Adversarial Item Promotion: Vulnerabilities at the Core of Top-N Recommenders that Use Images to Address Cold Start

被引:14
|
作者
Liu, Zhuoran [1 ]
Larson, Martha [1 ]
机构
[1] Radboud Univ Nijmegen, Nijmegen, Netherlands
来源
PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021) | 2021年
关键词
D O I
10.1145/3442381.3449891
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
E-commerce platforms provide their customers with ranked lists of recommended items matching the customers' preferences. Merchants on e-commerce platforms would like their items to appear as high as possible in the top-N of these ranked lists. In this paper, we demonstrate how unscrupulous merchants can create item images that artificially promote their products, improving their rankings. Recommender systems that use images to address the cold start problem are vulnerable to this security risk. We describe a new type of attack, Adversarial Item Promotion (AIP), that strikes directly at the core of Top-N recommenders: the ranking mechanism itself. Existing work on adversarial images in recommender systems investigates the implications of conventional attacks, which target deep learning classifiers. In contrast, our AIP attacks are embedding attacks that seek to push features representations in a way that fools the ranker (not a classifier) and directly leads to item promotion. We introduce three AIP attacks insider attack, expert attack, and semantic attack, which are defined with respect to three successively more realistic attack models. Our experiments evaluate the danger of these attacks when mounted against three representative visually-aware recommender algorithms in a framework that uses images to address cold start. We also evaluate potential defenses, including adversarial training and find that common, currently-existing, techniques do not eliminate the danger of AIP attacks. In sum, we show that using images to address cold start opens recommender systems to potential threats with clear practical implications.
引用
收藏
页码:3590 / 3602
页数:13
相关论文
共 7 条
  • [1] Sequential-based Adversarial Optimisation for Personalised Top-N Item Recommendation
    Manotumruksa, Jarana
    Yilmaz, Emine
    PROCEEDINGS OF THE 43RD INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '20), 2020, : 2045 - 2048
  • [2] User-based Clustering with Top-N Recommendation on Cold-Start Problem
    Ling Yanxiang
    Guo Deke
    Cai Fei
    Chen Honghui
    2013 THIRD INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEM DESIGN AND ENGINEERING APPLICATIONS (ISDEA), 2013, : 1585 - 1589
  • [3] ImposeSVD: Incrementing PureSVD For Top-N Recommendations for Cold-Start Problems and Sparse Datasets
    YILMAZER, H. A. K. A. N.
    OZEL, S. E. L. M. A. A. Y. S. E.
    COMPUTER JOURNAL, 2023, 66 (11): : 2595 - 2622
  • [4] Improving Top-N Recommendation for Cold-Start Users via Cross-Domain Information
    Mirbakhsh, Nima
    Ling, Charles X.
    ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2015, 9 (04) : 1 - 19
  • [5] Genetic Algorithm Influenced Top-N Recommender System to Alleviate New User Cold Start Problem
    Moses, Sharon J.
    Babu, Dhinesh L. D.
    INTERNATIONAL JOURNAL OF SWARM INTELLIGENCE RESEARCH, 2020, 11 (02) : 62 - 79
  • [6] Session Similarity based Approach for Alleviating Cold-start Session Problem in e-Commerce for Top-N Recommendations
    Esmeli, Ramazan
    Bader-El-Den, Mohamed
    Abdullahi, Hassana
    PROCEEDINGS OF THE 12TH INTERNATIONAL JOINT CONFERENCE ON KNOWLEDGE DISCOVERY, KNOWLEDGE ENGINEERING AND KNOWLEDGE MANAGEMENT (KDIR), VOL 1, 2020, : 179 - 186
  • [7] ADA-DR: An Adversarial Domain Adaptation Framework for Disaster Response to Address Cold-Start Issue for Multiclass Classification of Disaster Images
    Saima Saleem
    Anuradha Khattar
    Monica Mehrotra
    SN Computer Science, 5 (8)