{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:38:20Z","timestamp":1783438700810,"version":"3.54.6"},"reference-count":77,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,2,7]],"date-time":"2023-02-07T00:00:00Z","timestamp":1675728000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ARC Discovery Early Career Researcher Award","award":["DE200101465"],"award-info":[{"award-number":["DE200101465"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst."],"published-print":{"date-parts":[[2023,7,31]]},"abstract":"<jats:p>\n            With recent advancements in graph neural networks (GNN), GNN-based recommender systems (gRS) have achieved remarkable success in the past few years. Despite this success, existing research reveals that gRSs are still vulnerable to\n            <jats:italic>poison attacks<\/jats:italic>\n            , in which the attackers inject fake data to manipulate recommendation results as they desire. This might be due to the fact that existing poison attacks (and countermeasures) are either model-agnostic or specifically designed for traditional recommender algorithms (e.g., neighborhood-based, matrix-factorization-based, or deep-learning-based RSs) that are not gRS. As gRSs are widely adopted in the industry, the problem of how to design poison attacks for gRSs has become a need for robust user experience. Herein, we focus on the use of poison attacks to manipulate item promotion in gRSs. Compared to standard GNNs, attacking gRSs is more challenging due to the heterogeneity of network structure and the entanglement between users and items. To overcome such challenges, we propose\n            <jats:monospace>GSPAttack<\/jats:monospace>\n            \u2014a generative surrogate-based poison attack framework for gRSs.\n            <jats:monospace>GSPAttack<\/jats:monospace>\n            tailors a learning process to surrogate a recommendation model as well as generate fake users and user-item interactions while preserving the data correlation between users and items for recommendation accuracy. Although maintaining high accuracy for other items rather than the target item seems counterintuitive, it is equally crucial to the success of a poison attack. Extensive evaluations on four real-world datasets revealed that\n            <jats:monospace>GSPAttack<\/jats:monospace>\n            outperforms all baselines with competent recommendation performance and is resistant to various countermeasures.\n          <\/jats:p>","DOI":"10.1145\/3567420","type":"journal-article","created":{"date-parts":[[2022,10,19]],"date-time":"2022-10-19T12:59:51Z","timestamp":1666184391000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":54,"title":["Poisoning GNN-based Recommender Systems with Generative Surrogate-based Attacks"],"prefix":"10.1145","volume":"41","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6050-0774","authenticated-orcid":false,"given":"Toan","family":"Nguyen Thanh","sequence":"first","affiliation":[{"name":"Griffith University, Gold Coast, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4605-6275","authenticated-orcid":false,"given":"Nguyen Duc Khang","family":"Quach","sequence":"additional","affiliation":[{"name":"Griffith University, Gold Coast, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2586-7757","authenticated-orcid":false,"given":"Thanh Tam","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology, HUTECH University, Ho Chi Minh City, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2027-5362","authenticated-orcid":false,"given":"Thanh Trung","family":"Huynh","sequence":"additional","affiliation":[{"name":"Griffith University, Gold Coast, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4940-0422","authenticated-orcid":false,"given":"Viet Hung","family":"Vu","sequence":"additional","affiliation":[{"name":"Hanoi University of Science and Technology, Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6547-7641","authenticated-orcid":false,"given":"Phi Le","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Hanoi University of Science and Technology, Hanoi, Vietnam"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3099-2712","authenticated-orcid":false,"given":"Jun","family":"Jo","sequence":"additional","affiliation":[{"name":"Griffith University, Gold Coast, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9687-1315","authenticated-orcid":false,"given":"Quoc Viet Hung","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Griffith University, Gold Coast, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,2,7]]},"reference":[{"key":"e_1_3_2_2_2","article-title":"The unfairness of popularity bias in recommendation","author":"Abdollahpouri Himan","year":"2019","unstructured":"Himan Abdollahpouri, Masoud Mansoury, Robin Burke, and Bamshad Mobasher. 2019. The unfairness of popularity bias in recommendation. arXiv preprint arXiv:1907.13286 (2019).","journal-title":"arXiv preprint arXiv:1907.13286"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.5555\/2931100"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347050"},{"key":"e_1_3_2_5_2","article-title":"Frappe: Understanding the usage and perception of mobile app recommendations in-the-wild","author":"Baltrunas Linas","year":"2015","unstructured":"Linas Baltrunas, Karen Church, Alexandros Karatzoglou, and Nuria Oliver. 2015. Frappe: Understanding the usage and perception of mobile app recommendations in-the-wild. arXiv preprint arXiv:1505.03014 (2015).","journal-title":"arXiv preprint arXiv:1505.03014"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.5555\/3165154"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/2907070"},{"key":"e_1_3_2_8_2","unstructured":"BrijainR. Patel and KushikK. Rana. 2014. A survey on decision tree algorithm for classification. J. Eng. Devel. Res. 2 1 (2014)."},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2807452"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3003047"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2022-11355"},{"issue":"2","key":"e_1_3_2_12_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3373807","article-title":"Efficient neural matrix factorization without sampling for recommendation","volume":"38","author":"Chen Chong","year":"2020","unstructured":"Chong Chen, Min Zhang, Yongfeng Zhang, Yiqun Liu, and Shaoping Ma. 2020. Efficient neural matrix factorization without sampling for recommendation. ACM Trans. Inf. Syst. 38, 2 (2020), 1\u201328.","journal-title":"ACM Trans. Inf. Syst."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1002\/ett.3872"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00020"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/1864708.1864770"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372338"},{"key":"e_1_3_2_17_2","article-title":"On node features for graph neural networks","author":"Duong Chi Thang","year":"2019","unstructured":"Chi Thang Duong, Thanh Dat Hoang, Ha The Hien Dang, Quoc Viet Hung Nguyen, and Karl Aberer. 2019. On node features for graph neural networks. arXiv preprint arXiv:1911.08795 (2019).","journal-title":"arXiv preprint arXiv:1911.08795"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3426723"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.5555\/3086952"},{"key":"e_1_3_2_21_2","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. Adv. Neural Inf. Process. Syst. 27 (2014).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-012-9364-9"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3457949"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.9973"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401063"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"e_1_3_2_28_2","article-title":"Data poisoning attacks to deep learning based recommender systems","author":"Huang Hai","year":"2021","unstructured":"Hai Huang, Jiaming Mu, Neil Zhenqiang Gong, Qi Li, Bin Liu, and Mingwei Xu. 2021. Data poisoning attacks to deep learning based recommender systems. arXiv preprint arXiv:2101.02644 (2021).","journal-title":"arXiv preprint arXiv:2101.02644"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3466753"},{"key":"e_1_3_2_30_2","article-title":"Semi-supervised classification with graph convolutional networks","author":"Kipf Thomas N.","year":"2016","unstructured":"Thomas N. Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016).","journal-title":"arXiv preprint arXiv:1609.02907"},{"key":"e_1_3_2_31_2","first-page":"3499","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Kool Wouter","year":"2019","unstructured":"Wouter Kool, Herke Van Hoof, and Max Welling. 2019. Stochastic beams and where to find them: The Gumbel-Top-k trick for sampling sequences without replacement. In Proceedings of the International Conference on Machine Learning. PMLR, 3499\u20133508."},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2009.263"},{"key":"e_1_3_2_33_2","article-title":"Data poisoning attacks on factorization-based collaborative filtering","volume":"29","author":"Li Bo","year":"2016","unstructured":"Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. Adv. Neural Inf. Process. Syst. 29 (2016).","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3186727"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/1278366.1278372"},{"key":"e_1_3_2_37_2","article-title":"Entity alignment for knowledge graphs with multi-order convolutional networks","author":"Nguyen Tam Thanh","year":"2020","unstructured":"Tam Thanh Nguyen, Thanh Trung Huynh, Hongzhi Yin, Vinh Van Tong, Darnbi Sakong, Bolong Zheng, and Quoc Viet Hung Nguyen. 2020. Entity alignment for knowledge graphs with multi-order convolutional networks. IEEE Trans. Knowl. Data Eng. 34, 9 (2020).","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.04.018"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113857"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1018"},{"key":"e_1_3_2_41_2","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: From phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016).","journal-title":"arXiv preprint arXiv:1605.07277"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3382764"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-020-09898-3"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/371920.372071"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00021"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.108274"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.08.100"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3022962"},{"key":"e_1_3_2_50_2","first-page":"2323","volume-title":"Proceedings of the IEEE 37th International Conference on Data Engineering (ICDE)","author":"Tam Nguyen Thanh","year":"2021","unstructured":"Nguyen Thanh Tam, Huynh Thanh Trung, Hongzhi Yin, Tong Van Vinh, Darnbi Sakong, Bolong Zheng, and Nguyen Quoc Viet Hung. 2021. Entity alignment for knowledge graphs with multi-order convolutional networks. In Proceedings of the IEEE 37th International Conference on Data Engineering (ICDE). 2323\u20132324."},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.5555\/3172077.3172286"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380266"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3412243"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482393"},{"key":"e_1_3_2_55_2","first-page":"601","volume-title":"Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916)","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In Proceedings of the 25th USENIX Security Symposium (USENIX Security\u201916). 601\u2013618."},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00015"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-021-00700-6"},{"key":"e_1_3_2_58_2","article-title":"Attack graph convolutional networks by adding fake nodes","author":"Wang Xiaoyun","year":"2018","unstructured":"Xiaoyun Wang, Minhao Cheng, Joe Eaton, Cho-Jui Hsieh, and Felix Wu. 2018. Attack graph convolutional networks by adding fake nodes. arXiv preprint arXiv:1810.10751 (2018).","journal-title":"arXiv preprint arXiv:1810.10751"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/3331184.3331267"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401144"},{"key":"e_1_3_2_61_2","article-title":"Graph neural networks in recommender systems: A survey","author":"Wu Shiwen","year":"2020","unstructured":"Shiwen Wu, Fei Sun, Wentao Zhang, and Bin Cui. 2020. Graph neural networks in recommender systems: A survey. arXiv preprint arXiv:2011.02260 (2020).","journal-title":"arXiv preprint arXiv:2011.02260"},{"issue":"3","key":"e_1_3_2_62_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3398202","article-title":"On scalability of association-rule-based recommendation: A unified distributed-computing framework","volume":"14","author":"Wu Zhiang","year":"2020","unstructured":"Zhiang Wu, Changsheng Li, Jie Cao, and Yong Ge. 2020. On scalability of association-rule-based recommendation: A unified distributed-computing framework. ACM Trans. Web 14, 3 (2020), 1\u201321.","journal-title":"ACM Trans. Web"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-021-06573-8"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/3467023"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3314578"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3469887"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3446617"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/3331184.3331321"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460231.3474275"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467233"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/3285029"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449813"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3498386"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401165"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484805"},{"key":"e_1_3_2_76_2","first-page":"427","volume-title":"Proceedings of the International Conference on Algorithms and Architectures for Parallel Processing","author":"Zhou Qi","year":"2019","unstructured":"Qi Zhou, Yizhi Ren, Tianyu Xia, Lifeng Yuan, and Linqiang Chen. 2019. Data poisoning attacks on graph convolutional matrix completion. In Proceedings of the International Conference on Algorithms and Architectures for Parallel Processing. Springer, 427\u2013439."},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"}],"container-title":["ACM Transactions on Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3567420","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3567420","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:43:46Z","timestamp":1750286626000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3567420"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,7]]},"references-count":77,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,7,31]]}},"alternative-id":["10.1145\/3567420"],"URL":"https:\/\/doi.org\/10.1145\/3567420","relation":{},"ISSN":["1046-8188","1558-2868"],"issn-type":[{"value":"1046-8188","type":"print"},{"value":"1558-2868","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,7]]},"assertion":[{"value":"2022-06-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-10-04","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-02-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}