Clustering-Based Enhancement for Fake User Profiles Generation in Recommender Systems
摘要
Recommender systems are effective tools for addressing the problem of information overload. However, the prevalence of recommender system has also attracted unscrupulous parties trying to exploit these systems for illegal profits. Among various types of attacks, shilling attacks are among the most persistent and profitable. In a shilling attack, the attacker misleads the recommender system by injecting a large number of well-designed fake user profiles into the system. However, many existing shilling attack models do not work as expected in the real world, they suffer from many issues such as narrow range of target models and poor invisibility. Hence, a novel clustering enhanced poisoning framework for generating fake user profiles (CEFP) is proposed in this study. The proposed poisoning framework is based on the Generative Adversarial Networks (GANs). Experiment results demonstrate that CEFP can effectively spoof the recommender system in comparison to traditional and deep learning-based attack models, while remaining nearly undetectable by detection models.