Recommendation system injection attack method and system based on uncertainty
By introducing uncertainty quantification mechanism and dynamic attack strategy optimization in the recommendation system, the problem of weakening the effect of poisoning attacks in dynamic environments is solved, and higher attack robustness and stability are achieved.
Patent Information
- Application Number
- CN202510145280.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-06-17
AI Technical Summary
The existing poisoning attack methods are difficult to maintain the attack effect when facing the dynamic environment of the recommendation system, and fail to effectively deal with the 'attack dilution effect', resulting in weakening of the attack effect and insufficient uncertainty estimates.
By introducing uncertainty quantification mechanisms, false user portraits are generated and perturbed operations are performed, attack strategies are dynamically adjusted, and the injection of poisoned attack samples is optimized to maintain or improve the effectiveness of poisoned attacks.
It enhances the attack robustness of the recommendation system in complex dynamic environments, effectively deals with the attack dilution effect, and improves the stability and concealment of poisoned attacks.
Smart Images

Figure CN120165898A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of the robustness of recommendation systems, and particularly to a method and system for injecting attacks on recommendation systems based on uncertainty. Background Art
[0002] With the rapid development of Internet technology, recommendation systems have been widely applied in multiple fields such as e-commerce, social media, and content platforms. By analyzing users' historical behaviors and preferences, the systems recommend products, content, or services that users may be interested in. However, the security and robustness of recommendation systems have increasingly attracted attention, especially their protection capabilities against malicious attacks.
[0003] In recent years, recommendation systems have faced various security threats, among which poisoning attack is an important attack method. Poisoning attack aims to manipulate the recommendation results by injecting maliciously constructed data samples into the recommendation system, so as to significantly improve the ranking of specific target items, thereby increasing their exposure rate and sales volume. However, with the continuous improvement of defense mechanisms, the effect of poisoning attack has gradually weakened, and this phenomenon is called the "attack dilution effect".
[0004] Although existing poisoning attack methods can improve the ranking of target items to a certain extent, in practical applications, the attack effect is often restricted by the "attack dilution effect". Specifically, it is manifested as follows: (1) The attack effect weakens: As the recommendation system continuously receives and injects clean samples, the original poisoning attack effect is gradually diluted, resulting in a smaller increase in the ranking of target items, or even the inability to achieve the expected attack goal. (2) Insufficient uncertainty estimation: When existing methods quantify the uncertainty of model prediction, they fail to effectively focus on target items, resulting in inconsistent uncertainty estimation results with the actual model confidence, and unable to accurately reflect the model's prediction confidence in target items. (3) Poor adaptability to dynamic environments: When the recommendation system faces dynamically changing user behaviors and data distributions, existing poisoning attack strategies are difficult to adjust quickly, lacking the ability to respond to environmental changes in real time, which further exacerbates the attack dilution effect.
[0005] Therefore, existing attack methods do not consider the problem of attack dilution effect. The attack methods may be effective in a short period, but considering the proportion of injected clean samples, the attack effect will be greatly weakened. Moreover, existing attack methods do not consider the problem of dynamic adjustment. Summary of the Invention
[0006] The embodiments of the present application provide a method and system for injection attacks on recommendation systems based on uncertainty. Aiming at the dilution effect of poisoning attacks in recommendation systems, an optimization method based on uncertainty estimation is proposed. By introducing an uncertainty quantification mechanism, the attack strategy is dynamically adjusted to maintain or enhance the effectiveness of poisoning attacks, thereby enhancing the attack robustness of recommendation systems in the face of complex dynamic environments.
[0007] To solve the above technical problems, in a first aspect, the embodiments of the present application provide a method for injection attacks on recommendation systems based on uncertainty, including the following steps: First, generate a fake user profile according to the attack model and the interaction data of real users and items; then, perform a perturbation operation on the fake user profile to introduce uncertainty, generate a new fake user profile, and perform uncertainty estimation to obtain an uncertainty score; next, update the fake user profile based on the uncertainty score to obtain an optimal fake user profile; finally, construct a dataset using real-world samples and the optimal fake user profile and inject the dataset into the victim recommendation model for training to reflect the impact of malicious users.
[0008] In some exemplary embodiments, generating a fake user profile according to the attack model and the interaction data of real users and items includes: Denote the interaction data of real users and items as D real , expressed as:
[0009] D real ={(u l , i j , r ij )}
[0010] where the initial set of users and items is: U = {u1, u2,..., u n}, I = {i1, i2,..., i n}; the target item i t ∈ I is the target of the attack model;
[0011] Assume the profile of the fake user U f is P f , expressed as:
[0012] P f = M A (D real )
[0013] where M A represents any attack method.
[0014] In some exemplary embodiments, a perturbation operation is performed on the fake user profile to introduce uncertainty, generating a new fake user profile, and uncertainty estimation is carried out to obtain the uncertainty dynamics, including: for the fake user and its initial profile, performing multiple perturbation operations to generate new fake user profiles; for each perturbation, obtaining the prediction score of the target item; calculating the weighted variance of each sample based on the prediction score of the target item and the score weight; calculating the original output distribution of the model and the average distribution after perturbation, and calculating the KL divergence between the two; obtaining the uncertainty score based on the weighted variance of each sample and the KL divergence between the original output distribution of the model and the average distribution after perturbation.
[0015] In some exemplary embodiments, for the fake user and its initial profile, multiple perturbation operations are performed to generate new profiles, including:
[0016] For a given fake user u f ∈U f and its initial profile P, perform M perturbation operations; the perturbation operations include: removing randomly replacing with a new item set where C is the candidate set without the target item C = I\{i t}, generating a new fake user profile;
[0017] The new fake user profile is represented as:
[0018] P j =(P\R j )∪A j , j ∈ {1,..., M} where P is the initial profile corresponding to the fake user.
[0019] In some exemplary embodiments, the prediction score of the target item is as follows:
[0020]
[0021] where s j is the prediction score, i t is the target item, is the prediction function of the victim recommendation model, ∈ j is the added Gaussian noise.
[0022] In some exemplary embodiments, the calculation formula for the weighted variance of each sample is as follows:
[0023]
[0024] where s j is the prediction score, i t is the target item, M is the number of perturbation times, ωj is a fractional weight.
[0025] In some exemplary embodiments, the original output distribution of the model is p = {p k}, and the average distribution after perturbation is q = {q k}, as follows:
[0026]
[0027] The calculation formula of KL divergence is:
[0028]
[0029] where p k is the original output distribution of the model, and q k is the average distribution after perturbation;
[0030] The uncertainty score is the sum of the weighted variance and KL divergence, as follows:
[0031] U = Var + D KL (p||q)
[0032] where Var is the weighted variance of each sample, and D KL is the KL divergence between the original output distribution of the model and the average distribution after perturbation.
[0033] In some exemplary embodiments, based on the uncertainty score, the false user profile is updated to obtain the optimal false user profile, including:
[0034] By optimizing the false user profile, the optimal item combination is found to maximize the uncertainty of the score, as follows:
[0035]
[0036] where, is the optimal false user profile, P f is the profile of the false user, U is the set of items, U = {u1, u2,..., u n}.
[0037] In some exemplary embodiments, a dataset is constructed using real-world samples and the optimal false user profile, and the dataset is injected into the victim recommendation model for training, including:
[0038] After obtaining the optimal false user profile, a dataset D′ is constructed by combining real-world samples and the false user profile and injected into the victim recommendation model; where,
[0039] D′ = D ∪ D fake
[0040]
[0041] After injecting the malicious dataset D', the victim model M S is retrained on the dataset to reflect the impact of malicious users;
[0042] The training process includes defining a loss function, calculating gradients, and updating model parameters. The training steps are as follows:
[0043]
[0044] Calculate the loss by setting the regularization of BPR loss and L2 loss for all victim models, and update the gradients of the models as follows:
[0045]
[0046] where t represents the current training round.
[0047] In a second aspect, an injection attack system for a recommendation system based on uncertainty provided by an embodiment of the present application uses the injection attack method for a recommendation system based on uncertainty described in the above embodiment to enhance the attack robustness of the recommendation system in the face of a complex dynamic environment, including: a SpyUsers module and an uncertainty estimation module; wherein, the SpyUsers module acts as a spy user and gets as close as possible to real users through pre-training, and then reflects the poisoning situation of the model through its own feedback; the uncertainty estimation module is used to measure the uncertainty of the model and find the part with the highest uncertainty for key attacks.
[0048] The technical solutions provided by the embodiments of the present application have at least the following advantages:
[0049] An injection attack method and system for a recommendation system based on uncertainty provided by an embodiment of the present application includes the following steps: First, generate a false user profile according to the attack model and the interaction data of real users and items; then, perform a perturbation operation on the false user profile to trigger uncertainty, generate a new false user profile, and perform uncertainty estimation to obtain an uncertainty score; next, update the false user profile based on the uncertainty score to obtain an optimal false user profile; finally, construct a dataset using real-world samples and the optimal false user profile and inject the dataset into the victim recommendation model for training to reflect the impact of malicious users. The injection attack method and system for a recommendation system based on uncertainty provided by the present application introduce an uncertainty quantification mechanism and dynamically adjust the attack strategy to maintain or improve the effectiveness of the poisoning attack, thereby enhancing the attack robustness of the recommendation system in the face of a complex dynamic environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not constitute a limitation on the embodiments. Unless otherwise stated, the figures in the drawings do not constitute a scale limitation.
[0051] Figure 1 The flowchart of a method for injecting attacks on a recommendation system based on uncertainty provided by an embodiment of the present application.
[0052] Figure 2 The flowchart of a method for injecting attacks on a recommendation system based on uncertainty provided by an embodiment of the present application.
[0053] Figure 3 The result diagram of a method for injecting attacks on a recommendation system based on uncertainty provided by an embodiment of the present application. Detailed implementation manners
[0054] As can be seen from the background art, however, the existing attack methods do not consider the problem of attack dilution effect. The attack methods may be effective in a short period of time, but considering the proportion of clean samples injected, the attack effect will be greatly weakened. Moreover, the existing attack methods do not consider the problem of dynamic adjustment.
[0055] The recommendation system (RS) has made remarkable progress over the years, thanks to the advancement of algorithmic techniques and computing power. Traditional methods mainly adopt collaborative filtering (CF) methods, among which matrix factorization (MF) is a prominent technique that decomposes the user-item interaction matrix into latent user and item factors. Although MF has demonstrated effectiveness on large datasets, it faces the cold start problem, that is, new users or items lack sufficient historical data. The rise of deep learning has further transformed RS, leading to the application of advanced techniques in different environments.
[0056] With the popularity of graph data, many graph-based recommendation methods have been developed, mostly based on GNN methods and their different variants. For example, by propagating embeddings on the graph structure to capture high-order connections in user-item interactions. There are also related techniques that propose a novel recommendation method that uses a knowledge graph to propagate user preferences, enhancing the ability to capture complex relationships between users and items.
[0057] The recommendation system plays an important role in predicting user interests. At the same time, however, the vulnerability of the recommendation system has been questioned. For the poisoning attack on the recommendation system, the poisoning attack aims at the target item and generates false user profiles to increase or decrease the ranking of the target item. With the development of the recommendation model, the injection attack model is also changing.
[0058] Specifically, poisoning attack is an attack method against machine learning models. By injecting carefully designed malicious samples into the training data, it affects the training process of the model, thereby manipulating the output results of the model. In a recommendation system, the poisoning attack aims to change the recommendation results and improve the ranking or exposure rate of specific target items. The attack dilution effect refers to the phenomenon that during the poisoning attack, as clean (harmless) samples are continuously injected, the attack effect gradually weakens. This effect causes the attacker to need to invest more resources to maintain the attack effect, reducing the practicality and efficiency of the attack. Uncertainty Estimation refers to the method in machine learning for measuring the degree of uncertainty of the model's prediction results. Common uncertainty estimation methods include Monte Carlo Dropout, Bayesian Neural Networks, and Ensemble Learning, etc.
[0059] Early poisoning attacks mainly focused on heuristic methods, such as random attacks and average attacks. With the use of the NCF recommendation model architecture, the vulnerability of the NCF model was explored. In addition, due to the development of GNNs, many recommendation models are related to graph structures, and the attacks have accordingly shifted to graph-based models and achieved good results.
[0060] In recent years, the attack methods have focused on specific structures or extreme resources to improve concealment. With the rise of self-supervised learning, many recommendation models have utilized the characteristics of self-supervised learning. This has also led to the development of attacks against self-supervised models. This attack method targets the pre-training part of the model and attempts to manipulate the upstream data to affect the downstream recommendation task. In addition to targeting specific models, other attack models have also explored attacks in extreme environments.
[0061] However, the existing attack methods do not consider the attack dilution effect problem. The attack methods may be effective in a short period, but considering the proportion of injected clean samples, the attack effect will be greatly weakened.
[0062] It is worth noting that reinforcement learning is related to dynamic adjustment. Although dynamic adjustment has been concerned, black-box attacks usually limit the information from the model. These dynamic adjustment frameworks are usually based on strong assumptions, that is, this application can actually obtain the situation of the attacked model or view the recommendation list of the proxy model. But in the real world, these acquisition conditions are very high and the assumptions often do not hold.
[0063] To solve the above technical problems, the embodiments of the present application provide a method and system for injecting attacks on a recommendation system based on uncertainty. The method includes the following steps: First, generate a false user profile according to the attack model and the interaction data of real users and items. Then, perform a perturbation operation on the false user profile to introduce uncertainty, generate a new false user profile, and perform uncertainty estimation to obtain an uncertainty score. Next, update the false user profile based on the uncertainty score to obtain an optimal false user profile. Finally, construct a data set using real-world samples and the optimal false user profile and inject the data set into the victim recommendation model for training to reflect the impact of malicious users. The present application provides a method and system for injecting attacks on a recommendation system based on uncertainty, aiming to solve the following technical problems: (1) Propose an effective method for quantifying the attack dilution effect: By redesigning the uncertainty estimation mechanism and focusing on the prediction uncertainty of target items, accurately quantify the confidence change of the recommendation system for target items in a dynamic environment. (2) Develop a poisoning attack strategy based on uncertainty optimization: Utilize the uncertainty estimation results to dynamically adjust the injection strategy of poisoning samples to counteract the dilution effect of clean samples and maintain or enhance the effectiveness of the poisoning attack. (3) Enhance the adaptability and robustness of the attack strategy: By introducing an uncertainty-driven attack optimization method, improve the adaptability and robustness of the poisoning attack in different dynamic environments to ensure that the attack effect is still significant under various data injection conditions. (4) Verify the optimized uncertainty estimation method: Through systematic experimental design and data analysis, verify the correlation between the proposed uncertainty quantification method and the attack effect, and further optimize the method to achieve higher accuracy and stability.
[0064] The embodiments of the present application will be described in detail below with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present application, many technical details are proposed to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented.
[0065] Refer to Figure 1 , the embodiments of the present application provide a method for injecting attacks on a recommendation system based on uncertainty, including the following steps:
[0066] Step S101: Generate a false user profile according to the attack model and the interaction data of real users and items.
[0067] Step S102: Perform a perturbation operation on the false user profile to introduce uncertainty, generate a new false user profile, and perform uncertainty estimation to obtain an uncertainty score.
[0068] Step S103: Update the false user profile based on the uncertainty score to obtain the optimal false user profile.
[0069] Step S104: Construct a data set using real-world samples and the optimal false user profile, and inject the data set into the victim recommendation model for training to reflect the impact of malicious users.
[0070] This application proposes an optimization method based on uncertainty estimation for the dilution effect of poisoning attacks in recommendation systems. By introducing an uncertainty quantification mechanism, the attack strategy is dynamically adjusted to maintain or enhance the effectiveness of poisoning attacks, thereby enhancing the attack robustness of the recommendation system in the face of complex dynamic environments.
[0071] The flowchart of the uncertainty-based recommendation system injection attack method provided by the embodiments of this application is as Figure 2 shown. In the first step, generate a false user profile. The initial sets of users and items are U = {u1, u2,..., u n}, I = {i1, i2,..., i n}, and the target item i t ∈ I is the target of the attack model. Therefore, the researchers hope to improve the score of this target item by perturbing the false user profile.
[0072] In some embodiments, according to the attack model and the interaction data of real users and items, generate a false user profile, including: Denote the interaction data of real users and items as D real , expressed as:
[0073] D real = {(u i , i j , r ij )}
[0074] The initial of the false user profile is generated according to the attack model M A and the interaction data of real users and items. Assume that there is a part of real interaction data D real , that is, the rating data of users for items.
[0075] Assume that the profile of the false user U f is P f , expressed as:
[0076] P f = M A (D real )
[0077] Among them, M A represents any attack method. Since the method of this application is decoupled, MA It can represent traditional heuristic attacks (such as RandomAttack) or optimized attacks.
[0078] Second, perform uncertainty estimation. In some embodiments, a perturbation operation is performed on the false user profile to introduce uncertainty, generating a new false user profile, and uncertainty estimation is performed to obtain an uncertainty dynamics, including: for a false user and its initial profile, performing multiple perturbation operations to generate new false user profiles; for each perturbation, obtaining the prediction score of the target item; calculating the weighted variance of each sample based on the prediction score of the target item and the score weight; calculating the original output distribution of the model and the average distribution after perturbation, and calculating the KL divergence between the two; obtaining an uncertainty score based on the weighted variance of each sample and the KL divergence between the original output distribution of the model and the average distribution after perturbation.
[0079] In some embodiments, for a false user and its initial profile, performing multiple perturbation operations to generate new profiles, including:
[0080] For a given false user u f ∈U f and its initial profile P, performing M perturbation operations; the perturbation operations include: removing randomly replacing with a new item set where C is the candidate set after removing the target item C = I\{i t}, generating a new false user profile;
[0081] The new false user profile is represented as:
[0082] P j =(P\R j )∪A j , j ∈ {1,..., M}
[0083] where P is the initial profile corresponding to the false user.
[0084] In some exemplary embodiments, the prediction score of the target item is as follows:
[0085]
[0086] where s j is the prediction score, i t is the target item, is the prediction function of the victim recommendation model, ∈ j is the added Gaussian noise.
[0087] In some exemplary embodiments, the calculation formula for the weighted variance of each sample is as follows:
[0088]
[0089] Among them, s j is the predicted score, i t is the target item, M is the number of perturbations. The larger M is, the higher the time consumption, but the more accurate the uncertainty calculation. ω j is the score weight.
[0090] In some embodiments, the original output distribution of the model is p = {p k}, and the average distribution after perturbation is q = {q k}, as follows:
[0091]
[0092] The calculation formula of KL divergence is:
[0093]
[0094] Among them, p k is the original output distribution of the model, and q k is the average distribution after perturbation.
[0095] The uncertainty score is the sum of the weighted variance and KL divergence, as follows:
[0096] U = Var + D KL (p||q)
[0097] Among them, Var is the weighted variance of each sample, and D KL is the KL divergence between the original output distribution of the model and the average distribution after perturbation.
[0098] Thirdly, update the fake user profile. Based on the above uncertainty estimation, this application proposes a user profile update strategy, aiming to maximize the uncertainty of the target item by selecting an item combination and thus achieving an attack effect. To maximize the prediction uncertainty of the target item i t , this application finds the optimal item combination by optimizing the fake user profile to maximize the uncertainty of the score.
[0099] In some embodiments, based on the uncertainty score, update the fake user profile to obtain the optimal fake user profile, including:
[0100] Find the optimal item combination by optimizing the fake user profile to maximize the uncertainty of the score, as follows:
[0101]
[0102] Among them, For the optimal fake user profile, P f is the profile of the fake user, U is the set of items, U = {u1, u2,..., u n}.
[0103] Fourth step, fake data injection. In some embodiments, a dataset is constructed using real-world samples and the optimal fake user profile, and the dataset is injected into the victim recommendation model for training, including:
[0104] After obtaining the optimal fake user profile, a dataset D′ is constructed by combining real-world samples and the fake user profile, and it is injected into the victim recommendation model; where,
[0105] D′ = D ∪ D fake
[0106]
[0107] After injecting the malicious dataset D′, the victim model M S is retrained on the dataset to reflect the impact of malicious users;
[0108] The training process includes defining a loss function, calculating gradients, and updating model parameters. The training steps are as follows:
[0109]
[0110] Here is a black-box attack. Therefore, in this application, the regularization of BPR loss and L2 loss is uniformly set for all victim models to calculate the loss, update the gradients of the models, and the schematic diagram of the final result is as Figure 3 shown. The calculation formula for updating the model gradients is as follows:
[0111]
[0112] where t represents the current training round.
[0113] In addition, the embodiments of this application also provide a recommendation system injection attack system based on uncertainty. Using the recommendation system injection attack method based on uncertainty described in the above embodiments, the attack robustness of the recommendation system in the face of a complex dynamic environment is enhanced, including: the SpyUsers module and the uncertainty estimation module; where the SpyUsers module acts as a spy user and gets as close as possible to real users through pre-training, and then reflects the poisoning situation of the model through its own feedback; the uncertainty estimation module is used to measure the uncertainty of the model and find the part with the highest uncertainty for key attacks.
[0114] This application monitors the attack effect by introducing the SpyUser mechanism, which can provide real-time feedback on the attack effect for precise dynamic adjustment. This application also measures the uncertainty of the model through an uncertainty estimation module and focuses on attacking the parts with the highest uncertainty.
[0115] The method and system for injection attack of a recommendation system based on uncertainty provided by the embodiments of this application can, on the one hand, enhance the security and robustness of the recommendation system. The recommendation system is an important infrastructure in multiple industries such as e-commerce and social platforms. Being able to effectively deal with malicious attacks (such as poisoning attacks) is crucial for protecting the user experience and commercial value of the platform. The method of this application enhances the system's protection ability by introducing uncertainty estimation and dynamic optimization mechanisms, can effectively cope with complex dynamic environments and attack dilution effects, and protect the platform from attacks. On the other hand, this method can be dynamically adjusted and has strong adaptability. Traditional attack methods are usually static. Once an attack is identified, it is difficult to quickly adjust the defense measures. However, the innovative design of this application can dynamically adjust the injection strategy during the attack process, improving the concealment and persistence of the attack, enabling the system to handle various data injection situations, and enhancing the long-term attack protection ability. In addition, the method of this application has a broad market prospect. With the increasingly widespread application of recommendation algorithms and machine learning models in business, how to protect these systems from malicious attacks will be a continuous and increasingly important issue. The patent of this application not only has technological innovation but also has a strong market application prospect and can bring commercial value in multiple fields.
[0116] Compared with the prior art, the advantages of this application are as follows:
[0117] (1) This application measures the weaknesses of the model by designing an uncertainty estimation module for targeted attacks. Previous solutions attacked directly without measurement.
[0118] (2) The method of this application can dynamically adjust the attack strategy; conventional training cannot cope with the attack dilution effect. In traditional model training, the training data is static and does not consider the attack interference of the data. In actual applications, the recommendation system faces a dynamic and changing data environment, and attackers often manipulate the recommendation results by continuously injecting malicious samples. The method of this application can dynamically adjust the attack strategy to respond to changes in the attack effect in real time during the training process and prevent the dilution of the attack effect.
[0119] (3) The method of this application can improve the attack effect; conventional training ignores the confidence changes of the model for different recommended items, while the solution of this application can accurately quantify the prediction uncertainty of the recommendation system and dynamically adjust the attack strategy according to the uncertainty by introducing an uncertainty estimation mechanism. This method can not only improve the attack effect, but also enhance the adaptability and robustness of the system in a complex dynamic environment.
[0120] With the above technical solutions, the embodiments of this application provide an uncertainty-based injection attack method and system for a recommendation system. The method includes the following steps: First, generate a fake user profile according to the attack model and the interaction data of real users and items; then, perform a perturbation operation on the fake user profile to introduce uncertainty, generate a new fake user profile, and perform uncertainty estimation to obtain an uncertainty score; next, update the fake user profile based on the uncertainty score to obtain an optimal fake user profile; finally, construct a data set using real-world samples and the optimal fake user profile, and inject the data set into the victim recommendation model for training to reflect the influence of malicious users. The uncertainty-based injection attack method and system provided by this application can dynamically adjust the attack strategy by introducing an uncertainty quantification mechanism to maintain or improve the effectiveness of the poisoning attack, thereby enhancing the attack robustness of the recommendation system in the face of a complex dynamic environment.
[0121] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing this application, and in practical applications, various changes can be made in form and details without departing from the spirit and scope of this application. Any person skilled in the art can make their own changes and modifications without departing from the spirit and scope of this application. Therefore, the protection scope of this application should be subject to the scope defined by the claims.
Claims
1. A recommendation system injection attack method based on uncertainty, characterized in that: The following steps are involved: Generate fake user portraits based on the attack model and the interaction data between real users and items; Performing a perturbation operation on the false user profile to induce uncertainty, generating a new false user profile, and performing uncertainty estimation to obtain an uncertainty score; Based on the uncertainty score, the false user portrait is updated to obtain an optimal false user portrait; A dataset is constructed using real-world samples and optimal fake user portraits, and the dataset is injected into the victim recommendation model for training to reflect the influence of malicious users.
2. The recommendation system injection attack method based on uncertainty according to claim 1 is characterized in that: Generate fake user portraits based on the attack model and real user-item interaction data, including: The interaction data between real users and items is recorded as D real , expressed as: D real ={(u i ,i j ,r ij )} The initial set of users and items is: U = {u1, u2, ..., u n }, I = {i1, i2, ..., i n }; target item i t ∈I is the target of the attack model; Assume that the fake user U f The portrait is P f , expressed as: P f =M A (D real ) Among them, M A Represents any attack method.
3. The uncertainty-based recommendation system injection attack method according to claim 1, characterized in that: The false user profile is perturbed to induce uncertainty, a new false user profile is generated, and uncertainty estimation is performed to obtain uncertainty dynamics, including: For the fake user and its initial profile, multiple perturbations are performed to generate new fake user profiles; For each perturbation, obtain the predicted score of the target item; Based on the predicted score and score weight of the target item, calculate the weighted variance of each sample; Calculate the original output distribution of the model and the average distribution after perturbation, and calculate the KL divergence between the two; The uncertainty score is obtained based on the weighted variance of each sample and the KL divergence between the original output distribution of the model and the perturbed mean distribution.
4. The recommendation system injection attack method based on uncertainty according to claim 3 is characterized in that: For the fake user and its initial profile, multiple perturbation operations are performed to generate a new profile, including: For a given fake user u f ∈U f and its initial image P, and perform M perturbation operations; the perturbation operations include: removing Randomly replace with a new set of items Among them, C is the candidate set without the target item C = I\{i t }, generate new fake user portraits; The new fake user profile is represented as: P j =(P\R j )∪A j ,j∈{1,...,M} Among them, P is the initial portrait corresponding to the fake user.
5. The uncertainty-based recommendation system injection attack method according to claim 4 is characterized in that: The predicted scores for the target items are shown below: Among them, s j is the prediction score, i t For the target item, is the prediction function of the victim recommendation model, ∈ j is the Gaussian noise added.
6. The uncertainty-based recommendation system injection attack method according to claim 4 is characterized in that: The calculation formula for the weighted variance of each sample is as follows: Among them, s j is the prediction score, i t is the target item, M is the number of disturbances, ω j is the score weight.
7. The recommendation system injection attack method based on uncertainty according to claim 4 is characterized in that: The original output distribution of the model is p = {p k }, the average distribution after disturbance is q={q k }, as shown below: The calculation formula of KL divergence is: Among them, p k is the original output distribution of the model, q k is the average distribution after disturbance; The uncertainty score is the sum of the weighted variance and the KL divergence as follows: U=Var+D KL (p||q) Among them, Var is the weighted variance of each sample, D KL is the KL divergence between the original output distribution of the model and the perturbed average distribution.
8. The uncertainty-based recommendation system injection attack method according to claim 1, characterized in that: Based on the uncertainty score, the false user profile is updated to obtain an optimal false user profile, including: By optimizing the fake user portrait, we find the best combination of items to maximize the uncertainty of the rating, as shown below: in, is the optimal fake user portrait, P f is the portrait of the fake user, U is the set of items, U = {u1, u2, ..., u n }.
9. The uncertainty-based recommendation system injection attack method according to claim 1, characterized in that: A dataset is constructed using real-world samples and optimal fake user portraits, and the dataset is injected into the victim recommendation model for training, including: After obtaining the optimal fake user portrait, the real-world samples and the fake user portrait are constructed into a dataset D′ and injected into the victim recommendation model; D′=D∪D fake After injecting the malicious dataset D′, the victim model M S Retrain on the dataset to reflect the influence of malicious users; The training process includes defining the loss function, calculating the gradient, and updating the model parameters. The training steps are as follows: Set BPRloss and L2loss regularization for all victim models to calculate the loss and update the gradient of the model as follows: Where t represents the current training round number.
10. A recommendation system injection attack system based on uncertainty, which adopts the recommendation system injection attack method based on uncertainty as described in any one of claims 1 to 9 to enhance the attack robustness of the recommendation system in the face of complex dynamic environments, characterized in that: include: SpyUsers module and uncertainty estimation module; among them, The SpyUsers module acts as a spy user, and is as close to the real user as possible through pre-training, and then reflects the poisoning of the model through its own feedback; The uncertainty estimation module is used to measure the uncertainty of the model and find the part with the highest uncertainty for focused attack.