{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,20]],"date-time":"2025-12-20T22:02:21Z","timestamp":1766268141239,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,7,11]],"date-time":"2021-07-11T00:00:00Z","timestamp":1625961600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,7,11]]},"DOI":"10.1145\/3404835.3462848","type":"proceedings-article","created":{"date-parts":[[2021,7,12]],"date-time":"2021-07-12T02:41:54Z","timestamp":1626057714000},"page":"1094-1103","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":28,"title":["A Study of Defensive Methods to Protect Visual Recommendation Against Adversarial Manipulation of Images"],"prefix":"10.1145","author":[{"given":"Vito Walter","family":"Anelli","sequence":"first","affiliation":[{"name":"Polytechnic University of Bari, Bari, Italy"}]},{"given":"Yashar","family":"Deldjoo","sequence":"additional","affiliation":[{"name":"Polytechnic University of Bari, Bari, Italy"}]},{"given":"Tommaso","family":"Di Noia","sequence":"additional","affiliation":[{"name":"Polytechnic University of Bari, Bari, Italy"}]},{"given":"Daniele","family":"Malitesta","sequence":"additional","affiliation":[{"name":"Polytechnic University of Bari, Bari, Italy"}]},{"given":"Felice Antonio","family":"Merra","sequence":"additional","affiliation":[{"name":"Polytechnic University of Bari, Bari, Italy"}]}],"member":"320","published-online":{"date-parts":[[2021,7,11]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Tommaso Di Noia, and Felice Antonio Merra","author":"Anelli Vito Walter","year":"2021","unstructured":"Vito Walter Anelli, Alejandro Bellogin, Yashar Deldjoo, Tommaso Di Noia, and Felice Antonio Merra. 2021. MSAP: Multi-Step Adversarial Perturbations on Recommender Systems Embeddings. In FLAIRS."},{"key":"e_1_3_2_2_2_1","volume-title":"Daniele Malitesta, and Felice Antonio Merra.","author":"Anelli Vito Walter","year":"2020","unstructured":"Vito Walter Anelli, Tommaso Di Noia, Daniele Malitesta, and Felice Antonio Merra. 2020. Assessing Perceptual and Recommendation Mutation of Adversarially-Poisoned Visual Recommenders (short paper). In DP@AI*IA (CEUR Workshop Proceedings). CEUR-WS.org."},{"key":"e_1_3_2_2_3_1","volume-title":"ITWP","author":"Bhaumik Runa","year":"2006","unstructured":"Runa Bhaumik, Chad Williams, Bamshad Mobasher, and Robin Burke. 2006. Securing collaborative filtering against malicious attacks through anomaly detection. In ITWP 2006."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_2_5_1","unstructured":"Yuanjiang Cao Xiaocong Chen Lina Yao Xianzhi Wang and Wei Emma Zhang. 2020. Adversarial Attacks and Detection on Reinforcement Learning-Based Interactive Recommender Systems. In SIGIR. ACM 1669--1672."},{"key":"e_1_3_2_2_6_1","volume-title":"On Evaluating Adversarial Robustness. CoRR 2019","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian J. Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019. On Evaluating Adversarial Robustness. CoRR 2019 (2019)."},{"key":"e_1_3_2_2_7_1","volume-title":"Wagner","author":"Carlini Nicholas","year":"2016","unstructured":"Nicholas Carlini and David A. Wagner. 2016. Defensive Distillation is Not Robust to Adversarial Examples. CoRR 2016 (2016)."},{"key":"e_1_3_2_2_8_1","volume-title":"Wagner","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David A. Wagner. 2017a. Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods. In AISec@CCS 2017."},{"key":"e_1_3_2_2_9_1","volume-title":"Towards Evaluating the Robustness of Neural Networks. In SP","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David A. Wagner. 2017b. Towards Evaluating the Robustness of Neural Networks. In SP 2017."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3346987"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"crossref","unstructured":"Jingyuan Chen Hanwang Zhang Xiangnan He Liqiang Nie Wei Liu and Tat-Seng Chua. 2017. Attentive Collaborative Filtering: Multimedia Recommendation with Item- and Component-Level Attention. In SIGIR. ACM.","DOI":"10.1145\/3077136.3080797"},{"key":"e_1_3_2_2_12_1","volume-title":"Hierarchical Visual-aware Minimax Ranking Based on Co-purchase Data for Personalized Recommendation. In WWW","author":"Chong Xiaoya","year":"2020","unstructured":"Xiaoya Chong, Qing Li, Howard Leung, Qianhui Men, and Xianjin Chao. 2020. Hierarchical Visual-aware Minimax Ranking Based on Co-purchase Data for Personalized Recommendation. In WWW 2020."},{"key":"e_1_3_2_2_13_1","volume-title":"Dietmar Jannach, and Amihood Amir.","author":"Cohen Rami","year":"2021","unstructured":"Rami Cohen, Oren Sar Shalom, Dietmar Jannach, and Amihood Amir. 2021. A Black-Box Attack Model for Visually-Aware Recommender Systems., 94--102 pages."},{"key":"e_1_3_2_2_14_1","volume-title":"Tommaso Di Noia, and Felice Antonio Merra","author":"Deldjoo Yashar","year":"2021","unstructured":"Yashar Deldjoo, Tommaso Di Noia, and Felice Antonio Merra. 2021. A survey on adversarial recommender systems: from attack\/defense strategies to generative adversarial networks. ACM Computing Surveys (CSUR) (2021)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Yashar Deldjoo Tommaso Di Noia Eugenio Di Sciascio and Felice Antonio Merra. 2020 a. How Dataset Characteristics Affect the Robustness of Collaborative Recommendation Models. In SIGIR. ACM 951--960.","DOI":"10.1145\/3397271.3401046"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3407190"},{"key":"e_1_3_2_2_17_1","volume-title":"DSN--DSML","author":"Noia Tommaso Di","year":"2020","unstructured":"Tommaso Di Noia, Daniele Malitesta, and Felice Antonio Merra. 2020. TAaMR: Targeted Adversarial Attack against Multimedia Recommender Systems. In DSN--DSML 2020."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371789"},{"key":"e_1_3_2_2_19_1","volume-title":"ICLR","author":"Alexey Kurakand","year":"2017","unstructured":"Alexey Kurakand Ian J. Goodfellow and Samy Bengio. 2017. Adversarial examples the physical world. In ICLR 2017."},{"key":"e_1_3_2_2_20_1","volume-title":"Explaining and Harnessing Adversarial Examples. In ICLR","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR 2015."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3372192"},{"key":"e_1_3_2_2_22_1","volume-title":"ICLR","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo, Mayank Rana, Moustapha Ciss\u00e9, and Laurens van der Maaten. 2018. Countering Adversarial Images using Input Transformations. In ICLR 2018."},{"key":"e_1_3_2_2_23_1","volume-title":"Deep Residual Learning for Image Recognition. In CVPR","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In CVPR 2016."},{"key":"e_1_3_2_2_24_1","volume-title":"McAuley","author":"He Ruining","year":"2016","unstructured":"Ruining He and Julian J. McAuley. 2016a. Ups and Downs: Modeling the Visual Evolution of Fashion Trends with One-Class Collaborative Filtering. In WWW 2016."},{"key":"e_1_3_2_2_25_1","volume-title":"McAuley","author":"He Ruining","year":"2016","unstructured":"Ruining He and Julian J. McAuley. 2016b. VBPR: Visual Bayesian Personalized Ranking from Implicit Feedback. In AAAI 2016."},{"key":"e_1_3_2_2_26_1","volume-title":"Adversarial Personalized Ranking for Recommendation. In SIGIR","author":"He Xiangnan","year":"2018","unstructured":"Xiangnan He, Zhankui He, Xiaoyu Du, and Tat-Seng Chua. 2018. Adversarial Personalized Ranking for Recommendation. In SIGIR 2018."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"crossref","unstructured":"G. Hinton L. Deng D. Yu G. E. Dahl A. Mohamed N. Jaitly A. Senior V. Vanhoucke P. Nguyen T. N. Sainath and B. Kingsbury. 2012. Deep Neural Networks for Acoustic Modeling Speech Recognition: The Shared Views of Four Research Groups. IEEE Signal Processing Magazine (2012).","DOI":"10.1109\/MSP.2012.2205597"},{"key":"e_1_3_2_2_28_1","volume-title":"Visually-Aware Fashion Recommendation and Design with Generative Image Models. In ICDM","author":"Kang Wang-Cheng","year":"2017","unstructured":"Wang-Cheng Kang, Chen Fang, Zhaowen Wang, and Julian J. McAuley. [n.d.]. Visually-Aware Fashion Recommendation and Design with Generative Image Models. In ICDM 2017."},{"key":"e_1_3_2_2_29_1","volume-title":"WSDM","author":"Kordan Saeid Balaneshin","year":"2018","unstructured":"Saeid Balaneshin Kordan and Alexander Kotov. 2018. Deep Neural Architecture for Multi-Modal Retrieval based on Joint Embedding Space for Text and Images. In WSDM 2018."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2009.263"},{"key":"e_1_3_2_2_31_1","volume-title":"Hinton","author":"Krizhevsky Alex","year":"2012","unstructured":"Alex Krizhevsky, Ilya Sutskever, and Geoffrey E. Hinton. 2012. ImageNet Classification with Deep Convolutional Neural Networks. In NeurIPS 2012."},{"key":"e_1_3_2_2_32_1","volume-title":"CBRecSys@RecSys","author":"Kula Maciej","year":"2015","unstructured":"Maciej Kula. 2015. Metadata Embeddings for User and Item Cold-start Recommendations. In CBRecSys@RecSys 2015."},{"key":"e_1_3_2_2_33_1","volume-title":"Lam and John Riedl","author":"Shyong","year":"2004","unstructured":"Shyong K. Lam and John Riedl. 2004. Shilling recommender systems for fun and profit. In WWW 2004."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"crossref","unstructured":"Yang Liu Xianzhuo Xia Liang Chen Xiangnan He Carl Yang and Zibin Zheng. 2020. Certifiable Robustness to Discrete Adversarial Perturbations for Factorization Machines. In SIGIR. ACM 419--428.","DOI":"10.1145\/3397271.3401087"},{"key":"e_1_3_2_2_35_1","volume-title":"ICLR","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In ICLR 2018."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"crossref","unstructured":"Jarana Manotumruksa and Emine Yilmaz. 2020. Sequential-based Adversarial Optimisation for Personalised Top-N Item Recommendation. In SIGIR. ACM.","DOI":"10.1145\/3397271.3401264"},{"key":"e_1_3_2_2_37_1","volume-title":"Image-Based Recommendations on Styles and Substitutes. In SIGIR","author":"McAuley Julian J.","year":"2015","unstructured":"Julian J. McAuley, Christopher Targett, Qinfeng Shi, and Anton van den Hengel. 2015. Image-Based Recommendations on Styles and Substitutes. In SIGIR 2015."},{"key":"e_1_3_2_2_38_1","volume-title":"Neural Personalized Ranking for Image Recommendation. In WSDM","author":"Niu Wei","year":"2018","unstructured":"Wei Niu, James Caverlee, and Haokai Lu. 2018. Neural Personalized Ranking for Image Recommendation. In WSDM 2018."},{"key":"e_1_3_2_2_39_1","volume-title":"Silvestre","author":"O'Mahony Michael P.","year":"2004","unstructured":"Michael P. O'Mahony, Neil J. Hurley, Nicholas Kushmerick, and Guenole C. M. Silvestre. 2004. Collaborative recommendation: A robustness analysis. ACM Trans. Internet Techn. (2004)."},{"key":"e_1_3_2_2_40_1","unstructured":"Nicolas Papernot Fartash Faghri Nicholas Carlini Ian Goodfellow Reuben Feinman Alexey Kurakand Cihang Xie Yash Sharma Tom Brown Aurko Roy Alexander Matyasko Vahid Behzadan Karen Hambardzumyan Zhishuai Zhang Yi-LJuang Zhi Li Ryan Sheatsley Abhibhav Garg Jonathan Uesato Willi Gierke Yinpeng Dong David Berthelot Paul Hendricks Jonas Rauber and Rujun Long. 2018. Technical Report on the CleverHans v2.1.0 Adversarial Examples Library. Corr 2018 (2018)."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_2_42_1","volume-title":"NeurIPS","author":"Ren Shaoqing","year":"2015","unstructured":"Shaoqing Ren, Kaiming He, Ross B. Girshick, and Jian Sun. 2015. Faster R-CNN: Towards Real-Time Object Detection with Region Proposal Networks. In NeurIPS 2015."},{"key":"e_1_3_2_2_43_1","volume-title":"Factorization Machines. In ICDM","author":"Rendle Steffen","year":"2010","unstructured":"Steffen Rendle. 2010. Factorization Machines. In ICDM 2010."},{"key":"e_1_3_2_2_44_1","volume-title":"UAI","author":"Rendle Steffen","year":"2009","unstructured":"Steffen Rendle, Christoph Freudenthaler, Zeno Gantner, and Lars Schmidt-Thieme. 209. BPR: Bayesian Personalized Ranking from Implicit Feedback. In UAI 2009."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"crossref","unstructured":"Steffen Rendle Christoph Freudenthaler and Lars Schmidt-Thieme. 2010. Factorizing personalized Markov chains for next-basket recommendation. In WWW. ACM.","DOI":"10.1145\/1772690.1772773"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"crossref","unstructured":"Francesco Ricci Lior Rokach and Bracha Shapira (Eds.). 2015. Recommender Systems Handbook .Springer.","DOI":"10.1007\/978-1-4899-7637-6"},{"key":"e_1_3_2_2_47_1","volume-title":"NeurIPS","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi, Mahyar Najibi, AmGhiasi, Zheng Xu, John P. Dickerson, Christoph Studer, Larry S. Davis, GavTaylor, and Tom Goldstein. 2019. Adversarial training for free!. In NeurIPS 2019."},{"key":"e_1_3_2_2_48_1","volume-title":"ICLR","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In ICLR 2014."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2893638"},{"key":"e_1_3_2_2_50_1","volume-title":"Transferring Robustness for Graph Neural Network Against Poisoning Attacks. In WSDM","author":"Tang Xianfeng","year":"2020","unstructured":"Xianfeng Tang, Yandong Li, Yiwei Sun, Huaxiu Yao, Prasenjit Mitra, and Suhang Wang. 2020 b. Transferring Robustness for Graph Neural Network Against Poisoning Attacks. In WSDM 2020."},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"crossref","unstructured":"Sa\u00fa l Vargas. 2014. Novelty and diversity enhancement and evaluation in recommender systems and information retrieval. In SIGIR. ACM 1281.","DOI":"10.1145\/2600428.2610382"},{"key":"e_1_3_2_2_52_1","volume-title":"The Influence of Image Search Intents on User Behavior and Satisfaction. In WSDM","author":"Wu Zhijing","year":"2019","unstructured":"Zhijing Wu, Yiqun Liu, Qianfan Zhang, Kailu Wu, Min Zhang, and Shaoping Ma. 2019. The Influence of Image Search Intents on User Behavior and Satisfaction. In WSDM 2019."},{"key":"e_1_3_2_2_53_1","volume-title":"Enhancing Fashion Recommendation with Visual Compatibility Relationship. In WWW","author":"Yin Ruiping","year":"2019","unstructured":"Ruiping Yin, Kan Li, Jie Lu, and Guangquan Zhang. 2019. Enhancing Fashion Recommendation with Visual Compatibility Relationship. In WWW 2019."},{"key":"e_1_3_2_2_54_1","volume-title":"Aesthetic-based Clothing Recommendation. In WWW","author":"Yu Wenhui","year":"2018","unstructured":"Wenhui Yu, Huidi Zhang, Xiangnan He, Xu Chen, Li Xiong, and Zheng Qin. 2018. Aesthetic-based Clothing Recommendation. In WWW 2018, Pierre-Antoine Champin, Fabien L. Gandon, Mounia Lalmas, and Panagiotis G. Ipeirotis (Eds.)."},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"crossref","unstructured":"Feng Yuan Lina Yao and Boualem Benatallah. 2019 b. Adversarial Collaborative Neural Network for Robust Recommendation. In SIGIR. ACM 1065--1068.","DOI":"10.1145\/3331184.3331321"},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2631434"},{"key":"e_1_3_2_2_58_1","volume-title":"CIKM","author":"James Caverlee Zhang","year":"2019","unstructured":"YZhang and James Caverlee. 2019. Instagrammers, Fashionistas, and Me: Recurrent Fashion Recommendation with Implicit Visual Influence. In CIKM 2019."}],"event":{"name":"SIGIR '21: The 44th International ACM SIGIR Conference on Research and Development in Information Retrieval","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval"],"location":"Virtual Event Canada","acronym":"SIGIR '21"},"container-title":["Proceedings of the 44th International ACM SIGIR Conference on Research and Development in Information Retrieval"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3404835.3462848","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3404835.3462848","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:47:17Z","timestamp":1750193237000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3404835.3462848"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,11]]},"references-count":58,"alternative-id":["10.1145\/3404835.3462848","10.1145\/3404835"],"URL":"https:\/\/doi.org\/10.1145\/3404835.3462848","relation":{},"subject":[],"published":{"date-parts":[[2021,7,11]]},"assertion":[{"value":"2021-07-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}