arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.09551cs.CRcs.CL

一种高效且有效的智能体组群托攻击方法针对推荐系统

An Efficient and Effective Agentic Group Shilling Attack on Recommender Systems

  • Griffith University(格里菲斯大学)
  • Edith Cowan University(伊迪丝·考恩大学)
  • The University of Queensland(昆士兰大学)
  • HUTECH University(胡志明市工业大学)

机构由 AI 辅助整理,请以论文原文为准。

Quoc Viet Nguyen, Trinh Pham, Viet Huynh, Hongzhi Yin, Quoc Viet Hung Nguyen, Bay Vo, Thanh Tam Nguyen

AI总结:

针对现有推荐系统托攻击适应性差、易被检测的问题,提出智能体组群攻击系统AGAS,通过协调器指挥角色切换的智能体组自适应提升目标物品,在同等预算下更高效且不易被检测。

AI中文摘要:

推荐系统已成为现代在线平台的核心基础设施,能够大规模地个性化内容,并强烈影响用户看到、点击和购买的内容。然而,这种对用户交互的依赖也使其面临托攻击(shilling attacks)的威胁,恶意行为者可以注入虚假用户画像来扭曲物品排名并控制可见性。现有攻击方法通常依赖于针对特定目标的微调或固定的画像模板,这使得它们要么难以适应不同的受害者,要么更容易被检测到。为了克服这些局限性,我们提出了智能体组群攻击系统(Agentic Group Attack System, AGAS),这是一种协同的托攻击框架,其中中央协调器(Coordinator)指挥一组角色切换的工作智能体,以自适应地提升目标物品在不同受害者群体中的排名。当进展停滞或抑制信号增加时,协调器会动态调整策略,而工作智能体则追求共同目标,并在活跃与不活跃角色之间切换以避免重复模式。在相同的攻击预算和评估协议下,AGAS在目标提升方面持续超越强基线方法,同时更好地保持良性推荐质量,削弱代表性检测器,并实现比先前攻击更高的效率。这些发现还强调,防御推荐系统可能需要能够应对自适应托攻击活动的机制,而不仅仅是孤立的虚假画像注入。我们的代码可在以下网址获取:此https链接。

英文摘要:

Recommender systems have become core infrastructure for modern online platforms, personalizing content at scale and strongly influencing what users see, click on, and purchase. However, this dependence on user interaction also exposes them to shilling attacks, where malicious actors can inject fake profiles to distort item rankings and control visibility. Existing attacks often rely on target-specific fine-tuning or fixed profile templates, making them either difficult to adapt to different victims or easier to detect. To overcome these limitations, we propose the Agentic Group Attack System (AGAS), a coordinated shilling framework where a central Coordinator directs a group of role-switching worker agents to adaptively promote a target item across different victim families. The Coordinator dynamically adjusts the strategy when progress stalls or suppression signals increase, while workers pursue a shared objective and switch between active and inactive roles to avoid repetitive patterns. Under the same attack budgets and evaluation protocols, AGAS consistently surpasses strong baselines in target promotion while better preserving benign recommendation quality, weakening representative detectors, and achieving higher efficiency than prior attacks. These findings also emphasize that defending recommender systems may require mechanisms that can handle adaptive shilling campaigns, not just isolated fake-profile injections. Our code is available at https://github.com/phkhanhtrinh23/AGAS.

补充信息

↑