{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T08:54:15Z","timestamp":1780044855111,"version":"3.53.1"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102335"],"award-info":[{"award-number":["62102335"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"General Research Funds from the Hong Kong Research Grants Council","award":["PolyU 15200021"],"award-info":[{"award-number":["PolyU 15200021"]}]},{"name":"General Research Funds from the Hong Kong Research Grants Council","award":["15207322"],"award-info":[{"award-number":["15207322"]}]},{"DOI":"10.13039\/501100004377","name":"Hong Kong Polytechnic University","doi-asserted-by":"publisher","award":["P0036200"],"award-info":[{"award-number":["P0036200"]}],"id":[{"id":"10.13039\/501100004377","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004377","name":"Hong Kong Polytechnic University","doi-asserted-by":"publisher","award":["P0042693"],"award-info":[{"award-number":["P0042693"]}],"id":[{"id":"10.13039\/501100004377","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Research Collaborative","award":["P0041282"],"award-info":[{"award-number":["P0041282"]}]},{"name":"SHTM Interdisciplinary Large","award":["P0043302"],"award-info":[{"award-number":["P0043302"]}]},{"name":"Hong Kong Research Grant Council","award":["R1012-21"],"award-info":[{"award-number":["R1012-21"]}]},{"name":"APRC-CityU New Research Initiatives","award":["9610565"],"award-info":[{"award-number":["9610565"]}]},{"name":"New Faculty of City University of Hong Kong"},{"name":"SIRG-CityU Strategic Interdisciplinary Research","award":["7020046"],"award-info":[{"award-number":["7020046"]}]},{"name":"SIRG-CityU Strategic Interdisciplinary Research","award":["7020074"],"award-info":[{"award-number":["7020074"]}]},{"name":"HKIDS Early Career Research","award":["9360163"],"award-info":[{"award-number":["9360163"]}]},{"name":"Huawei Innovation Research Program"},{"name":"CCF-Ant Research Fund"},{"name":"Ant Group Research Fund"},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS1815636"],"award-info":[{"award-number":["CNS1815636"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS1845081"],"award-info":[{"award-number":["IIS1845081"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS1928278"],"award-info":[{"award-number":["IIS1928278"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS1955285"],"award-info":[{"award-number":["IIS1955285"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS2212032"],"award-info":[{"award-number":["IIS2212032"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS2212144"],"award-info":[{"award-number":["IIS2212144"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IOS2107215"],"award-info":[{"award-number":["IOS2107215"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IOS2035472"],"award-info":[{"award-number":["IOS2035472"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-2153326"],"award-info":[{"award-number":["IIS-2153326"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-2212145"],"award-info":[{"award-number":["IIS-2212145"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-21-1-0198"],"award-info":[{"award-number":["W911NF-21-1-0198"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004792","name":"Home Depot","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004792","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004351","name":"Cisco Systems","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004351","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Amazon Faculty Award"},{"name":"Johnson&amp;Johnson"},{"DOI":"10.13039\/100018569","name":"SNAP","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100018569","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Knowl. Data Eng."],"published-print":{"date-parts":[[2023,12,1]]},"DOI":"10.1109\/tkde.2023.3272652","type":"journal-article","created":{"date-parts":[[2023,5,3]],"date-time":"2023-05-03T18:52:55Z","timestamp":1683139975000},"page":"12415-12429","source":"Crossref","is-referenced-by-count":35,"title":["Adversarial Attacks for Black-Box Recommender Systems via Copying Transferable Cross-Domain User Profiles"],"prefix":"10.1109","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4049-1233","authenticated-orcid":false,"given":"Wenqi","family":"Fan","sequence":"first","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2926-4416","authenticated-orcid":false,"given":"Xiangyu","family":"Zhao","sequence":"additional","affiliation":[{"name":"City University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3370-471X","authenticated-orcid":false,"given":"Qing","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0080-5998","authenticated-orcid":false,"given":"Tyler","family":"Derr","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4985-8724","authenticated-orcid":false,"given":"Yao","family":"Ma","sequence":"additional","affiliation":[{"name":"New Jersey Institute of Technology, Newark, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3555-3495","authenticated-orcid":false,"given":"Hui","family":"Liu","sequence":"additional","affiliation":[{"name":"Michigan State University, Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9318-1482","authenticated-orcid":false,"given":"Jianping","family":"Wang","sequence":"additional","affiliation":[{"name":"City University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7125-3898","authenticated-orcid":false,"given":"Jiliang","family":"Tang","sequence":"additional","affiliation":[{"name":"Michigan State University, Lansing, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3240323.3240374"},{"key":"ref12","article-title":"Deep reinforcement learning in large discrete action spaces","author":"dulac-arnold","year":"2015"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3320496.3320500"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00140"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_28"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/187"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219886"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401165"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219890"},{"key":"ref11","first-page":"1115","article-title":"Adversarial attack on graph structured data","author":"dai","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467208"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3437963.3441757"},{"key":"ref54","article-title":"Catch the black sheep: Unified framework for shilling attack detection based on fraudulent action propagation","author":"zhang","year":"2015","journal-title":"Proc Int Joint Conf Artif Intell"},{"key":"ref17","article-title":"Generative diffusion models on graphs: Methods and applications","author":"fan","year":"2023"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12132"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313488"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531985"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23020"},{"key":"ref50","article-title":"Adversarial attacks and defenses in images, graphs and text: A review","author":"xu","year":"2019"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-3618-5_2"},{"key":"ref45","first-page":"681","article-title":"Bayesian learning via stochastic gradient Langevin dynamics","author":"welling","year":"2011","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462862"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3511808.3557583"},{"key":"ref42","author":"sutton","year":"2018","journal-title":"Reinforcement Learning An Introduction"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00021"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3331184.3331267"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3412243"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/2339530.2339684"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583355"},{"key":"ref7","first-page":"1597","article-title":"A simple framework for contrastive learning of visual representations","author":"chen","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347031"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013312"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4899-7637-6_27"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SMC.2018.00601"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539359"},{"key":"ref40","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016"},{"key":"ref35","first-page":"1885","article-title":"Data poisoning attacks on factorization-based collaborative filtering","author":"li","year":"2016","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988726"},{"key":"ref37","article-title":"Trustworthy AI: A computational perspective","author":"liu","year":"2021"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411884"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403049"},{"key":"ref30","article-title":"Adversarial attacks and defenses on graphs: A review and empirical study","author":"jin","year":"2020"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2009.263"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3073565"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.04.001"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2743240"},{"key":"ref39","first-page":"12905","article-title":"Cross-domain transferability of adversarial perturbations","author":"naseer","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref38","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2017","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"ref23","article-title":"A comprehensive survey on trustworthy recommender systems","author":"fan","year":"2022"},{"key":"ref26","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3008732"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE55515.2023.00056"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347011"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2015.2432811"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"ref29","article-title":"Self-supervised learning on graphs: Deep insights and new direction","author":"jin","year":"2020"}],"container-title":["IEEE Transactions on Knowledge and Data Engineering"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/69\/10311056\/10114977-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/69\/10311056\/10114977.pdf?arnumber=10114977","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,12,11]],"date-time":"2023-12-11T20:55:14Z","timestamp":1702328114000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10114977\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,1]]},"references-count":59,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tkde.2023.3272652","relation":{},"ISSN":["1041-4347","1558-2191","2326-3865"],"issn-type":[{"value":"1041-4347","type":"print"},{"value":"1558-2191","type":"electronic"},{"value":"2326-3865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,1]]}}}