A Dual Defense Design Against Data Poisoning Attacks in Deep Learning-Based Recommendation Systems
Xiaocui Dang, Priyadarsi Nanda, Manoranjan Mohanty, Haiyu Deng · 2024
Deep learning is being extensively utilized across various domains, with deep learning-based recommendation systems gaining prominence due to their exceptional performance. However, these systems are vulnerable to data poisoning attacks, where adversaries introduce carefully crafted fake user ratings to compromise the integrity of the recommendation model. We propose a dual defense to address this threat. The first line of defense, termed active defense, preemptively reduces the system’s vulnerability to poisoning attacks by incorporating crafted regularization into the loss function. This approach diminishes the attacker’s impact while preserving system performance, thereby lowering the success rate of targeted attacks. To further enhance the system’s robustness, we introduce a Generative Adversarial Network (GAN) based detection model as a passive defense strategy to accurately identify and filter out poisoned data. Empirical evaluations on three distinct datasets demonstrate that our dual defense approach significantly enhances both the proactive defense and passive detection capabilities of recommendation systems, effectively countering data poisoning attacks.