Sequential recommender systems stand out for their ability to capture users' dynamic interests and the patterns of item-to-item transitions. However, the inherent openness of sequential recommender systems renders them vulnerable to poisoning attacks, where fraudulent users are injected into the training data to manipulate learned patterns. Traditional defense strategies predominantly depend on predefined assumptions or rules extracted from specific known attacks, limiting their generalizability to unknown attack types. To solve the above problems, considering the rich open-world knowledge encapsulated in Large Language Models (LLMs), our research initially focuses on the capabilities of LLMs in the detection of unknown fraudulent activities within recommender systems, a strategy we denote as LLM4Dec. Empirical evaluations demonstrate the substantial capability of LLMs in identifying unknown fraudsters, leveraging their expansive, open-world knowledge. Building upon this, we propose the integration of LLMs into defense strategies to extend their effectiveness beyond the confines of known attacks. We propose LoRec, an advanced framework that employs LLM-Enhanced Calibration to strengthen the robustness of sequential recommender systems against poisoning attacks. LoRec integrates an LLM-enhanced CalibraTor (LCT) that refines the training process of sequential recommender systems with knowledge derived from LLMs, applying a user-wise reweighting to diminish the impact of fraudsters injected by attacks. By incorporating LLMs' open-world knowledge, the LCT effectively converts the limited, specific priors or rules into a more general pattern of fraudsters, offering improved defenses against poisoning attacks. Our comprehensive experiments validate that LoRec, as a general framework, significantly strengthens the robustness of sequential recommender systems.
翻译:序列推荐系统因其捕捉用户动态兴趣及项目间转换模式的能力而表现突出。然而,序列推荐系统固有的开放性使其容易遭受投毒攻击,攻击者通过向训练数据注入虚假用户来操纵学习到的模式。传统防御策略主要依赖于从特定已知攻击中提取的预设假设或规则,这限制了其对未知攻击类型的泛化能力。为解决上述问题,考虑到大语言模型(LLMs)中蕴含的丰富开放世界知识,本研究首先聚焦于LLMs在推荐系统中检测未知欺诈活动的能力,我们将其策略命名为LLM4Dec。实证评估表明,LLMs凭借其广泛的开放世界知识,在识别未知欺诈者方面展现出显著能力。在此基础上,我们提出将LLMs整合到防御策略中,以将其有效性扩展到已知攻击的边界之外。我们提出了LoRec,这是一个先进的框架,采用LLM增强校准来提升序列推荐系统对抗投毒攻击的鲁棒性。LoRec集成了LLM增强校准器(LCT),该校准器利用从LLMs中提取的知识优化序列推荐系统的训练过程,通过用户级重加权来削弱攻击注入的欺诈者影响。通过融入LLMs的开放世界知识,LCT有效地将有限的特定先验或规则转化为更通用的欺诈者模式,从而提供改进的投毒攻击防御。我们的综合实验验证了LoRec作为一个通用框架,能够显著增强序列推荐系统的鲁棒性。