Gray-Box Shilling Attack: An Adversarial Learning Approach

被引:8
|
作者
Wang, Zongwei [1 ]
Gao, Min [1 ]
Li, Jundong [2 ,3 ]
Zhang, Junwei [1 ]
Zhong, Jiang [4 ]
机构
[1] Chongqing Univ, Sch Big Data & Software Engn, Chongqing, Peoples R China
[2] Univ Virginia, Dept Elect & Comp Engn, Dept Comp Sci, Charlottesville, VA 22903 USA
[3] Univ Virginia, Sch Data Sci, Charlottesville, VA 22903 USA
[4] Chongqing Univ, Coll Comp Sci, Chongqing, Peoples R China
基金
中国国家自然科学基金;
关键词
Shilling attack; adversarial learning; GANs; RECOMMENDER SYSTEMS;
D O I
10.1145/3512352
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recommender systems are essential components of many information services, which aim to find relevant items that match user preferences. Several studies have shown that shilling attacks can significantly weaken the robustness of recommender systems by injecting fake user profiles. Traditional shilling attacks focus on creating hand-engineered fake user profiles, but these profiles can be detected effortlessly by advanced detection methods. Adversarial learning, which has emerged in recent years, can be leveraged to generate powerful and intelligent attack models. To this end, in this article we explore potential risks of recommender systems and shed light on a gray-box shilling attack model based on generative adversarial networks, named GSA-GANs. Specifically, we aim to generate fake user profiles that can achieve two goals: unnoticeable and offensive. Toward these goals, there are several challenges that we need to address: (1) learning complex user behaviors from user-item rating data, and (2) adversely influencing the recommendation results without knowing the underlying recommendation algorithms. To tackle these challenges, two essential GAN modules are respectively designed to make generated fake profiles more similar to real ones and harmful to recommendation results. Experimental results on three public datasets demonstrate that the proposed GSA-GANs framework outperforms baseline models in attack effectiveness, transferability, and camouflage. In the end, we also provide several possible defensive strategies against GSA-GANs. The exploration and analysis in our work will contribute to the defense research of recommender systems.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] Gray-Box Adversarial Training
    Vivek, B. S.
    Mopuri, Konda Reddy
    Babu, R. Venkatesh
    COMPUTER VISION - ECCV 2018, PT 15, 2018, 11219 : 213 - 228
  • [2] An Incremental Gray-box Physical Adversarial Attack on Neural Network Training
    Al-qudah, Rabiah
    Aloqaily, Moayad
    Ouni, Bassem
    Guizani, Mohsen
    Lestable, Thierry
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 45 - 50
  • [3] Language Model Agnostic Gray-Box Adversarial Attack on Image Captioning
    Aafaq, Nayyer
    Akhtar, Naveed
    Liu, Wei
    Shah, Mubarak
    Mian, Ajmal
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 626 - 638
  • [4] Gray-box Adversarial Testing for Control Systems with Machine Learning Components
    Yaghoubi, Shakiba
    Fainekos, Georgios
    PROCEEDINGS OF THE 2019 22ND ACM INTERNATIONAL CONFERENCE ON HYBRID SYSTEMS: COMPUTATION AND CONTROL (HSCC '19), 2019, : 179 - 184
  • [5] Exploring Public Data Vulnerabilities in Semi-Supervised Learning Models through Gray-box Adversarial Attack
    Jo, Junhyung
    Kim, Joongsu
    Suh, Young-Joo
    ELECTRONICS, 2024, 13 (05)
  • [6] Similarity-based Gray-box Adversarial Attack Against Deep Face Recognition
    Wang, Hanrui
    Wang, Shuo
    Jin, Zhe
    Wang, Yandan
    Chen, Cunjian
    Tistarelli, Massimo
    2021 16TH IEEE INTERNATIONAL CONFERENCE ON AUTOMATIC FACE AND GESTURE RECOGNITION (FG 2021), 2021,
  • [7] Surrogate Representation Learning with Isometric Mapping for Gray-box Graph Adversarial Attacks
    Liu, Zihan
    Luo, Yun
    Zang, Zelin
    Li, Stan Z.
    WSDM'22: PROCEEDINGS OF THE FIFTEENTH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2022, : 591 - 598
  • [8] Side-Channel Gray-Box Attack for DNNs
    Xiang, Yun
    Xu, Yongchao
    Li, Yingjie
    Ma, Wen
    Xuan, Qi
    Liu, Yi
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2021, 68 (01) : 501 - 505
  • [9] Mitigating Adversarial Gray-Box Attacks Against Phishing Detectors
    Apruzzese, Giovanni
    Subrahmanian, V. S.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 3753 - 3769
  • [10] Gray-box approach for fault detection of dynamical system
    Park, HG
    Zak, M
    JOURNAL OF DYNAMIC SYSTEMS MEASUREMENT AND CONTROL-TRANSACTIONS OF THE ASME, 2003, 125 (03): : 451 - 454