{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T18:39:26Z","timestamp":1775932766137,"version":"3.50.1"},"reference-count":252,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,2,1]],"date-time":"2026-02-01T00:00:00Z","timestamp":1769904000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172331"],"award-info":[{"award-number":["62172331"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["300102404301"],"award-info":[{"award-number":["300102404301"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Knowl. Data Eng."],"published-print":{"date-parts":[[2026,2]]},"DOI":"10.1109\/tkde.2025.3639434","type":"journal-article","created":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T18:49:56Z","timestamp":1764701396000},"page":"889-910","source":"Crossref","is-referenced-by-count":2,"title":["Attacks and Detections in Recommender Systems: A Comprehensive Analysis for Models, Progresses, and Trends"],"prefix":"10.1109","volume":"38","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-5399-2716","authenticated-orcid":false,"given":"Yan","family":"Feng","sequence":"first","affiliation":[{"name":"School of Data Science and Artificial Intelligence, Chang&#x2019;an University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1590-2587","authenticated-orcid":false,"given":"Zhihai","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Data Science and Artificial Intelligence, Chang&#x2019;an University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-5453-7885","authenticated-orcid":false,"given":"Kexin","family":"Li","sequence":"additional","affiliation":[{"name":"School of Data Science and Artificial Intelligence, Chang&#x2019;an University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianxin","family":"Li","sequence":"additional","affiliation":[{"name":"School of Business and Law, Edith Cowan University, Joondalup, WA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5779-6108","authenticated-orcid":false,"given":"Pinghui","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3934-2177","authenticated-orcid":false,"given":"Zhiquan","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Cyber Security, Jinan University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3145690"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MCI.2024.3363984"},{"key":"ref3","article-title":"Product recommendation engine market size share analysis - growth trends forecasts (2025-2030)","year":"2025"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3547333"},{"key":"ref5","article-title":"A deep dive into fairness, bias, threats, and privacy in recommender systems: Insights and future research","author":"Roy","year":"2024"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00290"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/tcss.2024.3465008"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3016827"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26774"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10141611"},{"key":"ref11","article-title":"Targeted data poisoning attack on news recommendation system by content perturbation","author":"Zhang","year":"2022"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599923"},{"key":"ref13","article-title":"Poisoning attacks and defenses in recommender systems: A survey","author":"Wang","year":"2024"},{"key":"ref14","article-title":"Poisoning attacks against recommender systems: A survey","author":"Wang","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3677328"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3439729"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-020-09898-3"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3022962"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-012-9364-9"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3757057"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23020"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657814"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645492"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom56396.2022.00086"},{"key":"ref26","first-page":"4543","article-title":"Inference attacks against graph neural networks","volume-title":"Proc. Conf. USENIX Secur.","author":"Zhang"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671474"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3706598.3714025"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3627826"},{"key":"ref30","article-title":"DBLP: Computer science bibliography","year":"2025"},{"key":"ref31","article-title":"Welcome to scopus preview","year":"2025"},{"key":"ref32","article-title":"Google scholar","year":"2025"},{"key":"ref33","article-title":"arxiv","year":"2025"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.2321584121"},{"key":"ref35","article-title":"Confusedpilot: Confused deputy risks in rag-based LLMs","author":"RoyChowdhury","year":"2024"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25611"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3576923"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-021-05586-8"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678946"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2792838.2799666"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3512352"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3181270"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3272652"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484805"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3183210"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3412243"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25558"},{"key":"ref50","doi-asserted-by":"crossref","DOI":"10.2139\/ssrn.5070783","article-title":"Precision profile pollution attack on sequential recommenders via influence function","author":"Du","year":"2024"},{"key":"ref51","article-title":"TODA: Target-oriented diffusion attacker against recommendation system","author":"Liu","year":"2024"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3665348.3665370"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3627673.3679592"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3674157"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/306"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3498386"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615073"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591722"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591777"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9013539"},{"key":"ref61","first-page":"1","article-title":"Data poisoning attacks on factorization-based collaborative filtering","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3726302.3729955"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3696105"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657764"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671795"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE55515.2023.00193"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539119"},{"key":"ref68","first-page":"29989","article-title":"Revisiting Injective Attacks on Recommender Systems","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401046"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/CSCWD61410.2024.10580115"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3627673.3679828"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3572834"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24525"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467233"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00021"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/MASS50613.2020.00050"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3358116"},{"key":"ref78","article-title":"Adversarial recommendation: Attack of the learned fake users","author":"Christakopoulou","year":"2018"},{"key":"ref79","first-page":"4042","article-title":"Data poisoning attacks on stochastic bandits","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Liu"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1109\/INVENTIVE.2016.7824865"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00094"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121630"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-024-10798-8"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599502"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3274759"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107390"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449891"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467335"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.07.041"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3117078"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411884"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671837"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1145\/3640457.3688148"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635751"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3592070"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3295601"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-49461-2_18"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583359"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110014"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1145\/3627673.3679804"},{"key":"ref102","article-title":"Shadow-free membership inference attacks: Recommender systems are more vulnerable than you thought","author":"Chi","year":"2024"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635830"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449813"},{"key":"ref107","first-page":"513","article-title":"Attriguard: A practical defense against attribute inference attacks via adversarial machine learning","volume-title":"Proc. USENIX Conf. Secur. Symp.","author":"Jia"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1145\/3568954"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3275161"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2954737"},{"key":"ref112","article-title":"LLM-powered text simulation attack against id-free recommender systems","author":"Wang","year":"2024"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1145\/3643685"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25612"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539359"},{"key":"ref116","doi-asserted-by":"publisher","DOI":"10.1145\/3437963.3441757"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00140"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1145\/3460231.3474275"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2018.08.001"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1145\/3567420"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i12.33392"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3522763"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1109\/ICCEIC64099.2024.10775988"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-024-4272-y"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE60146.2024.00173"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.02.025"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1145\/3539597.3570463"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00243"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1145\/3708344"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.124476"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2023.07.009"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.318"},{"key":"ref133","doi-asserted-by":"publisher","DOI":"10.1145\/3724393"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2025.111120"},{"key":"ref135","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347050"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1142\/S0219649219500114"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1049\/cje.2019.06.010"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLC.2018.8526971"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00916-8_43"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.1360\/N112017-00112"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2018.5131"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1145\/1390334.1390350"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-012-0164-6"},{"key":"ref144","first-page":"1","article-title":"Detection of shilling attacks in recommender systems via spectral clustering","volume-title":"Proc. Int. Conf. Inf. Fusion","author":"Zhang"},{"key":"ref145","first-page":"2408","article-title":"Catch the black sheep: Unified framework for shilling attack detection based on fraudulent action propagation","volume-title":"Proc. Int. Joint Conf. Artif. Intell.","author":"Zhang"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0130968"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3076295"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxy124"},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.02.015"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.04.012"},{"key":"ref151","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.07.081"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2017.0012"},{"key":"ref153","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00047"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0196533"},{"key":"ref155","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.05.001"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150508"},{"key":"ref157","doi-asserted-by":"publisher","DOI":"10.1145\/2600428.2609483"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2015.02.019"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2015.12.137"},{"key":"ref160","doi-asserted-by":"publisher","DOI":"10.23919\/MIPRO57284.2023.10159874"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/2323132"},{"key":"ref162","article-title":"On detecting data pollution attacks on recommender systems using sequential GANs","author":"Shahrasbi","year":"2020"},{"key":"ref163","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102493"},{"key":"ref164","doi-asserted-by":"publisher","DOI":"10.1155\/2019\/6523183"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxy008"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104030"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.1111\/coin.12579"},{"key":"ref168","doi-asserted-by":"publisher","DOI":"10.1145\/3523227.3546770"},{"key":"ref169","doi-asserted-by":"publisher","DOI":"10.3390\/app121910135"},{"key":"ref170","doi-asserted-by":"publisher","DOI":"10.1145\/3477300"},{"key":"ref171","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2019.102058"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113346"},{"key":"ref173","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2018.2887018"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.23919\/JCC.2019.10.008"},{"key":"ref175","article-title":"Understanding and improving adversarial collaborative filtering for robust recommendation","author":"Zhang","year":"2024"},{"key":"ref176","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635751"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2023.110931"},{"key":"ref178","doi-asserted-by":"publisher","DOI":"10.1109\/BigData55660.2022.10020712"},{"key":"ref179","doi-asserted-by":"publisher","DOI":"10.1145\/3559757"},{"key":"ref180","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833669"},{"key":"ref181","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-020-02164-y"},{"key":"ref182","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102390"},{"key":"ref183","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401196"},{"key":"ref184","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2019.113112"},{"key":"ref185","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI.2018.00102"},{"key":"ref186","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2018.02.032"},{"key":"ref187","doi-asserted-by":"publisher","DOI":"10.1016\/j.jksuci.2024.101964"},{"key":"ref188","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2021.3077738"},{"key":"ref189","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657684"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657684"},{"key":"ref191","first-page":"1703","article-title":"PORE: Provably robust recommender systems against data poisoning attacks","volume-title":"Proc. USENIX Conf. Secur. Symp.","author":"Jia"},{"key":"ref192","article-title":"Toward robust recommendation via real-time vicinal defense","author":"Xu","year":"2023"},{"key":"ref193","doi-asserted-by":"publisher","DOI":"10.1109\/AICCSA56895.2022.10017953"},{"key":"ref194","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20891-1_40"},{"key":"ref195","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462914"},{"key":"ref196","doi-asserted-by":"publisher","DOI":"10.3390\/sym12111805"},{"key":"ref197","doi-asserted-by":"publisher","DOI":"10.23919\/JCC.2019.08.012"},{"key":"ref198","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33014934"},{"key":"ref199","doi-asserted-by":"publisher","DOI":"10.3837\/tiis.2019.09.020"},{"key":"ref200","doi-asserted-by":"publisher","DOI":"10.1109\/SMC.2018.00601"},{"key":"ref201","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxad003"},{"key":"ref202","doi-asserted-by":"publisher","DOI":"10.3233\/IDA-230575"},{"key":"ref203","doi-asserted-by":"publisher","DOI":"10.1145\/3640457.3688120"},{"key":"ref204","doi-asserted-by":"publisher","DOI":"10.1007\/s40747-021-00357-2"},{"key":"ref205","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3146769"},{"key":"ref206","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/2907691"},{"key":"ref207","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN52387.2021.9533622"},{"key":"ref208","doi-asserted-by":"publisher","DOI":"10.1007\/s10844-021-00689-y"},{"key":"ref209","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3040618"},{"key":"ref210","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.05.084"},{"key":"ref211","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.105984"},{"key":"ref212","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2020.3013878"},{"key":"ref213","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401165"},{"key":"ref214","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.04.001"},{"issue":"8","key":"ref215","first-page":"155","article-title":"Data poisoning attack detection approach for quality of service aware cloud API recommender system","volume":"44","author":"Chen","year":"2023","journal-title":"J. Commun."},{"key":"ref216","doi-asserted-by":"publisher","DOI":"10.1155\/2023\/2854874"},{"key":"ref217","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2022.102154"},{"key":"ref218","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-023-16641-x"},{"key":"ref219","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-2233-8_8"},{"key":"ref220","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583289"},{"key":"ref221","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3327876"},{"key":"ref222","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3023114"},{"key":"ref223","doi-asserted-by":"publisher","DOI":"10.1177\/15501329221082415"},{"key":"ref224","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2022.103031"},{"key":"ref225","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-020-05162-6"},{"key":"ref226","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.103051"},{"key":"ref227","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2977023"},{"key":"ref228","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2016.08.011"},{"key":"ref229","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3354462"},{"key":"ref230","doi-asserted-by":"publisher","DOI":"10.3390\/math12020247"},{"key":"ref231","doi-asserted-by":"publisher","DOI":"10.1145\/3706112"},{"key":"ref232","doi-asserted-by":"publisher","DOI":"10.1145\/3604915.3608884"},{"key":"ref233","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612337"},{"key":"ref234","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS51746.2020.00026"},{"key":"ref235","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2877161"},{"key":"ref236","doi-asserted-by":"publisher","DOI":"10.1007\/s40815-018-0508-1"},{"key":"ref237","doi-asserted-by":"publisher","DOI":"10.1145\/2339530.2339684"},{"key":"ref238","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"ref239","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC.2006.1593032"},{"key":"ref240","article-title":"Trip advisor hotel reviews","year":"2025"},{"key":"ref241","doi-asserted-by":"publisher","DOI":"10.1145\/2806416.2806511"},{"key":"ref242","doi-asserted-by":"publisher","DOI":"10.1145\/3726302.3729886"},{"key":"ref243","article-title":"Bridging language and items for retrieval and recommendation","author":"Hou","year":"2024"},{"key":"ref244","doi-asserted-by":"publisher","DOI":"10.1145\/2736277.2741087"},{"key":"ref245","doi-asserted-by":"publisher","DOI":"10.1145\/2488388.2488520"},{"key":"ref246","article-title":"Food.com recipes and interactions","year":"2025"},{"key":"ref247","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-long.426"},{"key":"ref248","doi-asserted-by":"publisher","DOI":"10.23919\/CNSM46954.2019.9012686"},{"key":"ref249","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3502192"},{"key":"ref250","doi-asserted-by":"publisher","DOI":"10.1145\/3604915.3609490"},{"issue":"1","key":"ref251","first-page":"1","article-title":"General data protection regulation","volume":"25","author":"Regulation","year":"2018","journal-title":"Intouch"},{"key":"ref252","doi-asserted-by":"publisher","DOI":"10.21552\/aire\/2024\/1\/11"}],"container-title":["IEEE Transactions on Knowledge and Data Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/69\/11329113\/11271869.pdf?arnumber=11271869","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,6]],"date-time":"2026-01-06T05:51:35Z","timestamp":1767678695000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11271869\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2]]},"references-count":252,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tkde.2025.3639434","relation":{},"ISSN":["1041-4347","1558-2191","2326-3865"],"issn-type":[{"value":"1041-4347","type":"print"},{"value":"1558-2191","type":"electronic"},{"value":"2326-3865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2]]}}}