Exploring Recommendations Attacks Through Blind Optimization
摘要
Numerous studies have demonstrated various techniques for creating adversarial samples to exploit inherent or flawed behaviors in intelligent algorithms. However, many of these methods are intricate and may necessitate model- or data-specific information. This work introduces a novel approach to crafting adversarial samples, utilizing blind optimization algorithms combined with efficient population initialization methods. We apply this approach to evaluate the resilience of well-known recommendation algorithms in adversarial scenarios. Specifically, we conducted experiments using two recommendation systems featured in the Netflix Prize competition. Our primary objective was to inflate the ratings of a target movie, increasing the likelihood of it being recommended, by creating adversarial interactions (adversarial samples) within the network. Our evaluation results reveal that while the tested recommendation algorithms exhibit resilience to blind adversarial attacks, optimization-based methods can induce moderate shifts in predicted ratings, exposing subtle but exploitable vulnerabilities.