{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T02:30:35Z","timestamp":1783737035898,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","funder":[{"name":"Discovery Early Career Research Award of Australian Research Council","award":["Grant No. DE250100613"],"award-info":[{"award-number":["Grant No. DE250100613"]}]},{"name":"Linkage Project of Australian Research Council","award":["Grant No. LP230200892 and LP240200546"],"award-info":[{"award-number":["Grant No. LP230200892 and LP240200546"]}]},{"name":"the National Natural Science Foundation of China","award":["Grant No. 62176028"],"award-info":[{"award-number":["Grant No. 62176028"]}]},{"name":"Discovery Project of Australian Research Council","award":["Grant No. DP240101108"],"award-info":[{"award-number":["Grant No. DP240101108"]}]},{"name":"Graduate Program Core Curriculum of Chongqing University","award":["Grant No. 20210636"],"award-info":[{"award-number":["Grant No. 20210636"]}]},{"name":"Industrial Transformation Training Centre of Australian Research Council","award":["Grant No. IC200100022"],"award-info":[{"award-number":["Grant No. IC200100022"]}]},{"name":"Future Fellowship of Australian Research Council","award":["Grant No. FT210100624"],"award-info":[{"award-number":["Grant No. FT210100624"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,7,13]]},"DOI":"10.1145\/3726302.3730003","type":"proceedings-article","created":{"date-parts":[[2025,7,14]],"date-time":"2025-07-14T01:25:28Z","timestamp":1752456328000},"page":"1902-1911","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["ID-Free Not Risk-Free: LLM-Powered Agents Unveil Risks in ID-Free Recommender Systems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9774-4596","authenticated-orcid":false,"given":"Zongwei","family":"Wang","sequence":"first","affiliation":[{"name":"Chongqing University, Chongqing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0127-7477","authenticated-orcid":false,"given":"Min","family":"Gao","sequence":"additional","affiliation":[{"name":"Chongqing University, Chongqing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3401-9829","authenticated-orcid":false,"given":"Junliang","family":"Yu","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1146-8925","authenticated-orcid":false,"given":"Xinyi","family":"Gao","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9687-1315","authenticated-orcid":false,"given":"Quoc Viet Hung","family":"Nguyen","sequence":"additional","affiliation":[{"name":"Griffith University, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6739-4145","authenticated-orcid":false,"given":"Shazia","family":"Sadiq","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1395-261X","authenticated-orcid":false,"given":"Hongzhi","family":"Yin","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,7,13]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Scaling Synthetic Data Creation with 1,000,000,000 Personas. arXiv:2406.20094","author":"Chan Xin","year":"2024","unstructured":"Xin Chan, Xiaoyang Wang, Dian Yu, Haitao Mi, and Dong Yu. 2024. Scaling Synthetic Data Creation with 1,000,000,000 Personas. arXiv:2406.20094 (2024)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539359"},{"key":"e_1_3_2_1_3_1","volume-title":"Nguyen Quoc Viet Hung, and Hongzhi Yin","author":"Chen Lijian","year":"2024","unstructured":"Lijian Chen, Wei Yuan, Tong Chen, Guanhua Ye, Nguyen Quoc Viet Hung, and Hongzhi Yin. 2024. Adversarial item promotion on visually-aware recommender systems by guided diffusion. ACM Transactions on Information Systems (2024)."},{"key":"e_1_3_2_1_4_1","volume-title":"Agentverse: Facilitating multi-agent collaboration and exploring emergent behaviors in agents. arXiv preprint arXiv:2308.10848","author":"Chen Weize","year":"2023","unstructured":"Weize Chen, Yusheng Su, Jingwei Zuo, Cheng Yang, Chenfei Yuan, Chen Qian, Chi-Min Chan, Yujia Qin, Yaxi Lu, Ruobing Xie, et al. 2023. Agentverse: Facilitating multi-agent collaboration and exploring emergent behaviors in agents. arXiv preprint arXiv:2308.10848 (2023)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599502"},{"key":"e_1_3_2_1_6_1","volume-title":"Zero-shot recommender systems. arXiv preprint arXiv:2105.08318","author":"Ding Hao","year":"2021","unstructured":"Hao Ding, Yifei Ma, Anoop Deoras, Yuyang Wang, and Hao Wang. 2021. Zero-shot recommender systems. arXiv preprint arXiv:2105.08318 (2021)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615073"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467390"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401063"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539381"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615062"},{"key":"e_1_3_2_1_12_1","volume-title":"Recommender ai agent: Integrating large language models for interactive recommendations. arXiv preprint arXiv:2308.16505","author":"Huang Xu","year":"2023","unstructured":"Xu Huang, Jianxun Lian, Yuxuan Lei, Jing Yao, Defu Lian, and Xing Xie. 2023. Recommender ai agent: Integrating large language models for interactive recommendations. arXiv preprint arXiv:2308.16505 (2023)."},{"key":"e_1_3_2_1_13_1","unstructured":"Yue Huang Chujie Gao Siyuan Wu Haoran Wang Xiangqi Wang Yujun Zhou Yanbo Wang Jiayi Ye Jiawen Shi Qihui Zhang et al. 2025. On the trustworthiness of generative foundation models: Guideline assessment and perspective. arXiv preprint arXiv:2502.14296 (2025)."},{"key":"e_1_3_2_1_14_1","volume-title":"Nguyen Thanh Tam, Matthias Weidlich, Hongzhi Yin, and Xiaofang Zhou.","author":"Viet Hung Nguyen Quoc","year":"2017","unstructured":"Nguyen Quoc Viet Hung, Huynh Huu Viet, Nguyen Thanh Tam, Matthias Weidlich, Hongzhi Yin, and Xiaofang Zhou. 2017. Computing crowd consensus with partial agreement. IEEE Transactions on Knowledge and Data Engineering (2017)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00035"},{"key":"e_1_3_2_1_17_1","volume-title":"Mojtaba Heidarysafa, Sanjana Mendu, Laura Barnes, and Donald Brown.","author":"Kowsari Kamran","year":"2019","unstructured":"Kamran Kowsari, Kiana Jafari Meimandi, Mojtaba Heidarysafa, Sanjana Mendu, Laura Barnes, and Donald Brown. 2019. Text classification algorithms: A survey. Information (2019)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988726"},{"key":"e_1_3_2_1_19_1","volume-title":"Data poisoning attacks on factorization-based collaborative filtering. Advances in neural information processing systems","author":"Li Bo","year":"2016","unstructured":"Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. Advances in neural information processing systems (2016)."},{"key":"e_1_3_2_1_20_1","volume-title":"Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271","author":"Li Jinfeng","year":"2018","unstructured":"Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. 2018. Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271 (2018)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599519"},{"key":"e_1_3_2_1_22_1","volume-title":"Pasquale De Meo, and Hocine Cherifi","author":"Liu Xiaoyang","year":"2025","unstructured":"Xiaoyang Liu, Ziyang Zhang, Xiaoqin Zhang, Pasquale De Meo, and Hocine Cherifi. 2025. Multi-supervisor association network cold start recommendation based on meta-learning. Expert Systems with Applications (2025)."},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 2004 conference on empirical methods in natural language processing. 404--411","author":"Mihalcea Rada","year":"2004","unstructured":"Rada Mihalcea and Paul Tarau. 2004. Textrank: Bringing order into text. In Proceedings of the 2004 conference on empirical methods in natural language processing. 404--411."},{"key":"e_1_3_2_1_24_1","volume-title":"Thanh Tam Nguyen, Thanh Trung Huynh, Thanh Thi Nguyen, Matthias Weidlich, and Hongzhi Yin.","author":"Nguyen Thanh Toan","year":"2024","unstructured":"Thanh Toan Nguyen, Nguyen Quoc Viet Hung, Thanh Tam Nguyen, Thanh Trung Huynh, Thanh Thi Nguyen, Matthias Weidlich, and Hongzhi Yin. 2024. Manipulating recommender systems: A survey of poisoning attacks and countermeasures. Comput. Surveys (2024)."},{"key":"e_1_3_2_1_25_1","volume-title":"Thanh Tam Nguyen, Thanh Trung Huynh, Viet Hung Vu, Phi Le Nguyen, Jun Jo, and Quoc Viet Hung Nguyen.","author":"Thanh Toan Nguyen","year":"2023","unstructured":"Toan Nguyen Thanh, Nguyen Duc Khang Quach, Thanh Tam Nguyen, Thanh Trung Huynh, Viet Hung Vu, Phi Le Nguyen, Jun Jo, and Quoc Viet Hung Nguyen. 2023. Poisoning GNN-based recommender systems with generative surrogate-based attacks. ACM Transactions on Information Systems (2023)."},{"key":"e_1_3_2_1_26_1","volume-title":"Adversarial Text Rewriting for Text-aware Recommender Systems. arXiv preprint arXiv:2408.00312","author":"Oh Sejoon","year":"2024","unstructured":"Sejoon Oh, Gaurav Verma, and Srijan Kumar. 2024. Adversarial Text Rewriting for Text-aware Recommender Systems. arXiv preprint arXiv:2408.00312 (2024)."},{"key":"e_1_3_2_1_27_1","volume-title":"Chatlog: Recording and analyzing chatgpt across time. arXiv:2304.14106","author":"Tu Shangqing","year":"2023","unstructured":"Shangqing Tu, Chunyang Li, Jifan Yu, Xiaozhi Wang, Lei Hou, and Juanzi Li. 2023. Chatlog: Recording and analyzing chatgpt across time. arXiv:2304.14106 (2023)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Ahmet Murat Turk and Alper Bilge. 2019. Robustness Analysis of Multi-criteria Collaborative Filtering Algorithms against Shilling Attacks. Expert Syst. Appl. (2019) 386--402.","DOI":"10.1016\/j.eswa.2018.08.001"},{"key":"e_1_3_2_1_29_1","volume-title":"Voyager: An open-ended embodied agent with large language models. arXiv preprint arXiv:2305.16291","author":"Wang Guanzhi","year":"2023","unstructured":"Guanzhi Wang, Yuqi Xie, Yunfan Jiang, Ajay Mandlekar, Chaowei Xiao, Yuke Zhu, Linxi Fan, and Anima Anandkumar. 2023b. Voyager: An open-ended embodied agent with large language models. arXiv preprint arXiv:2305.16291 (2023)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Lei Wang Chen Ma Xueyang Feng Zeyu Zhang Hao Yang Jingsen Zhang Zhiyuan Chen Jiakai Tang Xu Chen Yankai Lin et al. 2024a. A survey on large language model based autonomous agents. Frontiers of Computer Science (2024).","DOI":"10.1007\/s11704-024-40231-1"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i16.17648"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3512352"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599324"},{"key":"e_1_3_2_1_34_1","volume-title":"Poisoning Attacks and Defenses in Recommender Systems: A Survey. arXiv preprint arXiv:2406.01022","author":"Wang Zongwei","year":"2024","unstructured":"Zongwei Wang, Junliang Yu, Min Gao, Guanhua Ye, Shazia Sadiq, and Hongzhi Yin. 2024b. Poisoning Attacks and Defenses in Recommender Systems: A Survey. arXiv preprint arXiv:2406.01022 (2024)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671795"},{"key":"e_1_3_2_1_36_1","volume-title":"Denny Zhou, et al.","author":"Wei Jason","year":"2022","unstructured":"Jason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma, Fei Xia, Ed Chi, Quoc V Le, Denny Zhou, et al. 2022. Chain-of-thought prompting elicits reasoning in large language models. Advances in neural information processing systems, Vol. 35 (2022), 24824--24837."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583206"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475665"},{"key":"e_1_3_2_1_39_1","volume-title":"Ready for emerging threats to recommender systems? A graph convolution-based generative shilling attack. Information Sciences","author":"Wu Fan","year":"2021","unstructured":"Fan Wu, Min Gao, Junliang Yu, Zongwei Wang, Kecheng Liu, and Xu Wang. 2021. Ready for emerging threats to recommender systems? A graph convolution-based generative shilling attack. Information Sciences (2021)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"e_1_3_2_1_41_1","volume-title":"William Yang Wang, and Haifeng Chen","author":"Yang Xianjun","year":"2023","unstructured":"Xianjun Yang, Wei Cheng, Yue Wu, Linda Petzold, William Yang Wang, and Haifeng Chen. 2023. Dna-gpt: Divergent n-gram analysis for training-free detection of gpt-generated text. arXiv preprint arXiv:2305.17359 (2023)."},{"key":"e_1_3_2_1_42_1","volume-title":"Proceedings of the 45th International ACM SIGIR Conference on Research and Development in Information Retrieval. 1294--1303","author":"Yu Junliang","year":"2022","unstructured":"Junliang Yu, Hongzhi Yin, Xin Xia, Tong Chen, Lizhen Cui, and Quoc Viet Hung Nguyen. 2022. Are graph augmentations necessary? simple graph contrastive learning for recommendation. In Proceedings of the 45th International ACM SIGIR Conference on Research and Development in Information Retrieval. 1294--1303."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591722"},{"key":"e_1_3_2_1_44_1","volume-title":"Quoc Viet Hung Nguyen, and Hongzhi Yin","author":"Yuan Wei","year":"2025","unstructured":"Wei Yuan, Chaoqun Yang, Liang Qu, Guanhua Ye, Quoc Viet Hung Nguyen, and Hongzhi Yin. 2025. Robust federated contrastive recommender system against targeted model poisoning attack. Science China Information Sciences (2025)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591932"},{"key":"e_1_3_2_1_46_1","volume-title":"Stealthy attack on large language model based recommendation. arXiv preprint arXiv:2402.14836","author":"Zhang Jinghao","year":"2024","unstructured":"Jinghao Zhang, Yuting Liu, Qiang Liu, Shu Wu, Guibing Guo, and Liang Wang. 2024. Stealthy attack on large language model based recommendation. arXiv preprint arXiv:2402.14836 (2024)."},{"key":"e_1_3_2_1_47_1","unstructured":"Wayne Xin Zhao Kun Zhou Junyi Li Tianyi Tang Xiaolei Wang Yupeng Hou Yingqian Min Beichen Zhang Junjie Zhang Zican Dong et al. 2023. A survey of large language models. arXiv preprint arXiv:2303.18223 (2023)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657814"}],"event":{"name":"SIGIR '25: The 48th International ACM SIGIR Conference on Research and Development in Information Retrieval","location":"Padua Italy","acronym":"SIGIR '25","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval"]},"container-title":["Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3726302.3730003","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T12:19:36Z","timestamp":1755865176000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3726302.3730003"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,13]]},"references-count":48,"alternative-id":["10.1145\/3726302.3730003","10.1145\/3726302"],"URL":"https:\/\/doi.org\/10.1145\/3726302.3730003","relation":{},"subject":[],"published":{"date-parts":[[2025,7,13]]},"assertion":[{"value":"2025-07-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}