{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T13:23:09Z","timestamp":1777987389709,"version":"3.51.4"},"reference-count":53,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172331"],"award-info":[{"award-number":["62172331"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["300102404301"],"award-info":[{"award-number":["300102404301"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.eswa.2026.132419","type":"journal-article","created":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T08:29:10Z","timestamp":1775896150000},"page":"132419","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Shoot the arrow at the target: Personalized adversarial defense driven by dynamic rewards"],"prefix":"10.1016","volume":"322","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-5453-7885","authenticated-orcid":false,"given":"Kexin","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5717-6196","authenticated-orcid":false,"given":"Zhihai","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-2146-5992","authenticated-orcid":false,"given":"Min","family":"Xue","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruping","family":"Zou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiquan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132419_bib0001","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2025.104468","article-title":"Protecting machine learning from poisoning attacks: A risk-based approach","volume":"155","author":"Bena","year":"2025","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132419_bib0002","series-title":"Proceedings of 19th international joint conference on artificial intelligence","first-page":"17","article-title":"Limited knowledge shilling attacks in collaborative filtering systems","author":"Burke","year":"2005"},{"key":"10.1016\/j.eswa.2026.132419_bib0003","series-title":"Proceedings of the 12th ACM SIGKDD international conference on knowledge discovery and data mining","first-page":"542","article-title":"Classification features for attack detection in collaborative recommender systems","author":"Burke","year":"2006"},{"key":"10.1016\/j.eswa.2026.132419_bib0004","series-title":"Proceedings of the 17th ACM conference on recommender systems","first-page":"245","article-title":"Adversarial collaborative filtering for free","author":"Chen","year":"2023"},{"key":"10.1016\/j.eswa.2026.132419_bib0005","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3439729","article-title":"A survey on adversarial recommender systems: from attack\/defense strategies to generative adversarial networks","volume":"54","author":"Deldjoo","year":"2021","journal-title":"ACM Computing Surveys"},{"key":"10.1016\/j.eswa.2026.132419_bib0006","series-title":"ICDE","first-page":"1583","article-title":"Attacking black-box recommendations via copying cross-domain profiles","author":"Fan","year":"2021"},{"key":"10.1016\/j.eswa.2026.132419_bib0007","doi-asserted-by":"crossref","first-page":"628","DOI":"10.1109\/9.751365","article-title":"Constrained dynamic programming with two discount factors: Applications and an algorithm","volume":"44","author":"Feinberg","year":"1999","journal-title":"IEEE Transactions on Automatic Control"},{"key":"10.1016\/j.eswa.2026.132419_bib0008","doi-asserted-by":"crossref","first-page":"889","DOI":"10.1109\/TKDE.2025.3639434","article-title":"Attacks and detections in recommender systems: A comprehensive analysis for models, progresses, and trends","volume":"38","author":"Feng","year":"2026","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"10.1016\/j.eswa.2026.132419_bib0009","series-title":"CCNC","first-page":"282","article-title":"FilmTrust: Movie recommendations using trust in web-based social networks","author":"Golbeck","year":"2006"},{"key":"10.1016\/j.eswa.2026.132419_bib0010","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2827872","article-title":"The movielens datasets: History and context","volume":"5","author":"Harper","year":"2015","journal-title":"ACM Transactions on Interactive Intelligent Systems"},{"key":"10.1016\/j.eswa.2026.132419_bib0011","series-title":"ACM SIGIR","first-page":"639","article-title":"LightGCN: Simplifying and powering graph convolution network for recommendation","author":"He","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0012","series-title":"ACM SIGIR","first-page":"355","article-title":"Adversarial personalized ranking for recommendation","author":"He","year":"2018"},{"key":"10.1016\/j.eswa.2026.132419_bib0013","series-title":"NDSS","first-page":"1","article-title":"Data to deep learning based recommender systems","author":"Huang","year":"2021"},{"key":"10.1016\/j.eswa.2026.132419_bib0014","series-title":"Proceedings of the 34th international conference on machine learning","first-page":"1885","article-title":"Understanding black-box predictions via influence functions","author":"Koh","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0015","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1109\/MC.2009.263","article-title":"Matrix factorization techniques for recommender systems","volume":"42","author":"Koren","year":"2009","journal-title":"Computer"},{"key":"10.1016\/j.eswa.2026.132419_bib0016","series-title":"Proceedings of the 13th international conference on world wide web","first-page":"393","article-title":"Shilling recommender systems for fun and profit","author":"Lam","year":"2004"},{"key":"10.1016\/j.eswa.2026.132419_bib0017","first-page":"565","article-title":"Robust statistics-the approach based on influence functions","volume":"35","author":"Law","year":"1986","journal-title":"Journal of the Royal Statistical Society Series D: The Statistician"},{"key":"10.1016\/j.eswa.2026.132419_bib0018","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.116967","article-title":"Information retrieval from scientific abstract and citation databases: A query-by-documents approach based on Monte-Carlo sampling","volume":"199","author":"Lechtenberg","year":"2022","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132419_bib0019","series-title":"ICDE","first-page":"2595","article-title":"Large-scale fake click detection for e-commerce recommendation systems","author":"Li","year":"2021"},{"key":"10.1016\/j.eswa.2026.132419_bib0020","series-title":"Proceedings of the 13th international conference on web search and data mining","first-page":"349","article-title":"Adversarial learning to compare: Self-attentive prospective customer recommendation in location based social networks","author":"Li","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0021","series-title":"Proceedings of the web conference 2021","first-page":"624","article-title":"User-oriented fairness in recommendation","author":"Li","year":"2021"},{"key":"10.1016\/j.eswa.2026.132419_bib0022","first-page":"1","article-title":"Defending federated recommender systems against untargeted attacks: A contribution-aware robust aggregation scheme","volume":"19","author":"Liang","year":"2025","journal-title":"ACM Transactions on Knowledge Discovery from Data"},{"key":"10.1016\/j.eswa.2026.132419_bib0023","series-title":"Proceedings of the 29th ACM international conference on information & knowledge management","first-page":"855","article-title":"Attacking recommender systems with augmented user profiles","author":"Lin","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.124476","article-title":"Stealthy attack on graph recommendation system","volume":"255","author":"Ma","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132419_bib0025","series-title":"Proceedings of the international conference on representation learning","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.eswa.2026.132419_bib0026","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121583","article-title":"POI recommendation for occasional groups based on hybrid graph neural networks","volume":"237","author":"Meng","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132419_bib0027","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1278366.1278372","article-title":"Toward trustworthy recommender systems: An analysis of attack models and algorithm robustness","volume":"7","author":"Mobasher","year":"2007","journal-title":"ACM Transactions on Internet Technology"},{"key":"10.1016\/j.eswa.2026.132419_bib0028","doi-asserted-by":"crossref","first-page":"362","DOI":"10.1109\/TCSS.2024.3465008","article-title":"Shilling attacks and fake reviews injection: Principles, models, and datasets","volume":"12","author":"Nawara","year":"2024","journal-title":"IEEE Transactions on Computational Social Systems"},{"key":"10.1016\/j.eswa.2026.132419_bib0029","unstructured":"Qiao S., Yuan W., Yu J., Chen T., Nguyen Q.V.H., & Yin H. (2025). Controllable and stealthy shilling attacks via dispersive latent diffusion. https:\/\/arxiv.org\/abs\/2508.01987."},{"key":"10.1016\/j.eswa.2026.132419_bib0030","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MIC.2017.72","article-title":"Two decades of recommender systems at amazon. com","volume":"21","author":"Smith","year":"2017","journal-title":"IEEE Internet Computing"},{"key":"10.1016\/j.eswa.2026.132419_bib0031","series-title":"ICDE","first-page":"157","article-title":"PoisonRec: An adaptive data poisoning framework for attacking black-box recommender systems","author":"Song","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0032","series-title":"Proceedings of the 14th ACM conference on recommender systems","first-page":"318","article-title":"Revisiting adversarially learned injection attacks against recommender systems","author":"Tang","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0033","series-title":"AAAI","first-page":"15206","article-title":"Revisiting item promotion in GNN-based collaborative filtering: A masked targeted topological attack perspective","author":"Wang","year":"2023"},{"key":"10.1016\/j.eswa.2026.132419_bib0034","series-title":"Proceedings of the 30th ACM SIGKDD conference on knowledge discovery and data mining","first-page":"3311","article-title":"Unveiling vulnerabilities of contrastive recommender systems to poisoning attacks","author":"Wang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132419_bib0035","unstructured":"Wang Z., Yu J., Gao M., Yuan W., Ye G., Sadiq S., & Yin H. (2024b). Poisoning attacks and defenses in recommender systems: A survey. https:\/\/arxiv.org\/abs\/2406.01022."},{"key":"10.1016\/j.eswa.2026.132419_bib0036","series-title":"Proceedings of the 27th ACM SIGKDD conference on knowledge discovery & data mining","first-page":"1830","article-title":"Triple adversarial learning for influence based poisoning attack in recommender systems","author":"Wu","year":"2021"},{"key":"10.1016\/j.eswa.2026.132419_bib0037","doi-asserted-by":"crossref","first-page":"11915","DOI":"10.1109\/TPAMI.2023.3274759","article-title":"Influence-driven data poisoning for robust recommender systems","volume":"45","author":"Wu","year":"2023","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.eswa.2026.132419_bib0038","first-page":"4425","article-title":"A survey on accuracy-oriented neural recommendation: From collaborative filtering to information-rich recommendation","volume":"35","author":"Wu","year":"2022","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"10.1016\/j.eswa.2026.132419_bib0039","doi-asserted-by":"crossref","first-page":"1595","DOI":"10.1109\/TCYB.2018.2877161","article-title":"HPSD: A hybrid Pu-learning-based spammer detection model for product reviews","volume":"50","author":"Wu","year":"2018","journal-title":"IEEE Transactions on Cybernetics"},{"key":"10.1016\/j.eswa.2026.132419_bib0040","series-title":"NDSS","article-title":"Fake co-visitation injection attacks to recommender systems","author":"Yang","year":"2017"},{"key":"10.1016\/j.eswa.2026.132419_bib0041","first-page":"879","article-title":"Probabilistic inference and trustworthiness evaluation of associative links toward malicious attack detection for online recommendations","volume":"19","author":"Yang","year":"2020","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.eswa.2026.132419_bib0042","series-title":"Proceedings of the 29th ACM SIGKDD conference on knowledge discovery and data mining","first-page":"5428","article-title":"UA-FedRec: Untargeted attack on federated news recommendation","author":"Yi","year":"2023"},{"key":"10.1016\/j.eswa.2026.132419_bib0043","series-title":"Proceedings of the 25th international conference on artificial intelligence and statistics","first-page":"1887","article-title":"A dual approach to constrained markov decision processes with entropy regularization","author":"Ying","year":"2023"},{"key":"10.1016\/j.eswa.2026.132419_bib0044","first-page":"1046","article-title":"Manipulating visually aware federated recommender systems and its countermeasures","volume":"42","author":"Yuan","year":"2023","journal-title":"ACM Transactions on Information Systems"},{"key":"10.1016\/j.eswa.2026.132419_bib0045","series-title":"RecSys","first-page":"59","article-title":"Defending substitution-based profile pollution attacks on sequential recommenders","author":"Yue","year":"2022"},{"key":"10.1016\/j.eswa.2026.132419_bib0046","series-title":"ACM SIGIR","first-page":"1860","article-title":"Adaptive graph integration for cross-domain recommendation via heterogeneous graph coordinators","author":"Zhang","year":"2025"},{"key":"10.1016\/j.eswa.2026.132419_bib0047","series-title":"ACM SIGIR","first-page":"1733","article-title":"LoRec: Combating poisons with large language model for robust sequential recommendation","author":"Zhang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132419_bib0048","series-title":"Neural information processing systems","article-title":"Understanding and improving adversarial collaborative filtering for robust recommendation","author":"Zhang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132419_bib0049","series-title":"ICLR","first-page":"1","article-title":"Soft robust MDPS and risk-sensitive MDPS: Equivalence, policy gradient, and sample complexity","author":"Zhang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132419_bib0050","series-title":"Proceedings of the web conference 2021","first-page":"3002","article-title":"graph embedding for recommendation against attribute inference attacks","author":"Zhang","year":"2021"},{"key":"10.1016\/j.eswa.2026.132419_bib0051","series-title":"WSDM","first-page":"1415","article-title":"PipAttack: Poisoning federated recommender systems for manipulating item promotion","author":"Zhang","year":"2022"},{"key":"10.1016\/j.eswa.2026.132419_bib0052","series-title":"ACM SIGIR","first-page":"689","article-title":"GCN-based user representation learning for unifying robust recommendation and fraudster detection","author":"Zhang","year":"2020"},{"key":"10.1016\/j.eswa.2026.132419_bib0053","series-title":"Proceedings of the 2021 ACM SIGSAC conference on computer and communications security","first-page":"51","article-title":"Reverse attack: Black-box attacks on collaborative recommendation","author":"Zhang","year":"2021"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426013321?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426013321?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T12:36:46Z","timestamp":1777984606000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426013321"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":53,"alternative-id":["S0957417426013321"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132419","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Shoot the arrow at the target: Personalized adversarial defense driven by dynamic rewards","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132419","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"132419"}}