arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过连通性对多智能体协同过滤系统发起攻击与防御

Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity

Anjun Hu, Hanting Xie, Saranya Govindan, Jas Kandola, Kurt Cutajar

arXiv 2608.03272首次发表:更新:

AI 中文总结

本研究将MAS的攻击与防御方法适配到AgentCF框架下的智能体CF场景,表征连通性对攻防结果的影响,还探索了流行病启发指标用于CF配置的健壮性评估。

AI 中文摘要

多智能体协同过滤(CF)系统通过自然语言交互协调由大型语言模型(LLM)驱动的自主用户智能体与物品智能体,以细化偏好并生成推荐。这些系统继承了数据驱动特性与多智能体交互的漏洞,且漏洞表现形式不同。理解连通性如何调节此类系统的漏洞,有助于开发更健壮的推荐流程。本研究将通用多智能体系统(MAS)文献中的攻击与防御方法适配到基于智能体的CF场景中,在AgentCF框架下系统变化连通性进行评估,其中CF连通性沿两个轴表征:(i)候选数(每轮每位用户的物品候选数量,衡量用户侧交互密度);(ii)目录集中度(用户间物品目录重叠的程度)。本研究的贡献包括:(1)适配:在智能体CF领域复现受MAS启发的攻击与防御方法,确认原始观察结果的部分可迁移性;(2)表征:表征连通性的两个方面如何塑造攻击与防御结果,揭示用户与物品智能体间的角色不对称性、攻击效能的非单调时间动态,以及传播与提取两类攻击目标的不同模式。此外,作为探索性扩展,本研究评估了受流行病启发的静态指标在按预期攻击结果对CF配置进行排序中的适用性,这可能实现成本高效的健壮性评估。实现代码可在该https URL获取。

英文摘要

Multi-agent collaborative filtering (CF) systems coordinate autonomous LLM-powered user and item agents through natural-language interaction to refine preferences and generate recommendations. These systems inherit vulnerabilities from both their data-driven nature and their multi-agent interactions, which manifest in distinct ways. Understanding how connectivity modulates vulnerability in these systems could facilitate the development of more robust recommendation pipelines. In this work, we adapt attacks and defenses from the general multi-agent systems (MAS) literature to the agent-based CF setting, evaluating them under systematically varied connectivity in the AgentCF framework, where CF connectivity is characterized along two axes: (i) candidate count (the number of item candidates per turn per user, measuring user-side interaction density) and (ii) catalog concentration (the degree of item catalog overlap across users). Our contributions include: (1) Adaptation: we reproduce MAS-inspired attacks and defenses in the agentic CF domain, confirming partial transferability of original observations. (2) Characterization: we characterize how the two aspects of connectivity shape attack and defense outcomes, revealing role asymmetries between user and item agents, non-monotonic temporal dynamics in attack efficacy, and divergent patterns across dissemination and extraction attack goals. Additionally, as an exploratory extension, we assess the applicability of epidemic-inspired static metrics in ranking CF configurations by expected attack outcome, potentially enabling cost-efficient robustness assessment. Implementation is available at https://github.com/anjunhu/ConnACF

Comments10 pages, 10 figures, 20th ACM Conference on Recommender Systems (RecSys '26)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑