arrow
Return

Gray-Box Shilling Attack: An Adversarial Learning Approach

delete2022-10-14
delete7
PRE
AI
Z
Zongwei Wang
高旻 (Min Gao) *
李俊东 (Jundong Li)
J
Junwei Zhang
J
Jiang Zhong
DOI:10.1145/3512352delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Recommender systems are essential components of many information services, which aim to find relevant items that match user preferences. Several studies have shown that shilling attacks can significantly weaken the robustness of recommender systems by injecting fake user profiles. Traditional shilling attacks focus on creating hand-engineered fake user profiles, but these profiles can be detected effortlessly by advanced detection methods. Adversarial learning, which has emerged in recent years, can be leveraged to generate powerful and intelligent attack models. To this end, in this article we explore potential risks of recommender systems and shed light on a gray-box shilling attack model based on generative adversarial networks, named GSA-GANs. Specifically, we aim to generate fake user profiles that can achieve two goals: unnoticeable and offensive. Toward these goals, there are several challenges that we need to address: (1) learning complex user behaviors from user-item rating data, and (2) adversely influencing the recommendation results without knowing the underlying recommendation algorithms. To tackle these challenges, two essential GAN modules are respectively designed to make generated fake profiles more similar to real ones and harmful to recommendation results. Experimental results on three public datasets demonstrate that the proposed GSA-GANs framework outperforms baseline models in attack effectiveness, transferability, and camouflage. In the end, we also provide several possible defensive strategies against GSA-GANs. The exploration and analysis in our work will contribute to the defense research of recommender systems.
Keywords:
Shilling attack
adversarial learning
GANs

Journal

ACM Transactions on Intelligent Systems and Technology cover
ACM Transactions on Intelligent Systems and Technology
IF:
6.6
Papers:
1.5K
Citations:
6.2K

Organization

C
Chongqing University
Scholars:
5.1W
Papers: 4.1W
Citations: 6.0W
U
University of Virginia
Scholars:
3.0W
Papers: 2.7W
Citations: 4.1W