vix.ing · top · new · best · stats · spec

Adversarial Recommendation: Attack of the Learned Fake Users

2018/09/21 by Konstantina Christakopoulou, Arindam Banerjee, Christakopoulou, Konstantina +1
Computer Science · #Adversarial Robustness in Machine Learning #Domain Adaptation and Few-Shot Learning #FOS: Computer and information sciences #Information Retrieval (cs.IR) #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Machine Learning and Algorithms

paper · pdf · doi:10.48550/arxiv.1809.08336

openalex publication_date 2018/09/21 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

Can machine learning models for recommendation be easily fooled? While the question has been answered for hand-engineered fake user profiles, it has not been explored for machine learned adversarial attacks. This paper attempts to close this gap. We propose a framework for generating fake user profiles which, when incorporated in the training of a recommendation system, can achieve an adversarial intent, while remaining indistinguishable from real user profiles. We formulate this procedure as a repeated general-sum game between two players: an oblivious recommendation system R and an adversarial fake user generator A with two goals: (G1) the rating distribution of the fake users needs to be close to the real users, and (G2) some objective fA encoding the attack intent, such as targeting the top-K recommendation quality of R for a subset of users, needs to be optimized. We propose a learning framework to achieve both goals, and offer extensive experiments considering multiple types of attacks highlighting the vulnerability of recommendation systems.

Citations

Related