Pith. sign in

REVIEW 3 cited by

Poisoning Attacks and Defenses in Recommender Systems: A Survey

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2406.01022 v2 pith:5HQSMMYR submitted 2024-06-03 cs.CR cs.IR

Poisoning Attacks and Defenses in Recommender Systems: A Survey

classification cs.CR cs.IR
keywords poisoningattacksattackattackerdatafurtherperspectivepipeline
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

Modern recommender systems (RS) have profoundly enhanced user experience across digital platforms, yet they face significant threats from poisoning attacks. These attacks, aimed at manipulating recommendation outputs for unethical gains, exploit vulnerabilities in RS through injecting malicious data or intervening model training. This survey presents a unique perspective by examining these threats through the lens of an attacker, offering fresh insights into their mechanics and impacts. Concretely, we detail a systematic pipeline that encompasses four stages of a poisoning attack: setting attack goals, assessing attacker capabilities, analyzing victim architecture, and implementing poisoning strategies. The pipeline not only aligns with various attack tactics but also serves as a comprehensive taxonomy to pinpoint focuses of distinct poisoning attacks. Correspondingly, we further classify defensive strategies into two main categories: poisoning data filtering and robust training from the defender's perspective. Finally, we highlight existing limitations and suggest innovative directions for further exploration in this field.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Green-Red Watermarking for Recommender Systems

    cs.IR 2026-04 unverdicted novelty 7.0

    GREW uses a secret-key-driven green-red item partition and three ranking-integrated modules to embed verifiable watermarks in recommender systems that resist extraction attacks without data injection.

  2. Sharpness-Aware Poisoning: Enhancing Transferability of Injective Attacks on Recommender Systems

    cs.LG 2026-04 unverdicted novelty 6.0

    SharpAP enhances transferability of injective poisoning attacks on recommender systems by formulating them as a tri-level optimization that seeks and attacks an approximately worst-case victim model using sharpness-aw...

  3. VENOMREC: Cross-Modal Interactive Poisoning for Targeted Promotion in Multimodal LLM Recommender Systems

    cs.CR 2026-02 conditional novelty 6.0

    Synchronized text+image poisoning steers multimodal LLM recommenders to promote target items, reaching 0.73 mean exposure@20.