Targeted Data Poisoning Attack on News Recommendation System by Content Perturbation

by   Xudong Zhang, et al.

News Recommendation System(NRS) has become a fundamental technology to many online news services. Meanwhile, several studies show that recommendation systems(RS) are vulnerable to data poisoning attacks, and the attackers have the ability to mislead the system to perform as their desires. A widely studied attack approach, injecting fake users, can be applied on the NRS when the NRS is treated the same as the other systems whose items are fixed. However, in the NRS, as each item (i.e. news) is more informative, we propose a novel approach to poison the NRS, which is to perturb contents of some browsed news that results in the manipulation of the rank of the target news. Intuitively, an attack is useless if it is highly likely to be caught, i.e., exposed. To address this, we introduce a notion of the exposure risk and propose a novel problem of attacking a history news dataset by means of perturbations where the goal is to maximize the manipulation of the target news rank while keeping the risk of exposure under a given budget. We design a reinforcement learning framework, called TDP-CP, which contains a two-stage hierarchical model to reduce the searching space. Meanwhile, influence estimation is also applied to save the time on retraining the NRS for rewards. We test the performance of TDP-CP under three NRSs and on different target news. Our experiments show that TDP-CP can increase the rank of the target news successfully with a limited exposure budget.


Practical Data Poisoning Attack against Next-Item Recommendation

Online recommendation systems make use of a variety of information sourc...

PipAttack: Poisoning Federated Recommender Systems forManipulating Item Promotion

Due to the growing privacy concerns, decentralization emerges rapidly in...

UA-FedRec: Untargeted Attack on Federated News Recommendation

News recommendation is critical for personalized news distribution. Fede...

Manipulating Federated Recommender Systems: Poisoning with Synthetic Users and Its Countermeasures

Federated Recommender Systems (FedRecs) are considered privacy-preservin...

Beyond the Coverage of Information Spreading: Analytical and Empirical Evidence of Re-exposure in Large-scale Online Social Networks

Peer influence and social contagion are key denominators in the adoption...

Improving Few-shot News Recommendation via Cross-lingual Transfer

The cold-start problem has been commonly recognized in recommendation sy...

Lumen: A Machine Learning Framework to Expose Influence Cues in Text

Phishing and disinformation are popular social engineering attacks with ...

Please sign up or login with your details

Forgot password? Click here to reset