In practice, users of a Recommender System (RS) fall into a few clusters based on their preferences. In this work, we conduct a systematic study on user-cluster targeted data poisoning attacks on Matrix Factorisation (MF) based RS, where an adversary injects fake users with falsely crafted user-item feedback to promote an item to a specific user cluster. We analyse how user and item feature matrices change after data poisoning attacks and identify the factors that influence the effectiveness of the attack on these feature matrices. We demonstrate that the adversary can easily target specific user clusters with minimal effort and that some items are more susceptible to attacks than others. Our theoretical analysis has been validated by the experimental results obtained from two real-world datasets. Our observations from the study could serve as a motivating point to design a more robust RS.
翻译:在实际应用中,推荐系统的用户会根据其偏好自然形成若干聚类。本文系统研究了基于矩阵分解的推荐系统中针对用户聚类的定向数据投毒攻击——攻击者通过注入伪造用户并构造虚假的用户-项目反馈,以将特定项目推广至目标用户聚类。我们分析了数据投毒攻击后用户和项目特征矩阵的变化规律,并识别了影响这些特征矩阵攻击效果的关键因素。研究表明,攻击者能够以极低成本轻易锁定特定用户聚类,且不同项目对攻击的敏感度存在显著差异。基于两个真实数据集的实验结果验证了本文理论分析的准确性。本研究的相关发现可为设计更具鲁棒性的推荐系统提供有价值的启发。