Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Zongwei, Yu, Junliang, Gao, Min, Yin, Hongzhi, Cui, Bin, Sadiq, Shazia
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911886550761472
author Wang, Zongwei
Yu, Junliang
Gao, Min
Yin, Hongzhi
Cui, Bin
Sadiq, Shazia
author_facet Wang, Zongwei
Yu, Junliang
Gao, Min
Yin, Hongzhi
Cui, Bin
Sadiq, Shazia
contents Contrastive learning (CL) has recently gained prominence in the domain of recommender systems due to its great ability to enhance recommendation accuracy and improve model robustness. Despite its advantages, this paper identifies a vulnerability of CL-based recommender systems that they are more susceptible to poisoning attacks aiming to promote individual items. Our analysis indicates that this vulnerability is attributed to the uniform spread of representations caused by the InfoNCE loss. Furthermore, theoretical and empirical evidence shows that optimizing this loss favors smooth spectral values of representations. This finding suggests that attackers could facilitate this optimization process of CL by encouraging a more uniform distribution of spectral values, thereby enhancing the degree of representation dispersion. With these insights, we attempt to reveal a potential poisoning attack against CL-based recommender systems, which encompasses a dual-objective framework: one that induces a smoother spectral value distribution to amplify the InfoNCE loss's inherent dispersion effect, named dispersion promotion; and the other that directly elevates the visibility of target items, named rank promotion. We validate the threats of our attack model through extensive experimentation on four datasets. By shedding light on these vulnerabilities, our goal is to advance the development of more robust CL-based recommender systems. The code is available at \url{https://github.com/CoderWZW/ARLib}.
format Preprint
id arxiv_https___arxiv_org_abs_2311_18244
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning Attacks
Wang, Zongwei
Yu, Junliang
Gao, Min
Yin, Hongzhi
Cui, Bin
Sadiq, Shazia
Information Retrieval
Cryptography and Security
Machine Learning
Contrastive learning (CL) has recently gained prominence in the domain of recommender systems due to its great ability to enhance recommendation accuracy and improve model robustness. Despite its advantages, this paper identifies a vulnerability of CL-based recommender systems that they are more susceptible to poisoning attacks aiming to promote individual items. Our analysis indicates that this vulnerability is attributed to the uniform spread of representations caused by the InfoNCE loss. Furthermore, theoretical and empirical evidence shows that optimizing this loss favors smooth spectral values of representations. This finding suggests that attackers could facilitate this optimization process of CL by encouraging a more uniform distribution of spectral values, thereby enhancing the degree of representation dispersion. With these insights, we attempt to reveal a potential poisoning attack against CL-based recommender systems, which encompasses a dual-objective framework: one that induces a smoother spectral value distribution to amplify the InfoNCE loss's inherent dispersion effect, named dispersion promotion; and the other that directly elevates the visibility of target items, named rank promotion. We validate the threats of our attack model through extensive experimentation on four datasets. By shedding light on these vulnerabilities, our goal is to advance the development of more robust CL-based recommender systems. The code is available at \url{https://github.com/CoderWZW/ARLib}.
title Unveiling Vulnerabilities of Contrastive Recommender Systems to Poisoning Attacks
topic Information Retrieval
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2311.18244