{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T14:20:40Z","timestamp":1784816440212,"version":"3.55.0"},"reference-count":166,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T00:00:00Z","timestamp":1728259200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,1,31]]},"abstract":"<jats:p>\n            Recommender systems have become an integral part of online services due to their ability to help users locate specific information in a sea of data. However, existing studies show that some recommender systems are vulnerable to poisoning attacks, particularly those that involve learning schemes. A poisoning attack is where an adversary injects carefully crafted data into the process of training a model with the goal of manipulating the system\u2019s final recommendations. Based on recent advancements in artificial intelligence (AI), such attacks have gained importance recently. At present, we do not have a full and clear picture of why adversaries mount such attacks, nor do we have comprehensive knowledge of the full capacity to which such attacks can undermine a model or the impacts that might have. While numerous countermeasures to poisoning attacks have been developed, they have not yet been systematically linked to the properties of the attacks. Consequently, assessing the respective risks and potential success of mitigation strategies is difficult, if not impossible. This survey aims to fill this gap by primarily focusing on poisoning attacks and their countermeasures. This is in contrast to prior surveys that mainly focus on attacks and their detection methods. Through an exhaustive literature review, we provide a novel taxonomy for poisoning attacks, formalise its dimensions, and accordingly organise 31 attacks described in the literature. Further, we review 43 countermeasures to detect and\/or prevent poisoning attacks, evaluating their effectiveness against specific types of attacks. This comprehensive survey should serve as a point of reference for protecting recommender systems against poisoning attacks. The article concludes with a discussion on open issues in the field and impactful directions for future research. A rich repository of resources associated with poisoning attacks is available at\n            <jats:ext-link xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" xlink:href=\"https:\/\/github.com\/tamlhp\/awesome-recsys-poisoning\">https:\/\/github.com\/tamlhp\/awesome-recsys-poisoning<\/jats:ext-link>\n            .\n          <\/jats:p>","DOI":"10.1145\/3677328","type":"journal-article","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T11:07:22Z","timestamp":1721905642000},"page":"1-39","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":52,"title":["Manipulating Recommender Systems: A Survey of Poisoning Attacks and Countermeasures"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6050-0774","authenticated-orcid":false,"given":"Thanh Toan","family":"Nguyen","sequence":"first","affiliation":[{"name":"Faculty of Information Technology, HUTECH University","place":["Ho Chi Minh City, Vietnam"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9687-1315","authenticated-orcid":false,"given":"Nguyen","family":"Quoc Viet hung","sequence":"additional","affiliation":[{"name":"Griffith University - Gold Coast Campus","place":["Southport, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2586-7757","authenticated-orcid":false,"given":"Thanh Tam","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Griffith University - Gold Coast Campus","place":["Southport, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2027-5362","authenticated-orcid":false,"given":"Thanh Trung","family":"Huynh","sequence":"additional","affiliation":[{"name":"Ecole Polytechnique Federale de Lausanne","place":["Lausanne, Switzerland"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9709-1663","authenticated-orcid":false,"given":"Thanh Thi","family":"Nguyen","sequence":"additional","affiliation":[{"name":"School of Information Technology, Deakin University Faculty of Science Engineering and Built Environment","place":["Waurn Ponds, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3325-7227","authenticated-orcid":false,"given":"Matthias","family":"Weidlich","sequence":"additional","affiliation":[{"name":"Humboldt-Universitat zu Berlin","place":["Berlin, Germany"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1395-261X","authenticated-orcid":false,"given":"Hongzhi","family":"Yin","sequence":"additional","affiliation":[{"name":"The University of Queensland","place":["Saint Lucia, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,10,7]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"IndustryARC. 2024. Recommendation Engine Market - Forecast(2024-2030). Retrieved 3 August 2024 from https:\/\/www.industryarc.com\/Research\/Recommendation-Engine-Market-Research-500995"},{"key":"e_1_3_2_3_2","unstructured":"BBC News. 2001. Sony admits using fake reviewer. Retrieved 3 August 2024 from http:\/\/news.bbc.co.uk\/2\/hi\/entertainment\/1368666.stm"},{"key":"e_1_3_2_4_2","unstructured":"Penta Security. 2021. Top 5 AI-powered cyber threats & how to prevent them. Retrieved from 3 August 2024 https:\/\/www.pentasecurity.com\/blog\/top-5-ai-powered-cyber-threats-how-to-prevent-them\/"},{"key":"e_1_3_2_5_2","unstructured":"Thanh Tam Nguyen. 2024. Github - Awesome Recsys Poisoning. Retrieved 3 August 2024 from https:\/\/github.com\/tamlhp\/awesome-recsys-poisoning"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-90403-0_2"},{"key":"e_1_3_2_7_2","first-page":"303","volume-title":"ICACSIS","author":"Aditya P. H.","year":"2016","unstructured":"P. H. Aditya, Indra Budi, and Qorib Munajat. 2016. A comparative analysis of memory-based and model-based collaborative filtering on the implementation of recommender system for E-commerce. In ICACSIS. 303\u2013308."},{"issue":"1","key":"e_1_3_2_8_2","first-page":"100004","article-title":"Generative adversarial network: An overview of theory and applications","volume":"1","author":"Aggarwal Alankrita","year":"2021","unstructured":"Alankrita Aggarwal, Mamta Mittal, and Gopi Battineni. 2021. Generative adversarial network: An overview of theory and applications. Int. J. Inf. Manag. Data Insights 1, 1 (2021), 100004.","journal-title":"Int. J. Inf. Manag. Data Insights"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","unstructured":"C. C. Aggarwal. 2016. Recommender systems (Vol. 1). Cham: Springer International Publishing. 10.1007\/978-3-319-29659-3","DOI":"10.1007\/978-3-319-29659-3"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347050"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1504\/ijaip.2020.105815"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113790"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/2908446.2908481"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11192-021-03909-y"},{"key":"e_1_3_2_15_2","doi-asserted-by":"crossref","unstructured":"E. Aliwa O. Rana C. Perera and P. Burnap. 2021. Cyberattacks and countermeasures for in-vehicle networks. ACM Computing Surveys (CSUR) 54 1(2021) 1\u201337.","DOI":"10.1145\/3431233"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2008.4630088"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462848"},{"issue":"2","key":"e_1_3_2_18_2","first-page":"231","article-title":"Machine learning-based book recommender system: A survey and new perspectives","volume":"13","author":"Anwar Khalid","year":"2020","unstructured":"Khalid Anwar, Jamshed Siddiqui, and Shahab Saquib Sohail. 2020. Machine learning-based book recommender system: A survey and new perspectives. Int. J. Intell. Inf. Datab. Syst. 13, 2-4 (2020), 231\u2013248.","journal-title":"Int. J. Intell. Inf. Datab. Syst."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140450"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107390"},{"key":"e_1_3_2_21_2","doi-asserted-by":"crossref","first-page":"75","DOI":"10.1145\/1455770.1455782","volume-title":"CCS","author":"Barth Adam","year":"2008","unstructured":"Adam Barth, Collin Jackson, and John C. Mitchell. 2008. Robust defenses for cross-site request forgery. In CCS. 75\u201388."},{"key":"e_1_3_2_22_2","first-page":"1","volume-title":"ICDATA","author":"Bhaumik Runa","year":"2011","unstructured":"Runa Bhaumik, Bamshad Mobasher, and Robin Burke. 2011. A clustering approach to unsupervised attack detection in collaborative recommender systems. In ICDATA. 1."},{"key":"e_1_3_2_23_2","doi-asserted-by":"crossref","unstructured":"A. Bilge Z. Ozdemir and H. Polat. 2014. A novel shilling attack detection method. Procedia Computer Science 31 (2014) 165\u2013174.","DOI":"10.1016\/j.procs.2014.05.257"},{"key":"e_1_3_2_24_2","doi-asserted-by":"crossref","unstructured":"P. Branco L. Torgo and R. P. Ribeiro. 2016. A survey of predictive modeling on imbalanced domains. ACM Computing Surveys (CSUR) 49 2 (2016) 1\u201350.","DOI":"10.1145\/2907070"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/CIBCB.2006.330995"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/1454008.1454034"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150465"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/CEC-EEE.2006.34"},{"key":"e_1_3_2_29_2","doi-asserted-by":"crossref","unstructured":"H. Cai and F. Zhang. 2019. BS-SC: An unsupervised approach for detecting shilling profiles in collaborative recommender systems. IEEE Transactions on Knowledge and Data Engineering 33 4 (2019) 1375\u20131388.","DOI":"10.1109\/TKDE.2019.2946247"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.04.001"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2019.113112"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3459992"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-012-0164-6"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI.2019.00137"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3358116"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539359"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1002\/ett.3872"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/1097047.1097061"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347031"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2013.01.020"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.3150\/12-BEJSP10"},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","unstructured":"D. Das L. Sahoo and S. Datta. 2017. A survey on recommendation system. International Journal of Computer Applications 160 7 (2017) 6\u201310.","DOI":"10.5120\/ijca2017913081"},{"key":"e_1_3_2_43_2","volume-title":"Bibliometrics and Citation Analysis: From the Science Citation Index to Cybermetrics","author":"Bellis Nicola De","year":"2009","unstructured":"Nicola De Bellis. 2009. Bibliometrics and Citation Analysis: From the Science Citation Index to Cybermetrics. SP."},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3439729"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/CISP.2010.5647190"},{"key":"e_1_3_2_46_2","unstructured":"M. Evangelopoulou and C. W. Johnson. 2014. Attack visualisation for cyber-security situation awareness."},{"key":"e_1_3_2_47_2","first-page":"48","volume-title":"DSC","author":"Fan Jiaxin","year":"2022","unstructured":"Jiaxin Fan, Qi Yan, Mohan Li, Guanqun Qu, and Yang Xiao. 2022. A survey on data poisoning attacks and defenses. In DSC. IEEE, 48\u201355."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00140"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"e_1_3_2_51_2","doi-asserted-by":"crossref","unstructured":"S. Fletcher and M. Z. Islam. 2019. Decision tree classification with differential privacy: A survey. ACM Computing Surveys (CSUR) 52 4 (2019) 1\u201333.","DOI":"10.1145\/3337064"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835868"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/2523813"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3003816"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092566"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10710-017-9314-z"},{"key":"e_1_3_2_57_2","article-title":"DA-GCN: A domain-aware attentive graph convolution network for shared-account cross-domain sequential recommendation","author":"Guo Lei","year":"2021","unstructured":"Lei Guo, Li Tang, Tong Chen, Lei Zhu, Quoc Viet Hung Nguyen, and Hongzhi Yin. 2021. DA-GCN: A domain-aware attentive graph convolution network for shared-account cross-domain sequential recommendation. arXiv preprint arXiv:2105.03300 (2021).","journal-title":"arXiv preprint arXiv:2105.03300"},{"key":"e_1_3_2_58_2","doi-asserted-by":"crossref","unstructured":"Q. Guo F. Zhuang C. Qin H. Zhu X. Xie H. Xiong and Q. He. 2020. A survey on knowledge graph-based recommender systems. IEEE Transactions on Knowledge and Data Engineering 34 8 (2020) 3549\u20133568.","DOI":"10.1109\/TKDE.2020.3028705"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1587\/transinf.2017EDR0003"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-020-05162-6"},{"key":"e_1_3_2_61_2","doi-asserted-by":"crossref","unstructured":"Y. Hao F. Zhang J. Wang Q. Zhao and J. Cao. 2019. Detecting shilling attacks with automatic features from multiple views. Security and Communication Networks 2019 1 (2019) 6523183.","DOI":"10.1155\/2019\/6523183"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM38437.2019.9013539"},{"key":"e_1_3_2_63_2","doi-asserted-by":"crossref","unstructured":". Hu Y. Koren and C. Volinsky. 2008. Collaborative filtering for implicit feedback datasets. In 2008 Eighth IEEE International Conference on Data Mining. IEEE 263\u2013272.","DOI":"10.1109\/ICDM.2008.22"},{"key":"e_1_3_2_64_2","article-title":"Data poisoning attacks to deep learning based recommender systems","author":"Huang Hai","year":"2021","unstructured":"Hai Huang, Jiaming Mu, Neil Zhenqiang Gong, Qi Li, Bin Liu, and Mingwei Xu. 2021. Data poisoning attacks to deep learning based recommender systems. arXiv preprint arXiv:2101.02644 (2021).","journal-title":"arXiv preprint arXiv:2101.02644"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3199674"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/544220.544231"},{"key":"e_1_3_2_67_2","article-title":"PORE: Provably robust recommender systems against data poisoning attacks","author":"Jia Jinyuan","year":"2023","unstructured":"Jinyuan Jia, Yupei Liu, Yuepeng Hu, and Neil Zhenqiang Gong. 2023. PORE: Provably robust recommender systems against data poisoning attacks. arXiv preprint arXiv:2303.14601 (2023).","journal-title":"arXiv preprint arXiv:2303.14601"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1155\/2013\/149023"},{"key":"e_1_3_2_69_2","doi-asserted-by":"crossref","unstructured":"Y. Koren R. Bell and C. Volinsky. 2009. Matrix factorization techniques for recommender systems. Computer 42 8 (2009) 30\u201337.","DOI":"10.1109\/MC.2009.263"},{"key":"e_1_3_2_70_2","doi-asserted-by":"crossref","unstructured":"S. K. T. Lam D. Frankowski and J. Riedl. 2006. Do you trust your recommendations? An exploration of security and privacy issues in recommender systems. In International Conference on Emerging Trends in Information and Communication Security. Berlin Heidelberg: Springer Berlin Heidelberg 14\u201329.","DOI":"10.1007\/11766155_2"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988726"},{"key":"e_1_3_2_72_2","first-page":"1885","volume-title":"NIPS","author":"Li Bo","year":"2016","unstructured":"Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. In NIPS. 1885\u20131893."},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462814"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411884"},{"key":"e_1_3_2_75_2","doi-asserted-by":"crossref","unstructured":"C. Lin S. Chen M. Zeng S. Zhang M. Gao and H. Li. 2022. Shilling black-box recommender systems by learning to generate fake user profiles. IEEE Transactions on Neural Networks and Learning Systems 35 1 (2022) 1305\u20131319.","DOI":"10.1109\/TNNLS.2022.3183210"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC49032.2021.9369553"},{"key":"e_1_3_2_77_2","first-page":"3590","volume-title":"WWW","author":"Liu Zhuoran","year":"2021","unstructured":"Zhuoran Liu and Martha Larson. 2021. Adversarial item promotion: Vulnerabilities at the core of Top-N recommenders that use images to address cold start. In WWW. 3590\u20133602."},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/1655077.1655081"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/3457607"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/1216295.1216307"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/1297231.1297240"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1145\/1390334.1390350"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11257-008-9050-4"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1145\/2379776.2379786"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2687258"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1145\/1278366.1278372"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2880197"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1145\/3567420"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-46146-9_49"},{"key":"e_1_3_2_90_2","volume-title":"Parameter Estimation for the Beta Distribution","author":"Owen Claire B.","year":"2008","unstructured":"Claire B. Owen. 2008. Parameter Estimation for the Beta Distribution. Brigham Young University."},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1145\/3459991"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453160"},{"key":"e_1_3_2_93_2","unstructured":"K. Periyasamy J. Jaiganesh K. Ponnambalam J. Rajasekar and K. Arputharaj. 2017. Analysis and performance evaluation of cosine neighbourhood recommender system. International Arab Journal of Information Technology (IAJIT) 14 5 (2017)."},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2019.100199"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-65172-9_43"},{"key":"e_1_3_2_96_2","doi-asserted-by":"crossref","unstructured":"S. Pouyanfar S. Sadiq Y. Yan H. Tian Y. Tao M. P. Reyes M. L. Shyu S. C. Chen and S. S. Iyengar. 2018. A survey on deep learning: Algorithms techniques and applications. ACM Computing Surveys (CSUR) 51 5 (2018) 1\u201336.","DOI":"10.1145\/3234150"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-020-09898-3"},{"key":"e_1_3_2_98_2","doi-asserted-by":"crossref","unstructured":"F. Ricci L. Rokach and B. Shapira. 2010. Introduction to recommender systems handbook. In Recommender Systems Handbook. Boston MA: springer US 1\u201335.","DOI":"10.1007\/978-0-387-85820-3_1"},{"key":"e_1_3_2_99_2","article-title":"Poisoning deep learning based recommender model in federated learning scenarios","author":"Rong Dazhong","year":"2022","unstructured":"Dazhong Rong, Qinming He, and Jianhai Chen. 2022. Poisoning deep learning based recommender model in federated learning scenarios. arXiv preprint arXiv:2204.13594 (2022).","journal-title":"arXiv preprint arXiv:2204.13594"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"issue":"2","key":"e_1_3_2_101_2","first-page":"8","article-title":"A survey on recommender systems based on collaborative filtering technique","volume":"2","author":"Sachan Atisha","year":"2013","unstructured":"Atisha Sachan and Vineet Richariya. 2013. A survey on recommender systems based on collaborative filtering technique. Int. J. Inf. Educ. Technol. 2, 2 (2013), 8\u201314.","journal-title":"Int. J. Inf. Educ. Technol."},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1145\/1390156.1390267"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1145\/1297231.1297249"},{"key":"e_1_3_2_104_2","article-title":"Pearson\u2019s correlation coefficient","volume":"345","author":"Sedgwick Philip","year":"2012","unstructured":"Philip Sedgwick. 2012. Pearson\u2019s correlation coefficient. Brit. Med. J. 345 (2012).","journal-title":"Brit. Med. J."},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","unstructured":"G. Shani and A. Gunawardana. 2011. Evaluating recommendation systems. In Recommender Systems Handbook F. Ricci L. Rokach B. Shapira and P. Kantor (Eds.). Springer Boston MA. 10.1007\/978-0-387-85820-3_8","DOI":"10.1007\/978-0-387-85820-3_8"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1145\/2556270"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"e_1_3_2_108_2","unstructured":"J. Sidhu R. Sakhuja and D. Zhou. 2016. Attacks on eBay. Lassonde School of Engineering. https:\/\/www.eecs.yorku.ca\/course_archive\/2015-16\/W\/3482\/Team12_eBayHacks.pdf"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-020-10031-6"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00021"},{"key":"e_1_3_2_111_2","doi-asserted-by":"crossref","unstructured":"F. Strub R. Gaudel and J. Mary. 2016. Hybrid recommender system based on autoencoders. In Proceedings of the 1st Workshop on Deep Learning for Recommender Syst.","DOI":"10.1145\/2988450.2988456"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"e_1_3_2_113_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5353"},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3022962"},{"key":"e_1_3_2_115_2","doi-asserted-by":"crossref","unstructured":"Elham Tabassi Kevin Burns Michael Hadjimichael Andres Molina-Markham and Julian Sexton. 2019. A taxonomy and terminology of adversarial machine learning. Technical Report. NIST.","DOI":"10.6028\/NIST.IR.8269-draft"},{"key":"e_1_3_2_116_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3412243"},{"key":"e_1_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1145\/3280989"},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401301"},{"key":"e_1_3_2_119_2","unstructured":"J. Wang and Q. Tang. 2015. Recommender systems and their security concerns. Technical Report. University of Luxembourg."},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380170"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2019.03.003"},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11518-018-5374-8"},{"key":"e_1_3_2_123_2","first-page":"1","volume-title":"ICSSSM","author":"Wang Youquan","year":"2015","unstructured":"Youquan Wang, Lu Zhang, Haicheng Tao, Zhiang Wu, and Jie Cao. 2015. A comparative study of shilling attack detectors for recommender systems. In ICSSSM. 1\u20136."},{"key":"e_1_3_2_124_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11761-007-0013-0"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467335"},{"key":"e_1_3_2_126_2","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462914"},{"key":"e_1_3_2_127_2","article-title":"FedAttack: Effective and covert poisoning attack on federated recommendation via hard sampling","author":"Wu Chuhan","year":"2022","unstructured":"Chuhan Wu, Fangzhao Wu, Tao Qi, Yongfeng Huang, and Xing Xie. 2022. FedAttack: Effective and covert poisoning attack on federated recommendation via hard sampling. arXiv preprint arXiv:2202.04975 (2022).","journal-title":"arXiv preprint arXiv:2202.04975"},{"key":"e_1_3_2_128_2","doi-asserted-by":"crossref","unstructured":"F. Wu M. Gao J. Yu Z. Wang K. Liu and X. Wang. 2021. Ready for emerging threats to recommender systems? A graph convolution-based generative shilling attack. Information Sciences 578 (2021) 683\u2013701.","DOI":"10.1016\/j.ins.2021.07.041"},{"key":"e_1_3_2_129_2","doi-asserted-by":"publisher","DOI":"10.1145\/2339530.2339684"},{"key":"e_1_3_2_130_2","unstructured":"Z. W. Wu C. T. Chen and S. H. Huang. 2022. Poisoning attacks against knowledge graph-based recommendation systems using deep reinforcement learning. Neural Computing and Applications. 1\u201319."},{"key":"e_1_3_2_131_2","doi-asserted-by":"crossref","unstructured":"H. Xia B. Fang M. Gao H. Ma Y. Tang and J. Wen. 2015. A novel item anomaly detection approach against shilling attacks in collaborative recommendation systems using the dynamic time interval segmentation technique. Information Sciences 306 (2015) 150\u2013165.","DOI":"10.1016\/j.ins.2015.02.019"},{"key":"e_1_3_2_132_2","doi-asserted-by":"publisher","DOI":"10.21629\/JSEE.2018.04.11"},{"key":"e_1_3_2_133_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.04.012"},{"key":"e_1_3_2_134_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/447"},{"key":"e_1_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23020"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2016.08.011"},{"key":"e_1_3_2_137_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2017.02.052"},{"key":"e_1_3_2_138_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3016827"},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2016.02.008"},{"key":"e_1_3_2_140_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2021.3063735"},{"key":"e_1_3_2_141_2","article-title":"UA-FedRec: Untargeted attack on federated news recommendation","author":"Yi Jingwei","year":"2022","unstructured":"Jingwei Yi, Fangzhao Wu, Bin Zhu, Yang Yu, Chao Zhang, Guangzhong Sun, and Xing Xie. 2022. UA-FedRec: Untargeted attack on federated news recommendation. arXiv preprint arXiv:2202.06701 (2022).","journal-title":"arXiv preprint arXiv:2202.06701"},{"key":"e_1_3_2_142_2","first-page":"938","volume-title":"WWW","author":"You Xiaoyu","year":"2023","unstructured":"Xiaoyu You, Chi Li, Daizong Ding, Mi Zhang, Fuli Feng, Xudong Pan, and Min Yang. 2023. Anti-FakeU: Defending shilling attacks on graph neural network based recommender model. In WWW. 938\u2013948."},{"key":"e_1_3_2_143_2","doi-asserted-by":"crossref","unstructured":"C. Yu J. Liu S. Nemati and G. Yin. 2021. Reinforcement learning in healthcare: A survey. ACM Computing Surveys (CSUR) 55 1 (2021) 1\u201336.","DOI":"10.1145\/3477600"},{"key":"e_1_3_2_144_2","article-title":"Socially-aware self-supervised tri-training for recommendation","author":"Yu Junliang","year":"2021","unstructured":"Junliang Yu, Hongzhi Yin, Min Gao, Xin Xia, Xiangliang Zhang, and Nguyen Quoc Viet Hung. 2021. Socially-aware self-supervised tri-training for recommendation. arXiv preprint arXiv:2106.03569 (2021).","journal-title":"arXiv preprint arXiv:2106.03569"},{"key":"e_1_3_2_145_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460231.3474275"},{"key":"e_1_3_2_146_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2018.02.032"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.4304\/jcp.7.1.226-234"},{"key":"e_1_3_2_148_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2014.04.020"},{"key":"e_1_3_2_149_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-018-8052-6"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3379992"},{"key":"e_1_3_2_151_2","unstructured":"H. Zhang Y. Li B. Ding and J. Gao. 2022. LOKI: a practical data poisoning attack framework against next item recommendations. IEEE Transactions on Knowledge and Data Engineering 35 5 (2022) 5047\u20135059."},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467233"},{"key":"e_1_3_2_153_2","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783267"},{"key":"e_1_3_2_154_2","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150508"},{"key":"e_1_3_2_155_2","doi-asserted-by":"publisher","DOI":"10.1145\/3158369"},{"key":"e_1_3_2_156_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488560.3498386"},{"key":"e_1_3_2_157_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401165"},{"key":"e_1_3_2_158_2","volume-title":"IJCAI","author":"Zhang Yongfeng","year":"2015","unstructured":"Yongfeng Zhang, Yunzhi Tan, Min Zhang, Yiqun Liu, Tat-Seng Chua, and Shaoping Ma. 2015. Catch the black sheep: Unified framework for shilling attack detection based on fraudulent action propagation. In IJCAI."},{"key":"e_1_3_2_159_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484805"},{"key":"e_1_3_2_160_2","doi-asserted-by":"publisher","DOI":"10.1145\/3427920"},{"key":"e_1_3_2_161_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110072"},{"key":"e_1_3_2_162_2","doi-asserted-by":"crossref","unstructured":"Q. Zhou J. Wu and L. Duan. 2020. Recommendation attack detection based on deep learning. Journal of Information Security and Applications 52 (2020) 102493.","DOI":"10.1016\/j.jisa.2020.102493"},{"key":"e_1_3_2_163_2","doi-asserted-by":"publisher","DOI":"10.1145\/2600428.2609483"},{"key":"e_1_3_2_164_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2014.6889419"},{"key":"e_1_3_2_165_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0130968"},{"key":"e_1_3_2_166_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0196533"},{"key":"e_1_3_2_167_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2015.12.137"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3677328","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3677328","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,3]],"date-time":"2025-07-03T20:33:47Z","timestamp":1751574827000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3677328"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,7]]},"references-count":166,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1,31]]}},"alternative-id":["10.1145\/3677328"],"URL":"https:\/\/doi.org\/10.1145\/3677328","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,7]]},"assertion":[{"value":"2022-10-17","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-06-18","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-10-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}