{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T17:18:05Z","timestamp":1780766285942,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,8,14]],"date-time":"2021-08-14T00:00:00Z","timestamp":1628899200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"JD AI Research and the Fundamental Research Funds for the Central Universities","award":["No. WK2150110017"],"award-info":[{"award-number":["No. WK2150110017"]}]},{"name":"National Natural Science Foundation of China","award":["No. 62022077 and 61976198"],"award-info":[{"award-number":["No. 62022077 and 61976198"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,8,14]]},"DOI":"10.1145\/3447548.3467335","type":"proceedings-article","created":{"date-parts":[[2021,8,12]],"date-time":"2021-08-12T06:12:08Z","timestamp":1628748728000},"page":"1830-1840","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":47,"title":["Triple Adversarial Learning for Influence based Poisoning Attack in Recommender Systems"],"prefix":"10.1145","author":[{"given":"Chenwang","family":"Wu","sequence":"first","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Defu","family":"Lian","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yong","family":"Ge","sequence":"additional","affiliation":[{"name":"University of Arizona, Tucson, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhihao","family":"Zhu","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Enhong","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,8,14]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/3122009.3176860"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347050"},{"key":"e_1_3_2_1_3_1","volume-title":"Wasserstein gan. arXiv preprint arXiv:1701.07875","author":"Arjovsky Martin","year":"2017","unstructured":"Martin Arjovsky , Soumith Chintala , and L\u00e9on Bottou . 2017. Wasserstein gan. arXiv preprint arXiv:1701.07875 ( 2017 ). Martin Arjovsky, Soumith Chintala, and L\u00e9on Bottou. 2017. Wasserstein gan. arXiv preprint arXiv:1701.07875 (2017)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150465"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3269206.3271743"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3346987"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1639714.1639739"},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of NIPS'17","author":"Chongxuan LI","year":"2017","unstructured":"LI Chongxuan , Taufik Xu , Jun Zhu , and Bo Zhang . 2017 . Triple generative adversarial nets . In Proceedings of NIPS'17 . 4088--4098. LI Chongxuan, Taufik Xu, Jun Zhu, and Bo Zhang. 2017. Triple generative adversarial nets. In Proceedings of NIPS'17. 4088--4098."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347031"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401046"},{"key":"e_1_3_2_1_11_1","volume-title":"Attacking Black-box Recommendations via Copying Cross-domain User Profiles. arXiv preprint arXiv:2005.08147","author":"Fan Wenqi","year":"2020","unstructured":"Wenqi Fan , Tyler Derr , Xiangyu Zhao , Yao Ma , Hui Liu , Jianping Wang , Jiliang Tang , and Qing Li. 2020. Attacking Black-box Recommendations via Copying Cross-domain User Profiles. arXiv preprint arXiv:2005.08147 ( 2020 ). Wenqi Fan, Tyler Derr, Xiangyu Zhao, Yao Ma, Hui Liu, Jianping Wang, Jiliang Tang, and Qing Li. 2020. Attacking Black-box Recommendations via Copying Cross-domain User Profiles. arXiv preprint arXiv:2005.08147 (2020)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2843948"},{"key":"e_1_3_2_1_15_1","unstructured":"Ian Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron Courville and Yoshua Bengio. 2014. Generative adversarial nets. In Advances in Neural Information Processing Systems. 2672--2680.  Ian Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron Courville and Yoshua Bengio. 2014. Generative adversarial nets. In Advances in Neural Information Processing Systems. 2672--2680."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3209978.3209981"},{"key":"e_1_3_2_1_17_1","unstructured":"Andrew Ilyas Shibani Santurkar Dimitris Tsipras Logan Engstrom Brandon Tran and Aleksander Madry. 2019. Adversarial examples are not bugs they are features. In Advances in Neural Information Processing Systems. 125--136.  Andrew Ilyas Shibani Santurkar Dimitris Tsipras Logan Engstrom Brandon Tran and Aleksander Madry. 2019. Adversarial examples are not bugs they are features. In Advances in Neural Information Processing Systems. 125--136."},{"key":"e_1_3_2_1_18_1","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Jin Binbin","year":"2020","unstructured":"Binbin Jin , Defu Lian , Zheng Liu , Qi Liu , Jianhui Ma , Xing Xie , and Enhong Chen . 2020 . Sampling-Decomposable Generative Adversarial Recommender . Advances in Neural Information Processing Systems , Vol. 33 (2020). Binbin Jin, Defu Lian, Zheng Liu, Qi Liu, Jianhui Ma, Xing Xie, and Enhong Chen. 2020. Sampling-Decomposable Generative Adversarial Recommender. Advances in Neural Information Processing Systems, Vol. 33 (2020)."},{"key":"e_1_3_2_1_19_1","volume-title":"International Conference on Machine Learning. 1885--1894","author":"Koh Pang Wei","year":"2017","unstructured":"Pang Wei Koh and Percy Liang . 2017 . Understanding Black-box Predictions via Influence Functions . In International Conference on Machine Learning. 1885--1894 . Pang Wei Koh and Percy Liang. 2017. Understanding Black-box Predictions via Influence Functions. In International Conference on Machine Learning. 1885--1894."},{"key":"e_1_3_2_1_20_1","unstructured":"Pang Wei W Koh Kai-Siang Ang Hubert Teo and Percy S Liang. 2019. On the accuracy of influence functions for measuring group effects. In Advances in Neural Information Processing Systems. 5254--5264.  Pang Wei W Koh Kai-Siang Ang Hubert Teo and Percy S Liang. 2019. On the accuracy of influence functions for measuring group effects. In Advances in Neural Information Processing Systems. 5254--5264."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988726"},{"key":"e_1_3_2_1_22_1","unstructured":"Bo Li Yining Wang Aarti Singh and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. In Advances in Neural Information Processing Systems. 1885--1893.  Bo Li Yining Wang Aarti Singh and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. In Advances in Neural Information Processing Systems. 1885--1893."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403252"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2951386"},{"key":"e_1_3_2_1_25_1","volume-title":"Attacking Recommender Systems with Augmented User Profiles. arXiv preprint arXiv:2005.08164","author":"Lin Chen","year":"2020","unstructured":"Chen Lin , Si Chen , Hui Li , Yanghua Xiao , Lianyun Li , and Qian Yang . 2020. Attacking Recommender Systems with Augmented User Profiles. arXiv preprint arXiv:2005.08164 ( 2020 ). Chen Lin, Si Chen, Hui Li, Yanghua Xiao, Lianyun Li, and Qian Yang. 2020. Attacking Recommender Systems with Augmented User Profiles. arXiv preprint arXiv:2005.08164 (2020)."},{"key":"e_1_3_2_1_26_1","unstructured":"Bhaskar Mehta. 2007. Unsupervised shilling detection for collaborative filtering. In AAAI. 1402--1407.  Bhaskar Mehta. 2007. Unsupervised shilling detection for collaborative filtering. In AAAI. 1402--1407."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/1278366.1278372"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"e_1_3_2_1_29_1","volume-title":"Two decades of recommender systems at Amazon. com. Ieee internet computing","author":"Smith Brent","year":"2017","unstructured":"Brent Smith and Greg Linden . 2017. Two decades of recommender systems at Amazon. com. Ieee internet computing , Vol. 21 , 3 ( 2017 ), 12--18. Brent Smith and Greg Linden. 2017. Two decades of recommender systems at Amazon. com. Ieee internet computing, Vol. 21, 3 (2017), 12--18."},{"key":"e_1_3_2_1_30_1","volume-title":"PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender Systems. In 2020 IEEE 36th International Conference on Data Engineering (ICDE). IEEE, 157--168","author":"Song Junshuai","year":"2020","unstructured":"Junshuai Song , Zhao Li , Zehong Hu , Yucheng Wu , Zhenpeng Li , Jian Li , and Jun Gao . 2020 . PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender Systems. In 2020 IEEE 36th International Conference on Data Engineering (ICDE). IEEE, 157--168 . Junshuai Song, Zhao Li, Zehong Hu, Yucheng Wu, Zhenpeng Li, Jian Li, and Jun Gao. 2020. PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender Systems. In 2020 IEEE 36th International Conference on Data Engineering (ICDE). IEEE, 157--168."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2893638"},{"key":"e_1_3_2_1_32_1","volume-title":"Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318--327","author":"Tang Jiaxi","year":"2020","unstructured":"Jiaxi Tang , Hongyi Wen , and Ke Wang . 2020 . Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318--327 . Jiaxi Tang, Hongyi Wen, and Ke Wang. 2020. Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318--327."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3077136.3080786"},{"key":"e_1_3_2_1_34_1","volume-title":"Neil Zhenqiang Gong, and Ying Cai","author":"Yang Guolei","year":"2017","unstructured":"Guolei Yang , Neil Zhenqiang Gong, and Ying Cai . 2017 . Fake Co-visitation Injection Attacks to Recommender Systems.. In NDSS. Guolei Yang, Neil Zhenqiang Gong, and Ying Cai. 2017. Fake Co-visitation Injection Attacks to Recommender Systems.. In NDSS."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3331184.3331321"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3379992"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150508"},{"key":"e_1_3_2_1_38_1","volume-title":"Twenty-Fourth International Joint Conference on Artificial Intelligence.","author":"Zhang Yongfeng","year":"2015","unstructured":"Yongfeng Zhang , Yunzhi Tan , Min Zhang , Yiqun Liu , Tat-Seng Chua , and Shaoping Ma . 2015 . Catch the black sheep: unified framework for shilling attack detection based on fraudulent action propagation . In Twenty-Fourth International Joint Conference on Artificial Intelligence. Yongfeng Zhang, Yunzhi Tan, Min Zhang, Yiqun Liu, Tat-Seng Chua, and Shaoping Ma. 2015. Catch the black sheep: unified framework for shilling attack detection based on fraudulent action propagation. In Twenty-Fourth International Joint Conference on Artificial Intelligence."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0196533"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2015.12.137"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"}],"event":{"name":"KDD '21: The 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Virtual Event Singapore","acronym":"KDD '21","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery &amp; Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447548.3467335","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3447548.3467335","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:18:22Z","timestamp":1750191502000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447548.3467335"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,8,14]]},"references-count":41,"alternative-id":["10.1145\/3447548.3467335","10.1145\/3447548"],"URL":"https:\/\/doi.org\/10.1145\/3447548.3467335","relation":{},"subject":[],"published":{"date-parts":[[2021,8,14]]},"assertion":[{"value":"2021-08-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}