{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:03:15Z","timestamp":1777806195267,"version":"3.51.4"},"reference-count":49,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2022,8,17]],"date-time":"2022-08-17T00:00:00Z","timestamp":1660694400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2022,8,25]]},"abstract":"<jats:p>Nowadays, online services, like e-commerce or streaming services, provide a personalized user experience through recommender systems. Recommender systems are built upon a vast amount of data about users\/items acquired by the services. Such knowledge represents an invaluable resource. However, commonly, part of this knowledge is public and can be easily accessed via the Internet. Unfortunately, that same knowledge can be leveraged by competitors or malicious users. The literature offers a large number of works concerning attacks on recommender systems, but most of them assume that the attacker can easily access the full rating matrix. In practice, this is never the case. The only way to access the rating matrix is by gathering the ratings (e.g., reviews) by crawling the service\u2019s website. Crawling a website has a cost in terms of time and resources. What is more, the targeted website can employ defensive measures to detect automatic scraping.<\/jats:p>\n                  <jats:p>In this paper, we assess the impact of a series of attacks on recommender systems. Our analysis aims to set up the most realistic scenarios considering both the possibilities and the potential attacker\u2019s limitations. In particular, we assess the impact of different crawling approaches when attacking a recommendation service. From the collected information, we mount various profile injection attacks. We measure the value of the collected knowledge through the identification of the most similar user\/item. Our empirical results show that while crawling can indeed bring knowledge to the attacker (up to 65% of neighborhood reconstruction on a mid-size dataset and up to 90% on a small-size dataset), this will not be enough to mount a successful shilling attack in practice.<\/jats:p>","DOI":"10.3233\/jcs-210041","type":"journal-article","created":{"date-parts":[[2021,11,5]],"date-time":"2021-11-05T14:56:34Z","timestamp":1636124194000},"page":"599-621","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":0,"title":["On the feasibility of crawling-based attacks against recommender systems"],"prefix":"10.1177","volume":"30","author":[{"given":"Fabio","family":"Aiolli","sequence":"first","affiliation":[{"name":"Department of Mathematics, University of Padova, Padova, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Padova, Padova, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stjepan","family":"Picek","sequence":"additional","affiliation":[{"name":"Department of Intelligent Systems, Delft University of Technology, Delft, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mirko","family":"Polato","sequence":"additional","affiliation":[{"name":"Department of Mathematics, University of Padova, Padova, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2022,8,17]]},"reference":[{"key":"ref001","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59013-0_9"},{"key":"ref002","doi-asserted-by":"publisher","DOI":"10.1145\/1062745.1062768"},{"key":"ref003","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242632"},{"key":"ref004","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242631"},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"W.\u00a0Bhebe and O.P.\u00a0Kogeda, Shilling attack detection in collaborative recommender systems using a meta learning strategy, in: 2015 International Conference on Emerging Trends in Networks and Computer Communications, 2015, pp.\u00a056\u201361.","DOI":"10.1109\/ETNCC.2015.7184808"},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"S.\u00a0Brin and L.\u00a0Page, The anatomy of a large-scale hypertextual web search engine, in: Proceedings of the Seventh International Conference on World Wide Web 7, WWW7, Elsevier, NLD, 1998, pp.\u00a0107\u2013117.","DOI":"10.1016\/S0169-7552(98)00110-X"},{"key":"ref007","unstructured":"R.\u00a0Burke, B.\u00a0Mobasher and R.\u00a0Bhaumik, Limited knowledge shilling attacks in collaborative filtering systems, in: Proceedings of the 3rd IJCAI Workshop in Intelligent Techniques for Personalization, 2005."},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150465"},{"key":"ref009","doi-asserted-by":"publisher","DOI":"10.1145\/1367497.1367558"},{"key":"ref010","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-39940-9_165"},{"key":"ref011","doi-asserted-by":"crossref","unstructured":"S.\u00a0Chakrabarti, B.\u00a0Dom, P.\u00a0Raghavan, S.\u00a0Rajagopalan, D.\u00a0Gibson and J.\u00a0Kleinberg, Automatic resource compilation by analyzing hyperlink structure and associated text, in: Proceedings of the Seventh International Conference on World Wide Web 7, WWW7, Elsevier, NLD, 1998, pp.\u00a065\u201374.","DOI":"10.1016\/S0169-7552(98)00087-7"},{"key":"ref012","doi-asserted-by":"publisher","DOI":"10.1145\/1097047.1097061"},{"key":"ref013","doi-asserted-by":"publisher","DOI":"10.1016\/S0169-7552(98)00108-1"},{"key":"ref014","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347031"},{"key":"ref015","unstructured":"Y.\u00a0Deldjoo, T.\u00a0Di Noia and F.A.\u00a0Merra, Assessing the impact of a user-item collaborative attack on class of users, in: Proceedings of the 13th ACM RecSys Workshop on Impact of Recommender Systems, (ImpactRS@RecSys\u201919), 2019, http:\/\/sisinflab.poliba.it\/publications\/2019\/DDM19."},{"key":"ref016","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-019-00738-1"},{"key":"ref017","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186183"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"M.\u00a0Ester, H.P.\u00a0Kriegel and M.\u00a0Schubert, Accurate and efficient crawling for relevant websites, in: Proceedings of the Thirtieth International Conference on Very Large Data Bases\u00a0\u2013 Volume 30, VLDB\u201904, VLDB Endowment, 2004, pp.\u00a0396\u2013407. ISBN 0120884690.","DOI":"10.1016\/B978-012088469-8\/50037-1"},{"key":"ref019","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"ref020","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-1153-7"},{"key":"ref021","doi-asserted-by":"publisher","DOI":"10.1145\/2843948"},{"key":"ref022","doi-asserted-by":"publisher","DOI":"10.3837\/tiis.2013.05.019"},{"key":"ref023","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-012-9364-9"},{"key":"ref024","unstructured":"G.\u00a0Guo, J.\u00a0Zhang and N.\u00a0Yorke-Smith, A\u00a0novel Bayesian similarity measure for recommender systems, in: Proceedings of the 23rd International Joint Conference on Artificial Intelligence (IJCAI), 2013, pp.\u00a02619\u20132625."},{"key":"ref025","doi-asserted-by":"publisher","DOI":"10.1145\/2766462.2767823"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05411-3_9"},{"key":"ref027","doi-asserted-by":"publisher","DOI":"10.1007\/s41109-019-0201-9"},{"key":"ref028","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2007.44"},{"key":"ref029","doi-asserted-by":"publisher","DOI":"10.1109\/INVENTIVE.2016.7824865"},{"key":"ref030","doi-asserted-by":"publisher","DOI":"10.1145\/2578726.2578747"},{"key":"ref031","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-85820-3_5"},{"key":"ref032","unstructured":"M.\u00a0Koster, Robots in the web: Threat or treat? ConneXions9(4) (1995)."},{"key":"ref033","doi-asserted-by":"crossref","unstructured":"A.\u00a0Lawankar and N.\u00a0Mangrulkar, A\u00a0review on techniques for optimizing web crawler results, in: 2016 World Conference on Futuristic Trends in Research and Innovation for Social Welfare (Startup Conclave), 2016, pp.\u00a01\u20134.","DOI":"10.1109\/STARTUP.2016.7583952"},{"key":"ref034","unstructured":"B.\u00a0Li, Y.\u00a0Wang, A.\u00a0Singh and Y.\u00a0Vorobeychik, Data poisoning attacks on factorization-based collaborative filtering, in: Proceedings of the 30th International Conference on Neural Information Processing Systems, NIPS\u201916, 2016, pp.\u00a01893\u20131901, http:\/\/dl.acm.org\/citation.cfm?id=3157096.3157308. ISBN 978-1-5108-3881-9."},{"key":"ref035","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2003.1167344"},{"key":"ref036","unstructured":"L.\u00a0Mu\u00f1oz-Gonz\u00e1lez, B.\u00a0Pfitzner, M.\u00a0Russo, J.\u00a0Carnerero-Cano and E.C.\u00a0Lupu, Poisoning attacks with generative adversarial nets, arXiv:1906.07773, 2019."},{"key":"ref037","unstructured":"L.\u00a0Page, S.\u00a0Brin, R.\u00a0Motwani and T.\u00a0Winograd, The PageRank citation ranking: Bringing order to the web, in: WWW 1999, 1999."},{"key":"ref038","doi-asserted-by":"crossref","unstructured":"K.\u00a0Patel, A.\u00a0Thakkar, C.\u00a0Shah and K.\u00a0Makvana, A\u00a0state of art survey on shilling attack in collaborative filtering based recommendation system, in: Proceedings of First International Conference on Information and Communication Technology for Intelligent Systems, Vol.\u00a01, S.C.\u00a0Satapathy and S.\u00a0Das, eds, Springer, Cham, 2016, pp.\u00a0377\u2013385. ISBN 978-3-319-30933-0.","DOI":"10.1007\/978-3-319-30933-0_38"},{"key":"ref039","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.01.057"},{"key":"ref040","unstructured":"S.\u00a0Rendle, C.\u00a0Freudenthaler, Z.\u00a0Gantner and L.\u00a0Schmidt-Thieme, BPR: Bayesian personalized ranking from implicit feedback, in: Proceedings of the Twenty-Fifth Conference on Uncertainty in Artificial Intelligence, UAI\u201909, AUAI Press, Arlington, Virginia, USA, 2009, pp.\u00a0452\u2013461. ISBN 9780974903958."},{"key":"ref041","doi-asserted-by":"crossref","unstructured":"F.\u00a0Ricci, L.\u00a0Rokach and B.\u00a0Shapira, Recommender Systems Handbook, 2nd edn, Springer Publishing Company, Incorporated, 2015. ISBN 1489976361.","DOI":"10.1007\/978-1-4899-7637-6"},{"key":"ref042","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9655-x"},{"key":"ref043","doi-asserted-by":"publisher","DOI":"10.1155\/2009\/421425"},{"key":"ref044","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3022962"},{"key":"ref045","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00064"},{"key":"ref046","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/p19-1248"},{"key":"ref047","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Zhang, H.\u00a0Gao, G.\u00a0Pei, S.\u00a0Luo, G.\u00a0Chang and N.\u00a0Cheng, A\u00a0survey of research on CAPTCHA designing and breaking techniques, in: 2019 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/13th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE), 2019, pp.\u00a075\u201384.","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00020"},{"key":"ref048","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0130968"},{"key":"ref049","doi-asserted-by":"publisher","DOI":"10.1145\/1060745.1060754"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-210041","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-210041","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-210041","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:38Z","timestamp":1777495538000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-210041"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,17]]},"references-count":49,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,8,25]]}},"alternative-id":["10.3233\/JCS-210041"],"URL":"https:\/\/doi.org\/10.3233\/jcs-210041","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,17]]}}}