{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T15:14:19Z","timestamp":1785856459604,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,9,13]],"date-time":"2021-09-13T00:00:00Z","timestamp":1631491200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,9,13]]},"DOI":"10.1145\/3460231.3474275","type":"proceedings-article","created":{"date-parts":[[2021,9,13]],"date-time":"2021-09-13T21:45:04Z","timestamp":1631569504000},"page":"44-54","source":"Crossref","is-referenced-by-count":62,"title":["Black-Box Attacks on Sequential Recommenders via Data-Free Model Extraction"],"prefix":"10.1145","author":[{"given":"Zhenrui","family":"Yue","sequence":"first","affiliation":[{"name":"Technical University of Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhankui","family":"He","sequence":"additional","affiliation":[{"name":"UC San Diego, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huimin","family":"Zeng","sequence":"additional","affiliation":[{"name":"Technical University of Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Julian","family":"McAuley","sequence":"additional","affiliation":[{"name":"UC San Diego, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,9,13]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"The long tail: Why the future of business is selling less of more","author":"Anderson Chris","unstructured":"Chris Anderson . 2006. The long tail: Why the future of business is selling less of more . Hachette Books . Chris Anderson. 2006. The long tail: Why the future of business is selling less of more. Hachette Books."},{"key":"e_1_3_2_2_2_1","volume-title":"Proceedings of 3rd international workshop on intelligent techniques for web personalization (ITWP 2005), 19th international joint conference on artificial intelligence (IJCAI","author":"Burke Robin","year":"2005","unstructured":"Robin Burke , Bamshad Mobasher , and Runa Bhaumik . 2005 . Limited knowledge shilling attacks in collaborative filtering systems . In Proceedings of 3rd international workshop on intelligent techniques for web personalization (ITWP 2005), 19th international joint conference on artificial intelligence (IJCAI 2005). 17\u201324. Robin Burke, Bamshad Mobasher, and Runa Bhaumik. 2005. Limited knowledge shilling attacks in collaborative filtering systems. In Proceedings of 3rd international workshop on intelligent techniques for web personalization (ITWP 2005), 19th international joint conference on artificial intelligence (IJCAI 2005). 17\u201324."},{"key":"e_1_3_2_2_3_1","unstructured":"Kyunghyun Cho Bart van Merrienboer \u00c7aglar G\u00fcl\u00e7ehre Dzmitry Bahdanau Fethi Bougares Holger Schwenk and Yoshua Bengio. 2014. Learning Phrase Representations using RNN Encoder-Decoder for Statistical Machine Translation. In EMNLP.  Kyunghyun Cho Bart van Merrienboer \u00c7aglar G\u00fcl\u00e7ehre Dzmitry Bahdanau Fethi Bougares Holger Schwenk and Yoshua Bengio. 2014. Learning Phrase Representations using RNN Encoder-Decoder for Statistical Machine Translation. In EMNLP."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347031"},{"key":"e_1_3_2_2_5_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. https:\/\/arxiv.org\/abs\/1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin , Ming-Wei Chang , Kenton Lee , and Kristina\u00a0 N. Toutanova . 2018 . BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. https:\/\/arxiv.org\/abs\/1810.04805 Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina\u00a0N. Toutanova. 2018. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"e_1_3_2_2_7_1","unstructured":"Ian Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron Courville and Yoshua Bengio. 2014. Generative adversarial nets. In Advances in neural information processing systems. 2672\u20132680.  Ian Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron Courville and Yoshua Bengio. 2014. Generative adversarial nets. In Advances in neural information processing systems. 2672\u20132680."},{"key":"e_1_3_2_2_8_1","unstructured":"Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572(2014).  Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572(2014)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-012-9364-9"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"crossref","unstructured":"F\u00a0Maxwell Harper and Joseph\u00a0A Konstan. 2015. The movielens datasets: History and context. Acm transactions on interactive intelligent systems (tiis) 5 4(2015) 1\u201319.  F\u00a0Maxwell Harper and Joseph\u00a0A Konstan. 2015. The movielens datasets: History and context. Acm transactions on interactive intelligent systems (tiis) 5 4(2015) 1\u201319.","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2016.0030"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"e_1_3_2_2_13_1","unstructured":"Bal\u00e1zs Hidasi Alexandros Karatzoglou Linas Baltrunas and Domonkos Tikk. 2015. Session-based recommendations with recurrent neural networks. arXiv preprint arXiv:1511.06939(2015).  Bal\u00e1zs Hidasi Alexandros Karatzoglou Linas Baltrunas and Domonkos Tikk. 2015. Session-based recommendations with recurrent neural networks. arXiv preprint arXiv:1511.06939(2015)."},{"key":"e_1_3_2_2_14_1","unstructured":"Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531(2015).  Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531(2015)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Hai Huang Jiaming Mu Neil\u00a0Zhenqiang Gong Qi Li Bin Liu and Mingwei Xu. 2021. Data Poisoning Attacks to Deep Learning Based Recommender Systems. arXiv preprint arXiv:2101.02644(2021).  Hai Huang Jiaming Mu Neil\u00a0Zhenqiang Gong Qi Li Bin Liu and Mingwei Xu. 2021. Data Poisoning Attacks to Deep Learning Based Recommender Systems. arXiv preprint arXiv:2101.02644(2021).","DOI":"10.14722\/ndss.2021.24525"},{"key":"e_1_3_2_2_16_1","volume-title":"Is BERT Really Robust. A Strong Baseline for Natural Language Attack on Text Classification and Entailment","author":"Jin Di","year":"2019","unstructured":"Di Jin , Zhijing Jin , Joey\u00a0Tianyi Zhou , and Peter Szolovits . 2019. Is BERT Really Robust. A Strong Baseline for Natural Language Attack on Text Classification and Entailment ( 2019 ). Di Jin, Zhijing Jin, Joey\u00a0Tianyi Zhou, and Peter Szolovits. 2019. Is BERT Really Robust. A Strong Baseline for Natural Language Attack on Text Classification and Entailment (2019)."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00035"},{"key":"e_1_3_2_2_18_1","volume-title":"MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation. arXiv preprint arXiv:2005.03161(2020).","author":"Kariyappa Sanjay","year":"2020","unstructured":"Sanjay Kariyappa , Atul Prakash , and Moinuddin Qureshi . 2020 . MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation. arXiv preprint arXiv:2005.03161(2020). Sanjay Kariyappa, Atul Prakash, and Moinuddin Qureshi. 2020. MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation. arXiv preprint arXiv:2005.03161(2020)."},{"key":"e_1_3_2_2_19_1","volume-title":"Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980(2014).","author":"Kingma P","year":"2014","unstructured":"Diederik\u00a0 P Kingma and Jimmy Ba . 2014 . Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980(2014). Diederik\u00a0P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980(2014)."},{"key":"e_1_3_2_2_20_1","volume-title":"International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Byl5NREFDr","author":"Krishna Kalpesh","year":"2020","unstructured":"Kalpesh Krishna , Gaurav\u00a0Singh Tomar , Ankur\u00a0 P. Parikh , Nicolas Papernot , and Mohit Iyyer . 2020 . Thieves on Sesame Street! Model Extraction of BERT-based APIs . In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Byl5NREFDr Kalpesh Krishna, Gaurav\u00a0Singh Tomar, Ankur\u00a0P. Parikh, Nicolas Papernot, and Mohit Iyyer. 2020. Thieves on Sesame Street! Model Extraction of BERT-based APIs. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Byl5NREFDr"},{"key":"e_1_3_2_2_21_1","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533(2016).  Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533(2016)."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988726"},{"key":"e_1_3_2_2_23_1","volume-title":"2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 252\u2013262","author":"Lee Sungho","year":"2017","unstructured":"Sungho Lee , Sungjae Hwang , and Sukyoung Ryu . 2017 . All about activity injection: Threats, semantics, and detection . In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 252\u2013262 . Sungho Lee, Sungjae Hwang, and Sukyoung Ryu. 2017. All about activity injection: Threats, semantics, and detection. In 2017 32nd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 252\u2013262."},{"key":"e_1_3_2_2_24_1","unstructured":"Bo Li Yining Wang Aarti Singh and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. arXiv preprint arXiv:1608.08182(2016).  Bo Li Yining Wang Aarti Singh and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. arXiv preprint arXiv:1608.08182(2016)."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3132926"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2766462.2767755"},{"key":"e_1_3_2_2_28_1","unstructured":"Stephen Merity Caiming Xiong James Bradbury and Richard Socher. 2016. Pointer sentinel mixture models. arXiv preprint arXiv:1609.07843(2016).  Stephen Merity Caiming Xiong James Bradbury and Richard Socher. 2016. Pointer sentinel mixture models. arXiv preprint arXiv:1609.07843(2016)."},{"key":"e_1_3_2_2_29_1","volume-title":"Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP)","author":"Ni Jianmo","year":"1865","unstructured":"Jianmo Ni , Jiacheng Li , and Julian McAuley . 2019. Justifying Recommendations using Distantly-Labeled Reviews and Fine-Grained Aspects . In Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP) . Association for Computational Linguistics , Hong Kong , China, 188\u2013197. https:\/\/doi.org\/10. 1865 3\/v1\/D19-1018 Jianmo Ni, Jiacheng Li, and Julian McAuley. 2019. Justifying Recommendations using Distantly-Labeled Reviews and Fine-Grained Aspects. In Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). Association for Computational Linguistics, Hong Kong, China, 188\u2013197. https:\/\/doi.org\/10.18653\/v1\/D19-1018"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_2_31_1","unstructured":"Soham Pal Yash Gupta Aditya Shukla Aditya Kanade Shirish Shevade and Vinod Ganapathy. 2019. A framework for the extraction of deep neural networks by leveraging public data. arXiv preprint arXiv:1905.09165(2019).  Soham Pal Yash Gupta Aditya Shukla Aditya Kanade Shirish Shevade and Vinod Ganapathy. 2019. A framework for the extraction of deep neural networks by leveraging public data. arXiv preprint arXiv:1905.09165(2019)."},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_2_33_1","volume-title":"24th {USENIX} Security Symposium ({USENIX} Security 15). 945\u2013959.","author":"Ren Chuangang","unstructured":"Chuangang Ren , Yulong Zhang , Hui Xue , Tao Wei , and Peng Liu . 2015. Towards discovering and understanding task hijacking in android . In 24th {USENIX} Security Symposium ({USENIX} Security 15). 945\u2013959. Chuangang Ren, Yulong Zhang, Hui Xue, Tao Wei, and Peng Liu. 2015. Towards discovering and understanding task hijacking in android. In 24th {USENIX} Security Symposium ({USENIX} Security 15). 945\u2013959."},{"key":"e_1_3_2_2_34_1","volume-title":"BPR: Bayesian personalized ranking from implicit feedback. arXiv preprint arXiv:1205.2618(2012).","author":"Rendle Steffen","year":"2012","unstructured":"Steffen Rendle , Christoph Freudenthaler , Zeno Gantner , and Lars Schmidt-Thieme . 2012 . BPR: Bayesian personalized ranking from implicit feedback. arXiv preprint arXiv:1205.2618(2012). Steffen Rendle, Christoph Freudenthaler, Zeno Gantner, and Lars Schmidt-Thieme. 2012. BPR: Bayesian personalized ranking from implicit feedback. arXiv preprint arXiv:1205.2618(2012)."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772773"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00021"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3357895"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3159652.3159656"},{"key":"e_1_3_2_2_39_1","volume-title":"Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318\u2013327","author":"Tang Jiaxi","year":"2020","unstructured":"Jiaxi Tang , Hongyi Wen , and Ke Wang . 2020 . Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318\u2013327 . Jiaxi Tang, Hongyi Wen, and Ke Wang. 2020. Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In Fourteenth ACM Conference on Recommender Systems. 318\u2013327."},{"key":"e_1_3_2_2_40_1","volume-title":"25th {USENIX} Security Symposium ({USENIX} Security 16). 601\u2013618.","author":"Tram\u00e8r Florian","unstructured":"Florian Tram\u00e8r , Fan Zhang , Ari Juels , Michael\u00a0 K Reiter , and Thomas Ristenpart . 2016. Stealing machine learning models via prediction apis . In 25th {USENIX} Security Symposium ({USENIX} Security 16). 601\u2013618. Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael\u00a0K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction apis. In 25th {USENIX} Security Symposium ({USENIX} Security 16). 601\u2013618."},{"key":"e_1_3_2_2_41_1","volume-title":"22nd {USENIX} Security Symposium ({USENIX} Security 13). 671\u2013686.","author":"Xing Xingyu","unstructured":"Xingyu Xing , Wei Meng , Dan Doozan , Alex\u00a0 C Snoeren , Nick Feamster , and Wenke Lee . 2013. Take this personally: Pollution attacks on personalized services . In 22nd {USENIX} Security Symposium ({USENIX} Security 13). 671\u2013686. Xingyu Xing, Wei Meng, Dan Doozan, Alex\u00a0C Snoeren, Nick Feamster, and Wenke Lee. 2013. Take this personally: Pollution attacks on personalized services. In 22nd {USENIX} Security Symposium ({USENIX} Security 13). 671\u2013686."},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"crossref","unstructured":"Guolei Yang Neil\u00a0Zhenqiang Gong and Ying Cai. 2017. Fake Co-visitation Injection Attacks to Recommender Systems.. In NDSS.  Guolei Yang Neil\u00a0Zhenqiang Gong and Ying Cai. 2017. Fake Co-visitation Injection Attacks to Recommender Systems.. In NDSS.","DOI":"10.14722\/ndss.2017.23020"},{"key":"e_1_3_2_2_43_1","volume-title":"Cross-site request forgeries: Exploitation and prevention. Bericht","author":"Zeller William","year":"2008","unstructured":"William Zeller and Edward\u00a0 W Felten . 2008. Cross-site request forgeries: Exploitation and prevention. Bericht , Princeton University( 2008 ). William Zeller and Edward\u00a0W Felten. 2008. Cross-site request forgeries: Exploitation and prevention. Bericht, Princeton University(2008)."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3379992"},{"key":"e_1_3_2_2_45_1","unstructured":"Xiangyu Zhao Liang Zhang Long Xia Zhuoye Ding Dawei Yin and Jiliang Tang. 2017. Deep reinforcement learning for list-wise recommendations. arXiv preprint arXiv:1801.00209(2017).  Xiangyu Zhao Liang Zhang Long Xia Zhuoye Ding Dawei Yin and Jiliang Tang. 2017. Deep reinforcement learning for list-wise recommendations. arXiv preprint arXiv:1801.00209(2017)."},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"}],"event":{"name":"RecSys '21: Fifteenth ACM Conference on Recommender Systems","location":"Amsterdam Netherlands","acronym":"RecSys '21","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web","SIGAI ACM Special Interest Group on Artificial Intelligence","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data","SIGIR ACM Special Interest Group on Information Retrieval","SIGCHI ACM Special Interest Group on Computer-Human Interaction","SIGecom Special Interest Group on Economics and Computation"]},"container-title":["Fifteenth ACM Conference on Recommender Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460231.3474275","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460231.3474275","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:12:17Z","timestamp":1750191137000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460231.3474275"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,13]]},"references-count":46,"alternative-id":["10.1145\/3460231.3474275","10.1145\/3460231"],"URL":"https:\/\/doi.org\/10.1145\/3460231.3474275","relation":{},"subject":[],"published":{"date-parts":[[2021,9,13]]}}}