{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T17:18:02Z","timestamp":1780766282369,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,7,11]],"date-time":"2021-07-11T00:00:00Z","timestamp":1625961600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the National Natural Science Foundation of China","award":["No. 61976198 and 62022077"],"award-info":[{"award-number":["No. 61976198 and 62022077"]}]},{"name":"the Fundamental Research Funds for the Central Universities"},{"name":"the National Key R&D Program of China","award":["No. 2020AAA0103800"],"award-info":[{"award-number":["No. 2020AAA0103800"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,7,11]]},"DOI":"10.1145\/3404835.3462914","type":"proceedings-article","created":{"date-parts":[[2021,7,12]],"date-time":"2021-07-12T02:41:54Z","timestamp":1626057714000},"page":"1074-1083","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":48,"title":["Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning Training"],"prefix":"10.1145","author":[{"given":"Chenwang","family":"Wu","sequence":"first","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Defu","family":"Lian","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yong","family":"Ge","sequence":"additional","affiliation":[{"name":"University of Arizona, Tucson, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhihao","family":"Zhu","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Enhong","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Senchao","family":"Yuan","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,7,11]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347050"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSSC.2017.8335371"},{"key":"e_1_3_2_1_3_1","volume-title":"Proper Network Interpretability Helps Adversarial Robustness in Classification. In International Conference on Machine Learning. PMLR, 1014--1023","author":"Boopathy Akhilan","year":"2020","unstructured":"Akhilan Boopathy, Sijia Liu, Gaoyuan Zhang, Cynthia Liu, Pin-Yu Chen, Shiyu Chang, and Luca Daniel. 2020. Proper Network Interpretability Helps Adversarial Robustness in Classification. In International Conference on Machine Learning. PMLR, 1014--1023."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150465"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-012-0164-6"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3346987"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3281659"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347031"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3439729"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2018.2887018"},{"key":"e_1_3_2_1_11_1","volume-title":"Attacking Black-box Recommendations via Copying Cross-domain User Profiles. arXiv preprint arXiv:2005.08147","author":"Fan Wenqi","year":"2020","unstructured":"Wenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma, Hui Liu, Jianping Wang, Jiliang Tang, and Qing Li. 2020. Attacking Black-box Recommendations via Copying Cross-domain User Profiles. arXiv preprint arXiv:2005.08147 (2020)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/239"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3209978.3209981"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"e_1_3_2_1_17_1","unstructured":"Andrew Ilyas Shibani Santurkar Dimitris Tsipras Logan Engstrom Brandon Tran and Aleksander Madry. 2019. Adversarial examples are not bugs they are features. In Advances in Neural Information Processing Systems. 125--136."},{"key":"e_1_3_2_1_18_1","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Jin Binbin","year":"2020","unstructured":"Binbin Jin, Defu Lian, Zheng Liu, Qi Liu, Jianhui Ma, Xing Xie, and Enhong Chen. 2020. Sampling-Decomposable Generative Adversarial Recommender. Advances in Neural Information Processing Systems, Vol. 33 (2020)."},{"key":"e_1_3_2_1_19_1","volume-title":"International Conference on Machine Learning. 1885--1894","author":"Koh Pang Wei","year":"2017","unstructured":"Pang Wei Koh and Percy Liang. 2017. Understanding Black-box Predictions via Influence Functions. In International Conference on Machine Learning. 1885--1894."},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. 425--433","author":"Lakshminarayanan Balaji","year":"2011","unstructured":"Balaji Lakshminarayanan, Guillaume Bouchard, and Cedric Archambeau. 2011. Robust Bayesian matrix factorisation. In Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics. 425--433."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988726"},{"key":"e_1_3_2_1_22_1","unstructured":"Bo Li Yining Wang Aarti Singh and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. In Advances in Neural Information Processing Systems. 1885--1893."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371841"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380187"},{"key":"e_1_3_2_1_25_1","volume-title":"Geography-Aware Sequential Location Recommendation. In In Proceedings of KDD'20","author":"Lian Defu","year":"2020","unstructured":"Defu Lian, Yongji Wu, Yong Ge, Xing Xie, and Enhong Chen. 2020 b. Geography-Aware Sequential Location Recommendation. In In Proceedings of KDD'20. 2009--2019."},{"key":"e_1_3_2_1_26_1","volume-title":"Attacking Recommender Systems with Augmented User Profiles. arXiv preprint arXiv:2005.08164","author":"Lin Chen","year":"2020","unstructured":"Chen Lin, Si Chen, Hui Li, Yanghua Xiao, Lianyun Li, and Qian Yang. 2020. Attacking Recommender Systems with Augmented User Profiles. arXiv preprint arXiv:2005.08164 (2020)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401087"},{"key":"e_1_3_2_1_28_1","volume-title":"Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective. arXiv preprint arXiv:2009.03728","author":"Machado Gabriel Resende","year":"2020","unstructured":"Gabriel Resende Machado, Eug\u00eanio Silva, and Ronaldo Ribeiro Goldschmidt. 2020. Adversarial Machine Learning in Image Classification: A Survey Towards the Defender's Perspective. arXiv preprint arXiv:2009.03728 (2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"International Conference on Learning Representations .","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations ."},{"key":"e_1_3_2_1_30_1","unstructured":"Bhaskar Mehta. 2007. Unsupervised shilling detection for collaborative filtering. In AAAI. 1402--1407."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1278366.1278372"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313416"},{"key":"e_1_3_2_1_33_1","unstructured":"Ludwig Schmidt Shibani Santurkar Dimitris Tsipras Kunal Talwar and Aleksander Madry. 2018. Adversarially robust generalization requires more data. In Advances in Neural Information Processing Systems. 5014--5026."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3269206.3271710"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2017.72"},{"key":"e_1_3_2_1_37_1","volume-title":"PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender Systems. In 2020 IEEE 36th International Conference on Data Engineering (ICDE). IEEE, 157--168","author":"Song Junshuai","year":"2020","unstructured":"Junshuai Song, Zhao Li, Zehong Hu, Yucheng Wu, Zhenpeng Li, Jian Li, and Jun Gao. 2020. PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender Systems. In 2020 IEEE 36th International Conference on Data Engineering (ICDE). IEEE, 157--168."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2893638"},{"key":"e_1_3_2_1_39_1","volume-title":"Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318--327","author":"Tang Jiaxi","year":"2020","unstructured":"Jiaxi Tang, Hongyi Wen, and Ke Wang. 2020. Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318--327."},{"key":"e_1_3_2_1_40_1","first-page":"2643","article-title":"Deep content-based music recommendation","volume":"26","author":"den Oord Aaron Van","year":"2013","unstructured":"Aaron Van den Oord, Sander Dieleman, and Benjamin Schrauwen. 2013. Deep content-based music recommendation. Advances in Neural Information Processing Systems, Vol. 26 (2013), 2643--2651.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2339530.2339684"},{"key":"e_1_3_2_1_42_1","volume-title":"Neil Zhenqiang Gong, and Ying Cai","author":"Yang Guolei","year":"2017","unstructured":"Guolei Yang, Neil Zhenqiang Gong, and Ying Cai. 2017. Fake Co-visitation Injection Attacks to Recommender Systems.. In NDSS ."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3331184.3331321"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISE.2009.5365077"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2018.02.032"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3379992"},{"key":"e_1_3_2_1_47_1","volume-title":"International Conference on Machine Learning. PMLR, 11278--11287","author":"Zhang Jingfeng","year":"2020","unstructured":"Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli. 2020 b. Attacks which do not kill training make adversarial learning stronger. In International Conference on Machine Learning. PMLR, 11278--11287."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150508"},{"key":"e_1_3_2_1_49_1","volume-title":"Zi Huang, and Lizhen Cui. 2020 c. GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster Detection. arXiv preprint arXiv:2005.10150","author":"Zhang Shijie","year":"2020","unstructured":"Shijie Zhang, Hongzhi Yin, Tong Chen, Quoc Viet Nguyen Hung, Zi Huang, and Lizhen Cui. 2020 c. GCN-Based User Representation Learning for Unifying Robust Recommendation and Fraudster Detection. arXiv preprint arXiv:2005.10150 (2020)."},{"key":"e_1_3_2_1_50_1","volume-title":"17th International Conference on Information Fusion (FUSION). IEEE, 1--8.","author":"Zhang Zhuo","year":"2014","unstructured":"Zhuo Zhang and Sanjeev R Kulkarni. 2014. Detection of shilling attacks in recommender systems via spectral clustering. In 17th International Conference on Information Fusion (FUSION). IEEE, 1--8."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313609"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0196533"}],"event":{"name":"SIGIR '21: The 44th International ACM SIGIR Conference on Research and Development in Information Retrieval","location":"Virtual Event Canada","acronym":"SIGIR '21","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval"]},"container-title":["Proceedings of the 44th International ACM SIGIR Conference on Research and Development in Information Retrieval"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3404835.3462914","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3404835.3462914","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:18:19Z","timestamp":1750191499000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3404835.3462914"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,11]]},"references-count":52,"alternative-id":["10.1145\/3404835.3462914","10.1145\/3404835"],"URL":"https:\/\/doi.org\/10.1145\/3404835.3462914","relation":{},"subject":[],"published":{"date-parts":[[2021,7,11]]},"assertion":[{"value":"2021-07-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}