Skip to main content
QUICK REVIEW

[Paper Review] Poisoning Attacks and Defenses in Recommender Systems: A Survey

Zongwei Wang, Junliang Yu|arXiv (Cornell University)|Jun 3, 2024
Spam and Phishing Detection4 citations
TL;DR

This survey presents a systematic pipeline for poisoning attacks in recommender systems, organizing attacks into four stages: defining goals, assessing capabilities, analyzing victim architecture, and implementing strategies. It also classifies defenses into data filtering and robust training, offering a comprehensive taxonomy to guide research on securing RS against evolving threats.

ABSTRACT

Modern recommender systems (RS) have profoundly enhanced user experience across digital platforms, yet they face significant threats from poisoning attacks. These attacks, aimed at manipulating recommendation outputs for unethical gains, exploit vulnerabilities in RS through injecting malicious data or intervening model training. This survey presents a unique perspective by examining these threats through the lens of an attacker, offering fresh insights into their mechanics and impacts. Concretely, we detail a systematic pipeline that encompasses four stages of a poisoning attack: setting attack goals, assessing attacker capabilities, analyzing victim architecture, and implementing poisoning strategies. The pipeline not only aligns with various attack tactics but also serves as a comprehensive taxonomy to pinpoint focuses of distinct poisoning attacks. Correspondingly, we further classify defensive strategies into two main categories: poisoning data filtering and robust training from the defender's perspective. Finally, we highlight existing limitations and suggest innovative directions for further exploration in this field.

Motivation & Objective

  • To address the growing threat of poisoning attacks that manipulate recommendation systems for unethical gains.
  • To provide a unified framework for understanding attacker strategies by organizing attacks into a systematic four-stage pipeline.
  • To classify and analyze existing defense mechanisms into two main categories: poisoning data filtering and robust training.
  • To identify critical research gaps and propose future directions for securing recommender systems against sophisticated, evolving attacks.

Proposed method

  • Proposes a four-stage attack pipeline: (1) setting attack goals, (2) assessing attacker capabilities (e.g., data access, model knowledge), (3) analyzing victim system architecture (e.g., collaborative filtering, deep learning), and (4) implementing tailored poisoning strategies.
  • Classifies poisoning attacks based on the attack pipeline stages, enabling a structured taxonomy of existing attack methods.
  • Categorizes defense strategies into two main types: (1) poisoning data filtering (e.g., anomaly detection via supervised, unsupervised, or confidence-based filtering), and (2) robust training (e.g., multi-model mutual enhancement, adaptive confidence learning, data augmentation).
  • Analyzes attack strategies based on data manipulation and gradient modification, highlighting architectural dependencies and stealth trade-offs.
  • Introduces the concept of data neutralization—injecting counteractive data to mitigate poisoning effects—as a novel, underexplored defense direction.
  • Advocates for adaptive learning in attack-defense co-evolution, simulating real-world cyber-arms race dynamics to improve resilience.

Experimental results

Research questions

  • RQ1How can poisoning attacks in recommender systems be systematically categorized based on attacker intent, capability, and system architecture?
  • RQ2What are the key vulnerabilities in centralized and decentralized recommender system architectures that enable effective poisoning attacks?
  • RQ3How do economic constraints and stealth requirements shape the design and effectiveness of poisoning attacks?
  • RQ4What are the most effective defense mechanisms for detecting and mitigating poisoning attacks in real-world RS deployments?
  • RQ5How can long-term and cumulative impacts of poisoning data be modeled and analyzed over time in evolving recommendation systems?

Key findings

  • The four-stage attack pipeline provides a comprehensive taxonomy that aligns with diverse attack tactics and enables systematic analysis of poisoning threats.
  • Traditional heuristic-based attacks (e.g., bandwagon, relation attacks) are increasingly detectable due to their static, predictable patterns.
  • Modern attacks are shifting toward architecture-aware strategies that exploit specific vulnerabilities in decentralized and centralized RS designs.
  • Defensive strategies based on data filtering (e.g., anomaly detection) and robust training (e.g., confidence-aware learning) are effective but face challenges in scalability and adaptability.
  • The long-term impact of poisoning data may diminish over time due to model retraining and data drift, suggesting a need for longitudinal vulnerability analysis.
  • Data neutralization—using counteractive data to offset poisoning effects—remains underexplored but holds promise as a novel defense mechanism.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.