Toward Adversarially Robust Recommendation From Adaptive Fraudster Detection

被引:2
|
作者
Lai, Yuni [1 ]
Zhu, Yulin [1 ]
Fan, Wenqi [1 ]
Zhang, Xiaoge [2 ]
Zhou, Kai [1 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Peoples R China
[2] Hong Kong Polytech Univ, Dept Ind & Syst Engn, Hong Kong, Peoples R China
基金
美国国家科学基金会;
关键词
Robustness; Recommender systems; Training; Feature extraction; Anomaly detection; Adaptation models; Uncertainty; Recommender system; adversarial robustness; graph neural networks; anomaly detection; label uncertainty; SHILLING ATTACK DETECTION; SYSTEMS;
D O I
10.1109/TIFS.2023.3327876
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The robustness of recommender systems under node injection attacks has garnered significant attention. Recently, GraphRfi, a Graph-Neural-Network-based (GNN-based) recommender system, was proposed and shown to effectively mitigate the impact of injected fake users. However, we demonstrate that GraphRfi remains vulnerable to attacks due to the supervised nature of its fraudster detection component, where obtaining clean labels is challenging in practice. In particular, we propose a powerful poisoning attack, MetaC, against both GNN-based and Martix-Faxtorization-based recommender systems. Furthermore, we analyze why GraphRfi fails under such an attack. Then, based on our insights obtained from vulnerability analysis, we design an adaptive fraudster detection module that explicitly considers label uncertainty. This module can serve as a plug-in for different recommender systems, resulting in a robust framework named Posterior-Detection Recommender (PDR). Comprehensive experiments show that our defense approach outperforms other benchmark methods under attacks. Overall, our research presents an effective framework for integrating fraudster detection into recommendation systems to achieve adversarial robustness.
引用
收藏
页码:907 / 919
页数:13
相关论文
共 50 条
  • [1] GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster Detection
    Zhang, Shijie
    Yin, Hongzhi
    Chen, Tong
    Quoc Viet Nguyen Hung
    Huang, Zi
    Cui, Lizhen
    PROCEEDINGS OF THE 43RD INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '20), 2020, : 689 - 698
  • [2] Adversarially Robust Deepfake Video Detection
    Devasthale, Aditya
    Sural, Shamik
    2022 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2022, : 396 - 403
  • [3] Towards Adversarially Robust Object Detection
    Zhang, Haichao
    Wang, Jianyu
    2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, : 421 - 430
  • [4] Adversarially Robust Change Point Detection
    Li, Mengchu
    Yu, Yi
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [5] Adversarial Vertex Mixup: Toward Better Adversarially Robust Generalization
    Lee, Saehyung
    Lee, Hyungyu
    Yoon, Sungroh
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 269 - 278
  • [6] Adversarially Robust One-Class Novelty Detection
    Lo, Shao-Yuan
    Oza, Poojan
    Patel, Vishal M. M.
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (04) : 4167 - 4179
  • [7] Adversarially Robust Malware Detection Using Monotonic Classification
    Incer, Inigo
    Theodorides, Michael
    Afroz, Sadia
    Wagner, David
    IWSPA '18: PROCEEDINGS OF THE FOURTH ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, 2018, : 54 - 63
  • [8] ARAE: Adversarially robust training of autoencoders improves novelty detection
    Salehi, Mohammadreza
    Arya, Atrin
    Pajoum, Barbod
    Otoofi, Mohammad
    Shaeiri, Amirreza
    Rohban, Mohammad Hossein
    Rabiee, Hamid R.
    NEURAL NETWORKS, 2021, 144 : 726 - 736
  • [9] Poster Abstract: Are Android Malware Detection Models Adversarially Robust?
    Rathore, Hemant
    Sahay, Sanjay K.
    Sewak, Mohit
    IPSN'21: PROCEEDINGS OF THE 20TH ACM/IEEE CONFERENCE ON INFORMATION PROCESSING IN SENSOR NETWORKS, 2021, : 408 - 409
  • [10] Reliable feature selection for adversarially robust cyber-attack detection
    Vitorino, Joao
    Silva, Miguel
    Maia, Eva
    Praca, Isabel
    ANNALS OF TELECOMMUNICATIONS, 2025, 80 (3-4) : 341 - 355