{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T16:15:06Z","timestamp":1778948106364,"version":"3.51.4"},"reference-count":80,"publisher":"Association for Computing Machinery (ACM)","issue":"4","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62376086 and 72188101"],"award-info":[{"award-number":["62376086 and 72188101"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities of China","doi-asserted-by":"crossref","award":["JZ2025HGTG0289, PA2025IISL0114"],"award-info":[{"award-number":["JZ2025HGTG0289, PA2025IISL0114"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Inf. Syst."],"published-print":{"date-parts":[[2026,5,31]]},"abstract":"<jats:p>\n                    Recommender Systems (RS) have been widely adopted to provide personalized suggestions based on historical user behaviors. However, some users are hesitant to allow RS to learn their preferences at the expense of their privacy information. Therefore, these users prefer to hide their preferences from RS. In this article, we consider this practical yet important question: can privacy-concerned users make RS unavailable to learn their preferences? The challenge lies in achieving this goal while complying with real-world constraints. Normal users still expect accurate recommendations; the scope should target privacy-concerned users. Also, as most companies do not allow users to delete their implicit feedback, the solution cannot rely on data deletion. To this end, we propose a novel\n                    <jats:italic toggle=\"yes\">ULRec<\/jats:italic>\n                    from the perspective of fake interaction generation, a general method for making preferences of privacy-concerned users\n                    <jats:italic toggle=\"yes\">U<\/jats:italic>\n                    n\n                    <jats:italic toggle=\"yes\">L<\/jats:italic>\n                    earnable to personalized\n                    <jats:italic toggle=\"yes\">Rec<\/jats:italic>\n                    ommendation algorithms. First, we formulate the constraints of the data attack based on practical considerations. Then, we define a bi-level optimization process, where the outer loop updates data addition, and the inner loop dynamically updates RS parameters. After that, we propose a loss function that simultaneously considers the requests of both privacy-concerned users and normal users. To ensure the feasible range and model efficiency, we adopt projected gradient descent and automatic differentiation. Finally, extensive experiments on three real-world datasets have demonstrated the effectiveness of our proposed\n                    <jats:italic toggle=\"yes\">ULRec<\/jats:italic>\n                    .\n                  <\/jats:p>","DOI":"10.1145\/3803545","type":"journal-article","created":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T14:24:02Z","timestamp":1774448642000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Privacy Matters: Data Attack to Make User Preferences Unlearnable in Recommendation"],"prefix":"10.1145","volume":"44","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2838-1987","authenticated-orcid":false,"given":"Pengyang","family":"Shao","sequence":"first","affiliation":[{"name":"Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4556-0581","authenticated-orcid":false,"given":"Le","family":"Wu","sequence":"additional","affiliation":[{"name":"Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0743-9003","authenticated-orcid":false,"given":"Kun","family":"Zhang","sequence":"additional","affiliation":[{"name":"Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-2942-257X","authenticated-orcid":false,"given":"Lei","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3094-7735","authenticated-orcid":false,"given":"Meng","family":"Wang","sequence":"additional","affiliation":[{"name":"Hefei University of Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,5,11]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3522672"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3511997"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3144"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3373807"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564284"},{"key":"e_1_3_2_7_2","unstructured":"Jinyin Chen Yangyang Wu Xuanheng Xu Yixian Chen Haibin Zheng and Qi Xuan. 2018. Fast gradient attack on network embedding. arXiv:1809.02797. Retrieved from https:\/\/arxiv.org\/abs\/1809.02797"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1002\/ett.3872"},{"key":"e_1_3_2_9_2","unstructured":"Lijian Chen Wei Yuan Tong Chen Nguyen Quoc Viet Hung Lizhen Cui and Hongzhi Yin. 2023. Adversarial item promotion on visually-aware recommender systems by guided diffusion. arXiv:2312.15826. Retrieved from https:\/\/arxiv.org\/abs\/2312.15826"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3638352"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2020408.2020579"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3706633"},{"key":"e_1_3_2_13_2","volume-title":"Proceedings of International Conference on Learning Representations","author":"Fu Shaopeng","year":"2021","unstructured":"Shaopeng Fu, Fengxiang He, Yang Liu, Li Shen, and Dacheng Tao. 2021. Robust unlearnable examples: Protecting data privacy against adversarial learning. In Proceedings of International Conference on Learning Representations."},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3594871"},{"key":"e_1_3_2_15_2","unstructured":"Edward Grefenstette Brandon Amos Denis Yarats Phu Mon Htut Artem Molchanov Franziska Meier Douwe Kiela Kyunghyun Cho and Soumith Chintala. 2019. Generalized inner loop meta-learning. arXiv:1910.01727. Retrieved from https:\/\/arxiv.org\/abs\/1910.01727"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3627673.3679637"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401063"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2008.22"},{"key":"e_1_3_2_20_2","unstructured":"Zhiyu Hu Yang Zhang Minghao Xiao Wenjie Wang Fuli Feng and Xiangnan He. 2024. Exact and efficient unlearning for large language model-based recommendation. arXiv:2404.10327. Retrieved from https:\/\/arxiv.org\/abs\/2404.10327"},{"key":"e_1_3_2_21_2","unstructured":"Hanxun Huang Xingjun Ma Sarah Monazam Erfani James Bailey and Yisen Wang. 2021. Unlearnable examples: Making personal data unexploitable. arXiv:2101.04898. Retrieved from https:\/\/arxiv.org\/abs\/2101.04898"},{"key":"e_1_3_2_22_2","doi-asserted-by":"crossref","unstructured":"Hai Huang Jiaming Mu Neil Zhenqiang Gong Qi Li Bin Liu and Mingwei Xu. 2021. Data poisoning attacks to deep learning based recommender systems. arXiv:2101.02644. Retrieved from https:\/\/arxiv.org\/abs\/2101.02644","DOI":"10.14722\/ndss.2021.24525"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3706419"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3569930"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/1008992.1009051"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-0716-2197-4_3"},{"key":"e_1_3_2_27_2","article-title":"Data poisoning attacks on factorization-based collaborative filtering","volume":"29","author":"Li Bo","year":"2016","unstructured":"Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. In Advances in Neural Information Processing Systems, Vol. 29.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_28_2","volume-title":"Proceedings of 11th International Conference on Learning Representations","author":"Li Haoxuan","unstructured":"Haoxuan Li, Chunyuan Zheng, and Peng Wu. [n. d.]. StableDR: Stabilized doubly robust learning for recommendation on data missing not at random. In Proceedings of 11th International Conference on Learning Representations."},{"key":"e_1_3_2_29_2","article-title":"Ultrare: Enhancing receraser for recommendation unlearning via error decomposition","volume":"36","author":"Li Yuyuan","year":"2024","unstructured":"Yuyuan Li, Chaochao Chen, Yizhao Zhang, Weiming Liu, Lingjuan Lyu, Xiaolin Zheng, Dan Meng, and Jun Wang. 2024. Ultrare: Enhancing receraser for recommendation unlearning via error decomposition. In Advances in Neural Information Processing Systems, Vol. 36.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_30_2","unstructured":"Yuyuan Li Xiaolin Zheng Chaochao Chen and Junlin Liu. 2022. Making recommender systems forget: Learning and unlearning for erasable recommendation. arXiv:2203.11491. Retrieved from https:\/\/arxiv.org\/abs\/2203.11491"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3672275"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3680708"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3638351"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3677328"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3567420"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3511708"},{"key":"e_1_3_2_37_2","unstructured":"Hamed Rahimian and Sanjay Mehrotra. 2019. Distributionally robust optimization: A review. arXiv:1908.05659. Retrieved from https:\/\/arxiv.org\/abs\/1908.05659"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3289600.3291002"},{"key":"e_1_3_2_39_2","first-page":"452","volume-title":"Proceedings of the 25th Conference on Uncertainty in Artificial Intelligence","author":"Rendle Steffen","year":"2009","unstructured":"Steffen Rendle, Christoph Freudenthaler, Zeno Gantner, and Lars Schmidt-Thieme. 2009. BPR: Bayesian personalized ranking from implicit feedback. In Proceedings of the 25th Conference on Uncertainty in Artificial Intelligence, 452\u2013461."},{"key":"e_1_3_2_40_2","doi-asserted-by":"crossref","unstructured":"Vinu Sankar Sadasivan Mahdi Soltanolkotabi and Soheil Feizi. 2023. Cuda: Convolution-based unlearnable datasets. arXiv:2303.04278. Retrieved from https:\/\/arxiv.org\/abs\/2303.04278","DOI":"10.1109\/CVPR52729.2023.00376"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/371920.372071"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3656639"},{"key":"e_1_3_2_43_2","doi-asserted-by":"crossref","unstructured":"Pengyang Shao Naixin Zhai Lei Chen Yonghui Yang Fengbin Zhu Xun Yang and Meng Wang. 2026. BalDRO: A distributionally robust optimization based framework for large language model unlearning. arXiv:2601.09172. Retrieved from https:\/\/arxiv.org\/abs\/2601.09172","DOI":"10.1145\/3774904.3792975"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657764"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3159652.3159656"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3412243"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3653448"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1111\/jcc4.12127"},{"issue":"2","key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3432244","article-title":"Toward dynamic user intention: Temporal evolutionary effects of item relations in sequential recommendation","volume":"39","author":"Wang Chenyang","year":"2020","unstructured":"Chenyang Wang, Weizhi Ma, Min Zhang, Chong Chen, Yiqun Liu, and Shaoping Ma. 2020. Toward dynamic user intention: Temporal evolutionary effects of item relations in sequential recommendation. ACM Transactions on Information Systems 39, 2 (2020), 1\u201333.","journal-title":"ACM Transactions on Information Systems"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3604915.3609490"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539253"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6077"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3711896.3736968"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM58522.2023.00175"},{"key":"e_1_3_2_55_2","article-title":"Temporal robustness against data poisoning","volume":"36","author":"Wang Wenxiao","year":"2024","unstructured":"Wenxiao Wang and Soheil Feizi. 2024. Temporal robustness against data poisoning. In Advances in Neural Information Processing Systems, Vol. 36.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645403"},{"key":"e_1_3_2_57_2","first-page":"6638","volume-title":"Proceedings of International Conference on Machine Learning","author":"Wang Xiaojie","year":"2019","unstructured":"Xiaojie Wang, Rui Zhang, Yu Sun, and Jianzhong Qi. 2019. Doubly robust joint learning for recommendation on data missing not at random. In Proceedings of International Conference on Machine Learning. PMLR, 6638\u20136647."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i12.33392"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645518"},{"key":"e_1_3_2_60_2","unstructured":"Zongwei Wang Min Gao Junliang Yu Hao Ma Hongzhi Yin and Shazia Sadiq. 2024. Poisoning attacks against recommender systems: A survey. arXiv:2401.01527. Retrieved from https:\/\/arxiv.org\/abs\/2401.01527"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512255"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3274759"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599240"},{"key":"e_1_3_2_64_2","first-page":"23297","article-title":"Understanding contrastive learning via distributionally robust optimization","volume":"36","author":"Wu Junkang","year":"2023","unstructured":"Junkang Wu, Jiawei Chen, Jiancan Wu, Wentao Shi, Xiang Wang, and Xiangnan He. 2023. Understanding contrastive learning via distributionally robust optimization. Advances in Neural Information Processing Systems, Vol. 36, 23297\u201323320.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462862"},{"key":"e_1_3_2_66_2","volume-title":"Proceedings of 13th International Conference on Learning Representations","author":"Wu Junkang","year":"2025","unstructured":"Junkang Wu, Yuexiang Xie, Zhengyi Yang, Jiancan Wu, Jiawei Chen, Jinyang Gao, Bolin Ding, Xiang Wang, and Xiangnan He. 2025. Towards robust alignment of language models: Distributionally robustifying direct preference optimization. In Proceedings of 13th International Conference on Learning Representations."},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450015"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401144"},{"key":"e_1_3_2_69_2","unstructured":"Yihong Wu Le Zhang Fengran Mo Tianyu Zhu Weizhi Ma and Jian-Yun Nie. 2024. Unifying graph convolution and contrastive learning in collaborative filtering. arXiv:2406.13996. Retrieved from https:\/\/arxiv.org\/abs\/2406.13996"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/3568954"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/1390334.1390437"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219890"},{"issue":"2","key":"e_1_3_2_73_2","first-page":"913","article-title":"XSimGCL: Towards extremely simple graph contrastive learning for recommendation","volume":"36","author":"Yu Junliang","year":"2023","unstructured":"Junliang Yu, Xin Xia, Tong Chen, Lizhen Cui, Nguyen Quoc Viet Hung, and Hongzhi Yin. 2023. XSimGCL: Towards extremely simple graph contrastive learning for recommendation. IEEE Transactions on Knowledge and Data Engineering 36, 2 (2023), 913\u2013926.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531937"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657868"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25611"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591722"},{"key":"e_1_3_2_78_2","unstructured":"Naixin Zhai Pengyang Shao Binbin Zheng Yonghui Yang Fei Shen Long Bai and Xun Yang. 2026. Maximizing local entropy where it matters: Prefix-aware localized LLM unlearning. arXiv:2601.03190. Retrieved from https:\/\/arxiv.org\/abs\/2601.03190"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467233"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635751"},{"key":"e_1_3_2_81_2","unstructured":"Kuan Zou and Aixin Sun. 2025. A survey of real-world recommender systems: Challenges constraints and industrial perspectives. arXiv:2509.06002. Retrieved from https:\/\/arxiv.org\/abs\/2509.06002"}],"container-title":["ACM Transactions on Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3803545","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T15:44:56Z","timestamp":1778946296000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3803545"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,11]]},"references-count":80,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,5,31]]}},"alternative-id":["10.1145\/3803545"],"URL":"https:\/\/doi.org\/10.1145\/3803545","relation":{},"ISSN":["1046-8188","1558-2868"],"issn-type":[{"value":"1046-8188","type":"print"},{"value":"1558-2868","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,11]]},"assertion":[{"value":"2024-12-05","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-08","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}