Modern recommender systems have seen substantial success, yet they remain vulnerable to malicious activities, notably poisoning attacks. These attacks involve injecting malicious data into the training datasets of RS, thereby compromising their integrity and manipulating recommendation outcomes for gaining illicit profits. This survey paper provides a systematic and up-to-date review of the research landscape on Poisoning Attacks against Recommendation (PAR). A novel and comprehensive taxonomy is proposed, categorizing existing PAR methodologies into three distinct categories: Component-Specific, Goal-Driven, and Capability Probing. For each category, we discuss its mechanism in detail, along with associated methods. Furthermore, this paper highlights potential future research avenues in this domain. Additionally, to facilitate and benchmark the empirical comparison of PAR, we introduce an open-source library, ARLib, which encompasses a comprehensive collection of PAR models and common datasets. The library is released at https://github.com/CoderWZW/ARLib.
翻译:现代推荐系统取得了显著成功,但仍易受到恶意活动(尤其是投毒攻击)的影响。此类攻击通过将恶意数据注入推荐系统的训练数据集,破坏其完整性并操纵推荐结果以获取非法利益。本文对推荐领域投毒攻击(PAR)的研究现状进行了系统且最新的综述。我们提出了一种新颖且全面的分类法,将现有PAR方法分为三类:组件特定型、目标驱动型与能力探测型。针对每类方法,本文详细阐述了其机制及相关对应方法。此外,本文指出了该领域未来潜在的研究方向。同时,为促进PAR的实证比较与基准测试,我们引入了一个开源库ARLib,该库整合了全面的PAR模型与常用数据集。该库已在 https://github.com/CoderWZW/ARLib 发布。