversarial Examples: Opportunities and Challenges
- Preventing the Popular Item Embedding Based Attack in Federated Recommendations
- Influence Function based Data Poisoning Attacks to Top-N Recommender Systems
- Adversarial Diffusion Attacks on Graph-based Traffic Prediction Models
- FedCom: A Byzantine-Robust Local Model Aggregation Rule Using Data Commitment for Federated Learning
- Data Poisoning Attacks to Local Differential Privacy Protocols
- Attacking Black-box Recommendations via Copying Cross-domain User Profiles
- Evaluating Impact of User-Cluster Targeted Attacks in Matrix Factorisation Recommenders
- Uplift Modeling for Target User Attacks on Recommender Systems
- Adversarial Item Promotion: Vulnerabilities at the Core of Top-N Recommenders that Use Images to Address Cold Start
- Data Poisoning Attacks on Neighborhood-based Recommender Systems
- Data Poisoning Attacks and Defenses to Crowdsourcing Systems
- On Detecting Data Pollution Attacks On Recommender Systems Using Sequential GANs
- 10 Security and Privacy Problems in Large Foundation Models
- Ready for Emerging Threats to Recommender Systems? A Graph Convolution-based Generative Shilling Attack
- MGA: Momentum Gradient Attack on Network
- AN-GCN: An Anonymous Graph Convolutional Network Defense Against Edge-Perturbing Attack
- Securing Visually-Aware Recommender Systems: An Adversarial Image Reconstruction and Detection Framework
- PipAttack: Poisoning Federated Recommender Systems forManipulating Item Promotion