<p>Shilling attacks pose a significant threat to the integrity and reliability of recommender systems by injecting fake user profiles to promote or demote targeted items. Existing generative approaches often suffer from unstable training dynamics and limited realism in the synthesized profiles. In this paper, we propose PGAN, a novel Penalized Generative Adversarial Network enhanced with latent space perturbations to generate high-quality, diverse, and undetectable shilling attack profiles. PGAN incorporates a gradient penalty to stabilize discriminator training and applies controlled noise perturbations in the generator’s latent space to improve robustness and attack diversity. We evaluate PGAN on real-world datasets and demonstrate that it consistently outperforms traditional statistical attacks and baseline GAN-based models across multiple evaluation metrics, including Hit Ratio@K, Prediction Shift, and attack success rate. Experimental results also confirm the realism of the generated profiles through similarity analysis with genuine users. Our proposed model outperforms traditional and state-of-the-art methods, achieving HR@10 scores of 0.2051 and 0.2076 on the MovieLens and Amazon datasets, respectively. </p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Penalized GANs with latent perturbation for robust shilling attack generation in recommender systems

  • Dina Nawara,
  • Rasha Kashef

摘要

Shilling attacks pose a significant threat to the integrity and reliability of recommender systems by injecting fake user profiles to promote or demote targeted items. Existing generative approaches often suffer from unstable training dynamics and limited realism in the synthesized profiles. In this paper, we propose PGAN, a novel Penalized Generative Adversarial Network enhanced with latent space perturbations to generate high-quality, diverse, and undetectable shilling attack profiles. PGAN incorporates a gradient penalty to stabilize discriminator training and applies controlled noise perturbations in the generator’s latent space to improve robustness and attack diversity. We evaluate PGAN on real-world datasets and demonstrate that it consistently outperforms traditional statistical attacks and baseline GAN-based models across multiple evaluation metrics, including Hit Ratio@K, Prediction Shift, and attack success rate. Experimental results also confirm the realism of the generated profiles through similarity analysis with genuine users. Our proposed model outperforms traditional and state-of-the-art methods, achieving HR@10 scores of 0.2051 and 0.2076 on the MovieLens and Amazon datasets, respectively.