English

Adversarial Recommendation: Attack of the Learned Fake Users

Information Retrieval 2018-09-25 v1 Machine Learning Machine Learning

Abstract

Can machine learning models for recommendation be easily fooled? While the question has been answered for hand-engineered fake user profiles, it has not been explored for machine learned adversarial attacks. This paper attempts to close this gap. We propose a framework for generating fake user profiles which, when incorporated in the training of a recommendation system, can achieve an adversarial intent, while remaining indistinguishable from real user profiles. We formulate this procedure as a repeated general-sum game between two players: an oblivious recommendation system RR and an adversarial fake user generator AA with two goals: (G1) the rating distribution of the fake users needs to be close to the real users, and (G2) some objective fAf_A encoding the attack intent, such as targeting the top-K recommendation quality of RR for a subset of users, needs to be optimized. We propose a learning framework to achieve both goals, and offer extensive experiments considering multiple types of attacks highlighting the vulnerability of recommendation systems.

Keywords

Cite

@article{arxiv.1809.08336,
  title  = {Adversarial Recommendation: Attack of the Learned Fake Users},
  author = {Konstantina Christakopoulou and Arindam Banerjee},
  journal= {arXiv preprint arXiv:1809.08336},
  year   = {2018}
}
R2 v1 2026-06-23T04:14:37.463Z