{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:17:21Z","timestamp":1783700241450,"version":"3.55.0"},"reference-count":96,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"name":"General Research Funds from the Hong Kong Research Grants Council","award":["PolyU 15207322, 15200023, 15206024, and 15224524"],"award-info":[{"award-number":["PolyU 15207322, 15200023, 15206024, and 15224524"]}]},{"name":"Hong Kong Research Grants Council\u2019s Theme-based Research Scheme","award":["T43-513\/23-N"],"award-info":[{"award-number":["T43-513\/23-N"]}]},{"name":"Hong Kong Research Grants Council\u2019s Research Impact Fund","award":["R1015-23"],"award-info":[{"award-number":["R1015-23"]}]},{"name":"Hong Kong Research Grants Council\u2019s Collaborative Research Fund","award":["C1043-24GF"],"award-info":[{"award-number":["C1043-24GF"]}]},{"name":"internal research funds from Hong Kong Polytechnic University","award":["P0042693, P0048625, and P0051361"],"award-info":[{"award-number":["P0042693, P0048625, and P0051361"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst."],"published-print":{"date-parts":[[2026,5,31]]},"abstract":"<jats:p>\n                    Recently, Large Language Model (LLM)-empowered recommender systems have revolutionized personalized recommendation frameworks and attracted extensive attention. Despite the remarkable success, existing LLM-empowered RecSys have been demonstrated to be highly vulnerable to minor perturbations. To mitigate the negative impact of such vulnerabilities, one potential solution is to employ collaborative signals based on item\u2013item co-occurrence to purify the malicious collaborative knowledge from the user\u2019s irrelevant historical interactions. On the other hand, due to the capabilities to expand insufficient internal knowledge of LLMs, Retrieval-Augmented Generation (RAG) techniques provide unprecedented opportunities to enhance the robustness of LLM-empowered recommender systems by introducing external collaborative knowledge. Therefore, in this article, we propose a novel framework (\n                    <jats:italic toggle=\"yes\">RETURN<\/jats:italic>\n                    ) by retrieving external collaborative signals to purify the poisoned user profiles and enhance the robustness of LLM-empowered RecSys in a plug-and-play manner. Specifically, retrieval-augmented perturbation positioning is proposed to identify potential perturbations within the users\u2019 historical sequences by retrieving external knowledge from collaborative item graphs. After that, we further retrieve the collaborative knowledge to cleanse the perturbations by using either deletion or replacement strategies and introduce a robust ensemble recommendation strategy to generate final robust predictions. Extensive experiments on three real-world datasets demonstrate the effectiveness of the proposed RETURN.\n                  <\/jats:p>","DOI":"10.1145\/3795521","type":"journal-article","created":{"date-parts":[[2026,2,3]],"date-time":"2026-02-03T14:11:49Z","timestamp":1770127909000},"page":"1-42","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Retrieval-Augmented Purifier for Robust LLM-Empowered Recommendation"],"prefix":"10.1145","volume":"44","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6903-8996","authenticated-orcid":false,"given":"Liangbo","family":"Ning","sequence":"first","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong SAR"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4049-1233","authenticated-orcid":false,"given":"Wenqi","family":"Fan","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong SAR"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3370-471X","authenticated-orcid":false,"given":"Qing","family":"Li","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong SAR"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,16]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Josh Achiam Steven Adler Sandhini Agarwal Lama Ahmad Ilge Akkaya Florencia Leoni Aleman Diogo Almeida Janko Altenschmidt Sam Altman Shyamal Anadkat et al. 2023. GPT-4 technical report. arXiv:2303.08774. Retrieved from https:\/\/arxiv.org\/abs\/2303.08774"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-024-03445-1"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.01.023"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"},{"key":"e_1_3_2_6_2","volume-title":"Proceedings of the International Joint Conferences on Artificial Intelligence","author":"Bai Tao","year":"2021","unstructured":"Tao Bai, Jinqi Luo, Jun Zhao, Bihan Wen, and Qian Wang. 2021. Recent advances in adversarial training for adversarial robustness. In Proceedings of the International Joint Conferences on Artificial Intelligence."},{"key":"e_1_3_2_7_2","volume-title":"Proceedings of the ACM Conference on Recommender Systems","author":"Bao Keqin","year":"2023","unstructured":"Keqin Bao, Jizhi Zhang, Yang Zhang, Wenjie Wang, Fuli Feng, and Xiangnan He. 2023. TALLRec: An effective and efficient tuning framework to align large language model with recommendation. In Proceedings of the ACM Conference on Recommender Systems."},{"key":"e_1_3_2_8_2","unstructured":"James Bennett and Stan Lanning. 2007. The Netflix prize. In KDD Cup Workshop 3\u20136."},{"key":"e_1_3_2_9_2","volume-title":"Findings of the Association for Computational Linguistics ACL 2024","author":"Cao Bochuan","year":"2024","unstructured":"Bochuan Cao, Yuanpu Cao, Lu Lin, and Jinghui Chen. 2024. Defending against alignment-breaking attacks via robustly aligned LLM. In Findings of the Association for Computational Linguistics ACL 2024."},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.777"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/1864708.1864770"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3604915.3608889"},{"key":"e_1_3_2_13_2","doi-asserted-by":"crossref","first-page":"8363","DOI":"10.1609\/aaai.v38i8.28678","article-title":"Enhancing job recommendation through LLM-based generative adversarial networks","volume":"38","author":"Du Yingpeng","year":"2024","unstructured":"Yingpeng Du, Di Luo, Rui Yan, Xiaopei Wang, Hongzhi Liu, Hengshu Zhu, Yang Song, and Jie Zhang. 2024. Enhancing job recommendation through LLM-based generative adversarial networks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38, 8363\u20138371.","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671470"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531985"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313488"},{"key":"e_1_3_2_17_2","first-page":"2033","volume-title":"IEEE Transactions on Knowledge and Data Engineering","volume":"34","author":"Fan Wenqi","year":"2020","unstructured":"Wenqi Fan, Yao Ma, Qing Li, Jianping Wang, Guoyong Cai, Jiliang Tang, and Dawei Yin. 2020. A graph neural network framework for social recommendations. IEEE Transactions on Knowledge and Data Engineering 34, 5 (2020), 2033\u20132047."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347011"},{"issue":"6","key":"e_1_3_2_19_2","doi-asserted-by":"crossref","first-page":"7225","DOI":"10.1109\/TMC.2023.3333944","article-title":"Learning co-occurrence patterns for next destination recommendation","volume":"23","author":"Fang Hui","year":"2023","unstructured":"Hui Fang, Zhu Xiao, Pengfei Zheng, Hongyang Chen, Zhao Li, Jiajun Bu, and Haishuai Wang. 2023. Learning co-occurrence patterns for next destination recommendation. IEEE Transactions on Mobile Computing 23, 6 (2023), 7225\u20137237.","journal-title":"IEEE Transactions on Mobile Computing"},{"key":"e_1_3_2_20_2","unstructured":"Yunfan Gao Yun Xiong Xinyu Gao Kangxiang Jia Jinliu Pan Yuxi Bi Yixin Dai Jiawei Sun Haofen Wang and Haofen Wang. 2023. Retrieval-augmented generation for large language models: A survey. arXiv:2312.10997. Retrieved from https:\/\/arxiv.org\/abs\/2312.10997"},{"issue":"5","key":"e_1_3_2_21_2","doi-asserted-by":"crossref","first-page":"1158","DOI":"10.1097\/HEP.0000000000000834","article-title":"Development of a liver disease-specific large language model chat interface using retrieval augmented generation","volume":"80","author":"Ge Jin","year":"2024","unstructured":"Jin Ge, Steve Sun, Joseph Owens, Victor Galvez, Oksana Gologorskaya, Jennifer C. Lai, Mark J. Pletcher, and Ki Lai. 2024. Development of a liver disease-specific large language model chat interface using retrieval augmented generation. Hepatology 80, 5 (2024), 1158\u20131168.","journal-title":"Hepatology"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3523227.3546767"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/2843948"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-012-9364-9"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_26_2","unstructured":"Alec Helbling Mansi Phute Matthew Hull and Duen Horng Chau. 2023. LLM self defense: By self examination LLMs know they are being tricked. arXiv:2308.07308. Retrieved from https:\/\/arxiv.org\/abs\/2308.07308"},{"key":"e_1_3_2_27_2","unstructured":"Yupeng Hou Jiacheng Li Zhankui He An Yan Xiusi Chen and Julian McAuley. 2024. Bridging language and items for retrieval and recommendation. arXiv:2403.03952. Retrieved from https:\/\/arxiv.org\/abs\/2403.03952"},{"key":"e_1_3_2_28_2","unstructured":"Neel Jain Schwarzschild Avi Yuxin Wen Gowthami Somepalli John Kirchenbauer Ping-Yeh Chiang Micah Goldblum Aniruddha Saha Jonas Geiping and Tom Goldstein. 2023. Baseline defenses for adversarial attacks against aligned language models. arXiv:2309.00614. Retrieved from https:\/\/arxiv.org\/abs\/2309.00614"},{"key":"e_1_3_2_29_2","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Jin Wei","year":"2024","unstructured":"Wei Jin, Haitao Mao, Zheng Li, Haoming Jiang, Chen Luo, Hongzhi Wen, Haoyu Han, Hanqing Lu, Zhengyang Wang, Ruirui Li, et al. 2024. Amazon-M2: A multilingual multi-locale shopping session dataset for recommendation and text generation. In Proceedings of the Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00035"},{"key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"2786","DOI":"10.1145\/3626772.3657670","volume-title":"Proceedings of the 47th International ACM SIGIR Conference on Research and Development in Information Retrieval","author":"Kemper Sara","year":"2024","unstructured":"Sara Kemper, Justin Cui, Kai Dicarlantonio, Kathy Lin, Danjie Tang, Anton Korikov, and Scott Sanner. 2024. Retrieval-augmented conversational recommendation with prompt-based semi-structured natural language state tracking. In Proceedings of the 47th International ACM SIGIR Conference on Research and Development in Information Retrieval, 2786\u20132790."},{"key":"e_1_3_2_32_2","first-page":"4171","volume-title":"Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers) (NAACL-HLT)","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers) (NAACL-HLT), 4171\u20134186."},{"key":"e_1_3_2_33_2","volume-title":"Proceedings of the 12th International Conference on Learning Representations","author":"Kirchenbauer John","year":"2023","unstructured":"John Kirchenbauer, Jonas Geiping, Yuxin Wen, Manli Shu, Khalid Saifullah, Kezhi Kong, Kasun Fernando, Aniruddha Saha, Micah Goldblum, and Tom Goldstein. 2023. On the reliability of watermarks for large language models. In Proceedings of the 12th International Conference on Learning Representations."},{"key":"e_1_3_2_34_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Kitaev Nikita","unstructured":"Nikita Kitaev, Lukasz Kaiser, and Anselm Levskaya. 2020. Reformer: The efficient transformer. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/3468.618255"},{"key":"e_1_3_2_36_2","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Lewis Patrick","year":"2020","unstructured":"Patrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni, Vladimir Karpukhin, Naman Goyal, Heinrich K\u00fcttler, Mike Lewis, Wen-Tau Yih, Tim Rockt\u00e4schel, et al. 2020. Retrieval-augmented generation for knowledge-intensive NLP tasks. In Proceedings of the Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_37_2","doi-asserted-by":"crossref","first-page":"8410","DOI":"10.1609\/aaai.v35i9.17022","article-title":"Token-aware virtual adversarial training in natural language understanding","volume":"35","author":"Li Linyang","year":"2021","unstructured":"Linyang Li and Xipeng Qiu. 2021. Token-aware virtual adversarial training in natural language understanding. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 35, 8410\u20138418.","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"e_1_3_2_38_2","volume-title":"Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics","author":"Li Linyang","year":"2023","unstructured":"Linyang Li, Demin Song, and Xipeng Qiu. 2023. Text adversarial purification as defense against adversarial attacks. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics."},{"key":"e_1_3_2_39_2","unstructured":"Xiang Li Zhenyu Li Chen Shi Yong Xu Qing Du Mingkui Tan Jun Huang and Wei Lin. 2024. AlphaFin: Benchmarking financial analysis with retrieval-augmented stock-chain framework. arXiv:2403.12582. Retrieved from https:\/\/arxiv.org\/abs\/2403.12582"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714727"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2959100.2959182"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657690"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3678004"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583479"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2003.1167344"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2025.3600103"},{"key":"e_1_3_2_47_2","unstructured":"Mingjie Liu Shizhe Diao Ximing Lu Jian Hu Xin Dong Yejin Choi Jan Kautz and Yi Dong. 2025. ProRL: Prolonged reinforcement learning expands reasoning boundaries in large language models. arXiv:2505.24864. Retrieved from https:\/\/arxiv.org\/abs\/2505.24864"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313513"},{"key":"e_1_3_2_49_2","unstructured":"Xiaodong Liu Hao Cheng Pengcheng He Weizhu Chen Yu Wang Hoifung Poon and Jianfeng Gao. 2020. Adversarial training for large neural language models. arXiv:2004.08994. Retrieved from https:\/\/arxiv.org\/abs\/2004.08994"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3604915.3608835"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhm.2020.102697"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/3701228"},{"key":"e_1_3_2_53_2","unstructured":"Yanxu Mao Tiehan Cui Peipei Liu Datao You and Hongsong Zhu. 2025. From LLMs to MLLMs to agents: A survey of emerging paradigms in jailbreak attacks and defenses within LLM ecosystem. arXiv:2506.15170. Retrieved from https:\/\/arxiv.org\/abs\/2506.15170"},{"key":"e_1_3_2_54_2","unstructured":"Wenjie Mo Jiashu Xu Qin Liu Jiongxiao Wang Jun Yan Chaowei Xiao and Muhao Chen. 2023. Test-time backdoor mitigation for black-box large language models with defensive demonstrations. arXiv:2311.09763. Retrieved from https:\/\/arxiv.org\/abs\/2311.09763"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3711896.3736555"},{"key":"e_1_3_2_56_2","doi-asserted-by":"crossref","first-page":"2284","DOI":"10.1145\/3637528.3671837","volume-title":"Proceedings of the ACM SIGKDD Conference on Knowledge Discovery and Data Mining","author":"Ning Liang-Bo","year":"2024","unstructured":"Liang-Bo Ning, Shijie Wang, Wenqi Fan, Qing Li, Xin Xu, Hao Chen, and Feiran Huang. 2024. CheatAgent: Attacking LLM-empowered recommender systems via LLM agent. In Proceedings of the ACM SIGKDD Conference on Knowledge Discovery and Data Mining, 2284\u20132295."},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3077136.3080724"},{"key":"e_1_3_2_58_2","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Penedo Guilherme","year":"2024","unstructured":"Guilherme Penedo, Quentin Malartic, Daniel Hesslow, Ruxandra Cojocaru, Hamza Alobeidli, Alessandro Cappelli, Baptiste Pannier, Ebtesam Almazrouei, and Julien Launay. 2024. The RefinedWeb dataset for Falcon LLM: Outperforming curated corpora with web data only. In Proceedings of the Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_59_2","first-page":"1667","volume-title":"Proceedings of the 2020 IEEE 36th International Conference on Data Engineering (ICDE)","author":"Pfadler Andreas","year":"2020","unstructured":"Andreas Pfadler, Huan Zhao, Jizhe Wang, Lifeng Wang, Pipei Huang, and Dik Lun Lee. 2020. Billion-scale recommendation with heterogeneous side information at Taobao. In Proceedings of the 2020 IEEE 36th International Conference on Data Engineering (ICDE). IEEE, 1667\u20131676."},{"key":"e_1_3_2_60_2","doi-asserted-by":"crossref","first-page":"1882","DOI":"10.18653\/v1\/2020.acl-main.170","volume-title":"Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics","author":"Provilkov Ivan","year":"2020","unstructured":"Ivan Provilkov, Dmitrii Emelianenko, and Elena Voita. 2020. BPE-dropout: Simple and effective subword regularization. In Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics. Association for Computational Linguistics, 1882\u20131892. Retrieved from https:\/\/www.aclweb.org\/anthology\/2020.acl-main.170"},{"key":"e_1_3_2_61_2","unstructured":"Haohao Qu Wenqi Fan Zihuai Zhao and Qing Li. 2024. TokenRec: Learning to tokenize ID for LLM-based generative recommendation. arXiv:2406.10450. Retrieved from https:\/\/arxiv.org\/abs\/2406.10450"},{"key":"e_1_3_2_62_2","unstructured":"Haohao Qu Liangbo Ning Rui An Wenqi Fan Tyler Derr Xin Xu and Qing Li. 2024. A survey of Mamba. arXiv:2408.01129. Retrieved from https:\/\/arxiv.org\/abs\/2408.01129"},{"key":"e_1_3_2_63_2","volume-title":"Proceedings of the 47th International ACM SIGIR Conference on Research and Development in Information Retrieval","author":"Ren Yankun","year":"2024","unstructured":"Yankun Ren, Zhongde Chen, Xinxing Yang, Longfei Li, Cong Jiang, Lei Cheng, Bo Zhang, Linjian Mo, and Jun Zhou. 2024. Enhancing sequential recommenders with augmented knowledge from aligned large language models. In Proceedings of the 47th International ACM SIGIR Conference on Research and Development in Information Retrieval."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531889"},{"key":"e_1_3_2_66_2","first-page":"13176","volume-title":"Findings of the Association for Computational Linguistics","author":"Tsai Alicia","year":"2024","unstructured":"Alicia Tsai, Adam Kraft, Long Jin, Chenwei Cai, Anahita Hosseini, Taibai Xu, Zemin Zhang, Lichan Hong, Ed Chi, and Xinyang Yi. 2024. Leveraging LLM reasoning enhances personalized recommender systems. In Findings of the Association for Computational Linguistics, 13176\u201313188."},{"key":"e_1_3_2_67_2","volume-title":"Findings of the Association for Computational Linguistics ACL 2024","author":"Varshney Neeraj","year":"2024","unstructured":"Neeraj Varshney, Pavel Dolin, Agastya Seth, and Chitta Baral. 2024. The art of defending: A systematic evaluation and analysis of LLM defense strategies on safety and over-defensiveness. In Findings of the Association for Computational Linguistics ACL 2024."},{"key":"e_1_3_2_68_2","unstructured":"Maxim Kuznetsov and Vladimir Vorobev. 2023. A Paraphrasing Model Based on ChatGPT Paraphrases. Retrieved from https:\/\/huggingface.co\/humarin\/chatgpt_paraphraser_on_T5_base"},{"key":"e_1_3_2_69_2","doi-asserted-by":"crossref","unstructured":"Bohao Wang Feng Liu Changwang Zhang Jiawei Chen Yudi Wu Sheng Zhou Xingyu Lou Jun Wang Yan Feng Chun Chen et al. 2024. LLM4DSR: Leveraging large language model for denoising sequential recommendation. arXiv:2408.08208. Retrieved from https:\/\/arxiv.org\/abs\/2408.08208","DOI":"10.1145\/3762182"},{"key":"e_1_3_2_70_2","first-page":"6555","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Wang Dilin","year":"2019","unstructured":"Dilin Wang, Chengyue Gong, and Qiang Liu. 2019. Improving neural language modeling via adversarial training. In Proceedings of the International Conference on Machine Learning. PMLR, 6555\u20136565."},{"key":"e_1_3_2_71_2","first-page":"27152","volume-title":"Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics","author":"Wang Shijie","year":"2025","unstructured":"Shijie Wang, Wenqi Fan, Yue Feng, Lin Shanru, Xinyu Ma, Shuaiqiang Wang, and Dawei Yin. 2025. Knowledge graph retrieval-augmented generation for LLM-based recommendation. In Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics, 27152\u201327168."},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3437963.3441800"},{"key":"e_1_3_2_73_2","first-page":"1288","volume-title":"Proceedings of the International ACM SIGIR Conference on Research and Development in Information Retrieval","author":"Wang Wenjie","year":"2021","unstructured":"Wenjie Wang, Fuli Feng, Xiangnan He, Hanwang Zhang, and Tat-Seng Chua. 2021. Clicks can be cheating: Counterfactual recommendation for mitigating clickbait issue. In Proceedings of the International ACM SIGIR Conference on Research and Development in Information Retrieval, 1288\u20131297."},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380186"},{"key":"e_1_3_2_75_2","first-page":"2757","volume-title":"Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics","author":"Wang Zhaoyang","year":"2023","unstructured":"Zhaoyang Wang, Zhiyue Liu, Xiaopeng Zheng, Qinliang Su, and Jiahai Wang. 2023. RMLM: A flexible defense framework for proactively mitigating word-level adversarial attacks. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics, 2757\u20132774."},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475665"},{"key":"e_1_3_2_77_2","unstructured":"Zeming Wei Yifei Wang and Yisen Wang. 2023. Jailbreak and guard aligned language models with only few in-context demonstrations. arXiv:2310.06387. Retrieved from https:\/\/arxiv.org\/abs\/2310.06387"},{"key":"e_1_3_2_78_2","first-page":"4003","volume-title":"Proceedings of the 12th Language Resources and Evaluation Conference","author":"Wenzek Guillaume","year":"2020","unstructured":"Guillaume Wenzek, Marie-Anne Lachaux, Alexis Conneau, Vishrav Chaudhary, Francisco Guzm\u00e1n, Armand Joulin, and \u00c9douard Grave. 2020. CCNet: Extracting high quality monolingual datasets from web crawl data. In Proceedings of the 12th Language Resources and Evaluation Conference, 4003\u20134012."},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671901"},{"key":"e_1_3_2_80_2","unstructured":"Sophie Xhonneux Alessandro Sordoni Stephan G\u00fcnnemann Gauthier Gidel and Leo Schwinn. 2024. Efficient adversarial training in LLMs with continuous attacks. arXiv:2405.15589. Retrieved from https:\/\/arxiv.org\/abs\/2405.15589"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657883"},{"key":"e_1_3_2_82_2","volume-title":"Proceedings of the 12th International Conference on Learning Representations","author":"Xu Xilie","year":"2024","unstructured":"Xilie Xu, Keyi Kong, Ning Liu, Lizhen Cui, Di Wang, Jingfeng Zhang, and Mohan Kankanhalli. 2024. An LLM can fool itself: A prompt-based adversarial attack. In Proceedings of the 12th International Conference on Learning Representations."},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2024.100211"},{"key":"e_1_3_2_84_2","unstructured":"Sibo Yi Yule Liu Zhen Sun Tianshuo Cong Xinlei He Jiaxing Song Ke Xu and Qi Li. 2024. Jailbreak attacks and defenses against large language models: A survey. arXiv:2407.04295. Retrieved from https:\/\/arxiv.org\/abs\/2407.04295"},{"key":"e_1_3_2_85_2","first-page":"10300","volume-title":"Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing","author":"Yu Jianxing","year":"2024","unstructured":"Jianxing Yu, Shiqi Wang, Han Yin, Zhenlong Sun, Ruobing Xie, Bo Zhang, and Yanghui Rao. 2024. Multimodal clickbait detection by de-confounding biases using causal representation inference. In Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing, 10300\u201310317."},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1145\/3511808.3557348"},{"key":"e_1_3_2_87_2","first-page":"5839","volume-title":"Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics","author":"Zhang Jinghao","year":"2024","unstructured":"Jinghao Zhang, Yuting Liu, Qiang Liu, Shu Wu, Guibing Guo, and Liang Wang. 2024. Stealthy attack on large language model based recommendation. In Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics, 5839\u20135857."},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1145\/3640457.3688120"},{"key":"e_1_3_2_89_2","doi-asserted-by":"crossref","unstructured":"Kaike Zhang Qi Cao Yunfan Wu Fei Sun Huawei Shen and Xueqi Cheng. 2024. LoRec: Large language model for robust sequential recommendation against poisoning attacks. arXiv:2401.17723. Retrieved from https:\/\/arxiv.org\/abs\/2401.17723","DOI":"10.1145\/3626772.3657684"},{"key":"e_1_3_2_90_2","first-page":"2942","volume-title":"IEEE Transactions on Knowledge and Data Engineering","volume":"36","author":"Zhang Liang","year":"2024","unstructured":"Liang Zhang, Guannan Liu, Xiaohui Liu, and Junjie Wu. 2024. Denoising item graph with disentangled learning for recommendation. IEEE Transactions on Knowledge and Data Engineering 36, 7 (2024), 2942\u20132955."},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401165"},{"key":"e_1_3_2_92_2","unstructured":"Zhen Zhang Guanhua Zhang Bairu Hou Wenqi Fan Qing Li Sijia Liu Yang Zhang and Shiyu Chang. 2023. Certified robustness for large language models with self-denoising. arXiv:2307.07171. Retrieved from https:\/\/arxiv.org\/abs\/2307.07171"},{"key":"e_1_3_2_93_2","first-page":"6889","volume-title":"IEEE Transactions on Knowledge and Data Engineering","volume":"36","author":"Zhao Zihuai","year":"2024","unstructured":"Zihuai Zhao, Wenqi Fan, Jiatong Li, Yunqing Liu, Xiaowei Mei, Yiqi Wang, Zhen Wen, Fei Wang, Xiangyu Zhao, Jiliang Tang, et al. 2024. Recommender systems in the era of large language models. IEEE Transactions on Knowledge and Data Engineering 36, 11 (2024), 6889\u20136907."},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE60146.2024.00118"},{"key":"e_1_3_2_95_2","unstructured":"Ziang Zhou Zhihao Ding Jieming Shi Qing Li and Shiqi Shen. 2024. TINED: GNNs-to-MLPs by teacher injection and Dirichlet energy distillation. arXiv:2412.11180. Retrieved from https:\/\/arxiv.org\/abs\/2412.11180"},{"key":"e_1_3_2_96_2","first-page":"42644","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Zhou Ziang","year":"2023","unstructured":"Ziang Zhou, Jieming Shi, Renchi Yang, Yuanhang Zou, and Qing Li. 2023. SlotGAT: Slot-based message passing for heterogeneous graphs. In Proceedings of the International Conference on Machine Learning. PMLR, 42644\u201342657."},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219826"}],"container-title":["ACM Transactions on Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3795521","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T15:22:37Z","timestamp":1776352957000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3795521"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,16]]},"references-count":96,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,5,31]]}},"alternative-id":["10.1145\/3795521"],"URL":"https:\/\/doi.org\/10.1145\/3795521","relation":{},"ISSN":["1046-8188","1558-2868"],"issn-type":[{"value":"1046-8188","type":"print"},{"value":"1558-2868","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,16]]},"assertion":[{"value":"2025-04-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-13","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}