PARL: Poisoning Attacks Against Reinforcement Learning-based Recommender Systems

被引:1
|
作者
Du, Linkang [1 ]
Yuan, Quan [1 ]
Chen, Min [2 ]
Sun, Mingyang [1 ]
Cheng, Peng [1 ]
Chen, Jiming [1 ,3 ]
Zhang, Zhikun [1 ]
机构
[1] Zhejiang Univ, Hangzhou, Zhejiang, Peoples R China
[2] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
[3] Hangzhou Dianzi Univ, Hangzhou, Zhejiang, Peoples R China
关键词
Poisoning Attack; Recommender System; Reinforcement Learning;
D O I
10.1145/3634737.3637660
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recommender systems predict and suggest relevant options to users in various domains, such as e-commerce, streaming services, and social media. Recently, deep reinforcement learning (DRL)-based recommendation systems have become increasingly popular in academics and industry since DRL can characterize the long-term interaction between the system and users to achieve a better recommendation experience, e.g., Netflix, Spotify, Google, and YouTube. This paper demonstrates that an adversary can manipulate the DRL-based recommender system by injecting carefully designed user-system interaction records. The poisoning attack against the DRL-based recommender system is formulated as a non-convex integer programming problem. To solve the problem, we proposed a three-phase mechanism (called PARL) to maximize the hit ratio (the proportion of recommendations that result in actual user interactions, such as clicks, purchases, or other relevant actions) while avoiding easy detection. The core idea of PARL is to improve the ranking of the target item while fixing the rankings of other items. Considering the sequential decision-making characteristics of DRL, PARL rearranges the items' order of the fake users to mimic the normal users' sequential features, an aspect usually overlooked in existing work. Our experiments on three real-world datasets demonstrate the effectiveness of PARL and better concealment against the detection techniques. PARL is open-sourced at https://github.com/PARL-RS/PARL.
引用
收藏
页码:1331 / 1344
页数:14
相关论文
共 50 条
  • [31] Model poisoning attacks against distributed machine learning systems
    Tomsett, Richard
    Chan, Kevin
    Chakraborty, Supriyo
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS, 2019, 11006
  • [32] Defending Against Data Integrity Attacks in Smart Grid: A Deep Reinforcement Learning-Based Approach
    An, Dou
    Yang, Qingyu
    Liu, Wenmao
    Zhang, Yang
    IEEE ACCESS, 2019, 7 : 110835 - 110845
  • [33] RDERL: Reliable deep ensemble reinforcement learning-based recommender system
    Ahmadian, Milad
    Ahmadian, Sajad
    Ahmadi, Mahmood
    KNOWLEDGE-BASED SYSTEMS, 2023, 263
  • [34] Poisoning GNN-based Recommender Systems with Generative Surrogate-based Attacks
    Thanh, Toan Nguyen
    Quach, Nguyen Duc Khang
    Nguyen, Thanh Tam
    Huynh, Thanh Trung
    Vu, Viet Hung
    Le Nguyen, Phi
    Jo, Jun
    Nguyen, Quoc Viet Hung
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2023, 41 (03)
  • [35] Comparison of deep learning-based autoencoders for recommender systems
    Lee, Hyo Jin
    Jung, Yoonsuh
    KOREAN JOURNAL OF APPLIED STATISTICS, 2021, 34 (03) : 329 - 345
  • [36] Deep Reinforcement Learning-Based Multi-Object Adaptive Route Planning for Traveling Recommender Systems
    Wang, Yan
    Hu, Pei
    IEEE ACCESS, 2023, 11 : 120258 - 120269
  • [37] A Survey on Reinforcement Learning and Deep Reinforcement Learning for Recommender Systems
    Rezaei, Mehrdad
    Tabrizi, Nasseh
    DEEP LEARNING THEORY AND APPLICATIONS, DELTA 2023, 2023, 1875 : 385 - 402
  • [38] Reward poisoning attacks in deep reinforcement learning based on exploration strategies
    Cai, Kanting
    Zhu, Xiangbin
    Hu, Zhaolong
    NEUROCOMPUTING, 2023, 553
  • [39] Adversarial Attacks on Deep Reinforcement Learning-based Traffic Signal Control Systems with Colluding Vehicles
    Qu, Ao
    Tang, Yihong
    Ma, Wei
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2023, 14 (06)
  • [40] Deep Reinforcement Learning-Based Detection Framework for False Data Injection Attacks in Power Systems
    Prabhu, T. N.
    Ranjeethkumar, C.
    Mohankumar, B.
    Rajaram, A.
    INTERNATIONAL JOURNAL OF RENEWABLE ENERGY RESEARCH, 2024, 14 (02): : 311 - 323