1 of 54

Trait Study of Semantic Aware Shilling Attacks And Detection

for Recommender System

Presented by:

Farhana Khan (1705100)

Sumaiya Azad (1705048)

1

Supervisor:

Dr. Mahmuda Naznin

Professor

Department of CSE, BUET

2 of 54

Introduction

&

Motivation

2

3 of 54

Recommendation System

  • Assist users' decision-making
  • Used in e-commerce platforms e.g.,
    • Trivago : hotels to stay
    • Netflix : movies to watch

3

Which movie do I watch next?

Types

Content-based

Filtering

Collaborative

Filtering

User’s own information

Other users information

Focus of our work

4 of 54

Recommender System

  • Collaborative Filtering
  • Calculates similarity between users
  • Filters items based on reactions by similar users

4

5 of 54

Shilling Attack

  • Malicious fake user profile injected
  • Rates items
  • Alter the recommendation of a target item

5

Shilling Attack types

Push

Nuke

To Increase Popularity

To Decrease Popularity

6 of 54

Semantic Aware Shilling Attack (SAShA)

  • Uses Knowledge Graph
  • Strengthens existing shilling models

6

6

The Structure of a Shilling Profile (the Fake Users)

- Selected items

- Using the adversary’s knowledge on the system data

- Unrated items

- Items not rated

Target Item

Pushed or Nuked

- Filler items

- Items randomly selected to rate

Knowledge graph addition:

  • Compute similarity/relatedness
  • Find items similar to target item
  • Items features in public Knowledge graphs

Attack strength increases

7 of 54

Knowledge Graph

7

Represents a network of real-world entities (objects, events, situations, or concepts)

Illustrates the relationship between them

Christopher Nolan

Inception

Interstellar

Directed by

Directed by

Similar item

8 of 54

Shilling Attack Traits

8

Attack size

Filler size

Higher attack size

Expensive attack

Harder for the attacker

Attackers target: high impact with small attack size

Higher filler size

Expensive and conspicuous attack

Harder for the attacker, easier to detect

Attackers target: high impact with small filler size

9 of 54

Motivation

9

- Collaboration of knowledge graphs and recommendation systems

- Currently attracting interests of researchers in this field

- Public Knowledge graph is used to launch stronger shilling attacks

- lack of study of defence

- lack of study of attack traits of semantic aware shilling attack

- cost effectivity

10 of 54

Related Work

10

11 of 54

SAShA: Semantic-Aware Shilling Attacks on Recommender Systems Exploiting Knowledge Graphs [1]

Vito Walter Anelli, Yashar Deldjoo, Tommaso Di Noia, Eugenio Di Sciascio, Felice Antonio Merra ESWC 2020

11

12 of 54

Semantic-Aware Shilling Attacks on Recommender Systems Exploiting Knowledge Graphs

12

Problems Addressed :

  • Can public knowledge make attack better?
  • How different features affect attack performance?

Findings:

  • Novel strategy
  • improve the attacker’s performance
  • Ontological features give the most improvement

Gaps:

  • Tested on only three types of shilling attacks
    • Random attack
    • Average attack
    • Love-hate attack
  • How detection mechanisms perform?

13 of 54

Preventing Shilling Attacks in Online Recommender Systems [2]

Chirita, Paul-Alexandru, Wolfgang Nejdl, and Cristian Zamfir

Proceedings of the 7th annual ACM international workshop on Web information and data management. 2005.

13

14 of 54

Preventing Shilling Attacks in Online Recommender Systems

14

Problems Addressed :

  • Performance of detection metrics on different attacks

Findings:

  • Detection metrics
  • Number of Prediction Differences
  • Standard Deviation in User’s Ratings
  • Degree of Agreement with Other Users
  • Degree of Similarity with Top Neighbors
  • Novel detection algorithm

Gaps:

  • Not tested on Semantic Aware Shilling Attack

15 of 54

Problem Domain

15

16 of 54

Our Challenges

We tried to answer these following research questions:

16

Attack Size

  • Reach of target items in various attack sizes
  • Contrast between semantic aware attacks and base attacks

Filler Size

  • Influence of filler length for a fixed attack size
  • Contrast between semantic aware attacks and base attacks

Detection Algorithms performance

  • Does detection performance vary for algorithms based on different detection assumption?

Dataset density

  • User-item interaction
  • Does effectivity of semantic attacks vary?

17 of 54

Our Challenge 1: Reach of Target Items in Various Attack Sizes

In our experiment we have -

  • Generated attacks with attack sizes 1%, 2%, 3%, 4%, 5%, 6% and 7%.
  • Used constant filler size 1.
  • Evaluated attack impact

17

18 of 54

Our Challenge 2: Influence of Different Filler Length

In our experiment we have -

  • Generated attacks with filler sizes 0.5, 1, 1.5, 2, 2.5, 3, 3.5 and 4
  • Used constant attack size 5%
  • Evaluated attack impact

18

19 of 54

Our Challenge 3: Effectiveness on Different Density Datasets

  • Experimented with two very commonly used datasets
  • One sparse, and one dense

19

Yahoo Movies

Dense

High user-item interaction. (a lot of users have rated a lot of items)

Small Library Things

Sparse

Low user-item interaction

Yahoo Movies

Small Library Things

dataset trait

dense

sparse

Number of users

860

1357

Number of items

629

701

Total ratings

6919

7652

Average number of items rated by each user

8

5

Average number of users rated an item

11

10

20 of 54

Our Challenge 4: Performance of Detection Methods

2 Widely used Detection methods

20

Number of Prediction Difference

(NPD) [2]

Principal Component Analysis

(PCA) [3]

21 of 54

Our Challenge 4: Performance of Detection Methods

  • NPD for user u

= number of recommendation prediction changes, removing u from the system

  • Detection Assumption:
    • Attack profile’s target change prediction for target item
    • Hence have high NPD

21

Small Library Things (sparse)

Yahoo Movies (dense)

22 of 54

Our Challenge 4: Performance of Detection Methods

  • PCA [3]
    • Correlation between user profiles
    • Based on items rated
  • Detection Assumption:
    • Attack profiles high similarity

22

Red marked profiles are shillers

23 of 54

Our Solution Approach: Dataset Preprocessing

23

  • 25% of the dataset
  • Sampled randomly
  • Faster result generation
  • Dropped users with less than 5 ratings
  • To avoid cold start
  • 50 different target items
  • Items with the least mean rating
  • Ontological features of the knowledge graph for semantic attacks
  • Best performance [1]

24 of 54

Our Solution Approach: Attack Models

24

Base Attacks

  • Random attack
  • Average attack

Semantic Aware Attacks

  • SAShA-Random attack
  • SAShA-Average attack
  • SAShA-Segment attack

25 of 54

Our Solution Approach: Recommendation Systems

25

Memory Based

(Classical)

User Based

Model Based

(Popular)

Matrix Factorization

Collaborative Filtering Recommendation System

Item Based

- Decomposes the user-item interaction matrix into latent factors

- Latent factors captures hidden characteristics of users and items

User-user similarity

Item-item similarity

26 of 54

Our Solution Approach: Performance Measuring Parameter

26

Hit Ratio

Accuracy

Reach of Target Item

On the Top k Recommendations

Detected Fake Profiles

Number of Real Users Marked True

27 of 54

Our Solution Approach: Summary View

27

KG Data

(public)

RS Data

(partially public)

Step 1: List

Target items

Step 2: Generate pre-attack recommendations

Step 4: Generate post-attack recommendations

Step 3: Generate

fake profiles

Step 5: HR@k vs attack traits

Challenges 1, 2, 3

Step 6: Detect fake profiles

Step 7: Detection Accuracy Challenge 4

28 of 54

Results:

Attack Traits

28

29 of 54

  • In Yahoo Movies dataset
  • Hit Ratio vs Filler size
  • Of Average attack and Semantic aware average attack
  • For Matrix Factorization RS
  • Higher the number of similar filler items, stronger the semantic attacks

Our Findings: Attack Traits

29

Slower decrease

30 of 54

In Matrix Factorization RS, higher the number of similar filler items, stronger the semantic attacks

Our Findings: Attack Traits

30

31 of 54

Our Findings: Attack Traits

31

Dataset

RecSys

Dense (Yahoo movies)

Sparse (Small library things)

Inference

Base Attacks

Semantic Attacks

Base Attacks

Semantic Attacks

Matrix Factorization

filler size

HR@k

filler size

HR@k slow

filler size

HR@k

filler size

HR@k slow

in both datasets, adding higher number of similar filler items is causing the semantic attack to be stronger

Item Based

attack size

HR@k

attack size

HR@k

attack size

HR@k

attack size

HR@k

in both datasets, adding higher number of similar users is causing the semantic attack to be stronger

User Based

all attack traits are same, infact baseline attacks perform better than semantic attacks

cannot leverage item similarities information from knowledge graph

Table: Summary Table of Our Findings

32 of 54

  • In Yahoo Movies dataset
  • Hit Ratio vs Attack Size
  • Of Average attack and Semantic aware average attack
  • For Item Based RS
  • Higher the number of similar fake users, stronger the semantic attacks

Our Findings: Attack Traits

32

Increased performance

33 of 54

In Item based RS, higher the number of similar fake users, stronger the semantic attacks.

Our Findings: Attack Traits

33

34 of 54

This is reflected in the overall performance of the semantic attacks

Our Findings: Attack Traits

In Item based RS, higher the number of similar fake users, stronger the semantic attacks

34

35 of 54

Our Findings: Attack Traits

35

Dataset

RecSys

Dense (Yahoo movies)

Sparse (Small library things)

Inference

Base Attacks

Semantic Attacks

Base Attacks

Semantic Attacks

Matrix Factorization

filler size

HR@k

filler size

HR@k slow

filler size

HR@k

filler size

HR@k slow

in both datasets, adding higher number of similar filler items is causing the semantic attack to be stronger

Item Based

attack size

HR@k

attack size

HR@k

attack size

HR@k

attack size

HR@k

in both datasets, adding higher number of similar users is causing the semantic attack to be stronger

User Based

all attack traits are same, infact baseline attacks perform better than semantic attacks

cannot leverage item similarities information from knowledge graph

Table: Summary Table of Our Findings

36 of 54

In User based, HR@k vs Attack size

Our Findings: Attack Traits

36

37 of 54

In User based, HR@k vs Filler size

Our Findings: Attack Traits

37

38 of 54

In User based, semantic attacks performs just as good as base attacks, if not worse

Our Findings: Attack Traits

38

39 of 54

Our Findings : Summary

39

Dataset

RecSys

Dense (Yahoo movies)

Sparse (Small library things)

Inference

Base Attacks

Semantic Attacks

Base Attacks

Semantic Attacks

Matrix Factorization

filler size

HR@k

filler size

HR@k slow

filler size

HR@k

filler size

HR@k slow

in both datasets, adding higher number of similar filler items is causing the semantic attack to be stronger

Item Based

attack size

HR@k

attack size

HR@k

attack size

HR@k

attack size

HR@k

in both datasets, adding higher number of similar users is causing the semantic attack to be stronger

User Based

all attack traits are same, infact baseline attacks perform better than semantic attacks

cannot leverage item similarities information from knowledge graph

Table: Summary Table of Our Findings

40 of 54

Results:

Detection Methods

40

41 of 54

Our Hypothesis: Detection Methods

41

Semantic aware shilling profiles are crafted to be more like real users

Should be better at fooling the detection methods

42 of 54

Accuracy of detection methods

Our Findings: Detection Methods

42

PCA performed better on Semantic aware attacks

e.i,

Contradicts hypothesis

43 of 54

Our Findings: Detection Methods

43

Our Hypothesis Based on Results

In sparse dataset semantic aware attacks are easily detected by detection methods based on profile similarity trait.

44 of 54

Our Result Explanation: Detection Methods

44

In sparse dataset

Less user-item interaction

Probability of having rated common items by two real users is small

Similarity between real users is very small

45 of 54

Our Result Explanation: Detection Methods

45

Filler items are randomly chosen

What happens in base attacks?

No similarity between items

46 of 54

Our Result Explanation: Detection Methods

46

What happens in Semantic attacks?

47 of 54

Our Result Explanation: Detection Methods

47

Target item

Filler items are sampled from similar items

Filler items are similar to each other

Generate items similar to target using KG

Increases similarity between fake profiles

Conspicuous profile similarity

48 of 54

Our Result Explanation: Detection Methods

48

Clustered into 2 groups based on profile similarity

Green : detected fake profiles

Red : fake profiles

PCA of datasets

49 of 54

Our Findings: Detection Methods

49

Even though semantic awareness is strengthening the attack,

  • But it also makes it easier to detect
  • In recommendation systems with less user-item interactions
  • By profile similarity based detection methods
  • With the increase in user-item interactions, similarity patterns in the semantic aware fake profiles become similar to real users
  • Harder to detect

50 of 54

Conclusion

50

  • Focused on semantic aware shilling attacks and their detection in recommender systems
  • Trait study was conducted to understand the semantic manipulation techniques employed by attackers
  • The research contributes to the field by addressing the previously overlooked defence of semantic aware shilling attacks
  • This research shows that profile similarity based detection methods are valuable tool for platform administrators to enhance the security and trustworthiness of recommender systems

51 of 54

Future Work

51

52 of 54

Future Work

  • Test performance of more detection methods based on profile similarity on different datasets.
  • Experiment how supervised detection mechanism work on Semantic Aware Shilling Attacks.
  • Explore advanced semantic analysis techniques, considering user context, and evaluating on diverse datasets
  • Explore traits of Generative Adversarial Network based attack models

52

53 of 54

Reference

  1. Anelli, Vito Walter, et al. "Sasha: Semantic-aware shilling attacks on recommender systems exploiting knowledge graphs." The Semantic Web: 17th International Conference, ESWC 2020, Heraklion, Crete, Greece, May 31–June 4, 2020, Proceedings. Cham: Springer International Publishing, 2020.
  2. Chirita, Paul-Alexandru, Wolfgang Nejdl, and Cristian Zamfir. "Preventing shilling attacks in online recommender systems." Proceedings of the 7th annual ACM international workshop on Web information and data management. 2005.
  3. Mehta, Bhaskar, and Wolfgang Nejdl. "Unsupervised strategies for shilling detection and robust collaborative filtering." User Modeling and User-Adapted Interaction 19 (2009): 65-97.

53

54 of 54

Thank You

Q/A

54