As a prominent instance of vandalism edits, Wiki search poisoning for illicit promotion is a cybercrime in which the adversary aims at editing Wiki articles to promote illicit businesses through Wiki search results of relevant queries. In this paper, we report a study that, for the first time, shows that such stealthy blackhat SEO on Wiki can be automated. Our technique, called MAWSEO, employs adversarial revisions to achieve real-world cybercriminal objectives, including rank boosting, vandalism detection evasion, topic relevancy, semantic consistency, user awareness (but not alarming) of promotional content, etc. Our evaluation and user study demonstrate that MAWSEO is capable of effectively and efficiently generating adversarial vandalism edits, which can bypass state-of-the-art built-in Wiki vandalism detectors, and also get promotional content through to Wiki users without triggering their alarms. In addition, we investigated potential defense, including coherence based detection and adversarial training of vandalism detection, against our attack in the Wiki ecosystem.
翻译:作为恶意编辑的典型案例,针对非法推广的维基搜索投毒是一种网络犯罪行为,攻击者旨在通过编辑维基百科文章,使得相关查询的搜索结果优先展示非法商业推广内容。本文首次报道了一项研究表明,这种隐蔽的维基百科黑帽SEO手段可以实现自动化。我们提出的技术MAWSEO采用对抗性修订手段,达成真实网络犯罪目标,包括排名提升、破坏性检测规避、主题相关性、语义一致性、用户对推广内容的感知(但不引起警觉)等。实验评估与用户研究证明,MAWSEO能够高效生成对抗性恶意编辑,不仅可绕过现有最先进的维基内置破坏性检测器,还能将推广内容推送给用户而不触发其警觉机制。此外,我们针对维基生态系统中的攻击行为,探讨了潜在防御措施,包括基于一致性的检测与破坏性检测的对抗训练。