A data poisoning attack method for recommendation system based on dynamic adaptation of data and model
Xiaosai Wang, Jintao Tang, Qinhang Xu, Ting Wang · 2023
Data poisoning attack has been one of the most prominent threats for data-driven machine learning model. Specifically, in the field of recommendation system, an attacker could manipulate recommendation results by injecting some crafted fake data into recommendation model. In this paper, a data poisoning attack method based on dynamic adaptation of data and model is proposed for the recommendation system, referred to as dynamic attack, which solves the problem that the fake data fails to keep aggressive due to difference between models. Experimental results on the two real datasets, MovieLens-100K and MovieLens-1M, show that dynamic attack outperforms existing heuristic-based attacks and the average attack success rate is increased by more than 10 times.