论文标题

通过内容扰动对新闻推荐系统的有针对性数据中毒攻击

Targeted Data Poisoning Attack on News Recommendation System by Content Perturbation

论文作者

Zhang, Xudong, Wang, Zan, Zhao, Jingke, Wang, Lanjun

论文摘要

新闻推荐系统(NRS)已成为许多在线新闻服务的基本技术。同时,几项研究表明,推荐系统(RS)容易受到数据中毒攻击的影响,并且攻击者有能力误导该系统作为其需求。当对NRS的处理与其他项目固定的其他系统相同时,可以在NRS上使用广泛研究的攻击方法,注射假用户。但是,在NRS中,随着每个项目(即新闻)更具信息性,我们提出了一种新颖的方法来毒化NRS,这是驱散一些浏览新闻的内容,从而导致操纵目标新闻等级。从直觉上讲,如果攻击很可能被捕获,即暴露于攻击是没有用的。为了解决这个问题,我们介绍了暴露风险的概念,并提出了一个新的问题,即通过扰动攻击历史新闻数据集的新问题是,目标是最大程度地利用目标新闻等级的操纵,同时将暴露风险保持在给定的预算下。我们设计了一个称为TDP-CP的增强学习框架,该框架包含一个两阶段的分层模型,以减少搜索空间。同时,还采用了影响估计来节省重新奖励NR的时间。我们在三个NRS和不同的目标新闻下测试TDP-CP的性能。我们的实验表明,TDP-CP可以通过有限的接触预算成功提高目标新闻的排名。

News Recommendation System(NRS) has become a fundamental technology to many online news services. Meanwhile, several studies show that recommendation systems(RS) are vulnerable to data poisoning attacks, and the attackers have the ability to mislead the system to perform as their desires. A widely studied attack approach, injecting fake users, can be applied on the NRS when the NRS is treated the same as the other systems whose items are fixed. However, in the NRS, as each item (i.e. news) is more informative, we propose a novel approach to poison the NRS, which is to perturb contents of some browsed news that results in the manipulation of the rank of the target news. Intuitively, an attack is useless if it is highly likely to be caught, i.e., exposed. To address this, we introduce a notion of the exposure risk and propose a novel problem of attacking a history news dataset by means of perturbations where the goal is to maximize the manipulation of the target news rank while keeping the risk of exposure under a given budget. We design a reinforcement learning framework, called TDP-CP, which contains a two-stage hierarchical model to reduce the searching space. Meanwhile, influence estimation is also applied to save the time on retraining the NRS for rewards. We test the performance of TDP-CP under three NRSs and on different target news. Our experiments show that TDP-CP can increase the rank of the target news successfully with a limited exposure budget.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源