Publication Type
Conference Proceeding Article
Version
publishedVersion
Publication Date
1-2026
Abstract
Sequential Recommenders, which exploit dynamic user intents through interaction sequences, are vulnerable to adversarial attacks. While existing attacks primarily rely on data poisoning, they require large-scale user access or fake profiles, thus lacking practicality. In this paper, we focus on the Profile Pollution Attack that subtly contaminates partial user interactions to induce targeted mispredictions. Previous PPA methods suffer from two limitations, i.e., i) overreliance on sequence horizon impact restricts fine-grained perturbations on item transitions, and ii) holistic modifications cause detectable distribution shifts. To address these challenges, we propose a constrained reinforcement driven attack CREAT that synergizes a bi-level optimization framework with multi-reward reinforcement learning to balance adversarial efficacy and stealthiness. We first develop a Pattern Balanced Rewarding Policy, which integrates pattern inversion rewards to invert critical patterns and distribution consistency rewards to minimize detectable shifts via unbalanced co-optimal transport. Then we employ a Constrained Group Relative Reinforcement Learning paradigm, enabling stepwise perturbations through dynamic barrier constraints and group-shared experience replay, achieving targeted pollution with minimal detectability. Extensive experiments demonstrate the effectiveness of CREAT.
Discipline
Artificial Intelligence and Robotics | Information Security
Research Areas
Intelligent Systems and Optimization
Areas of Excellence
Digital transformation
Publication
Proceedings of the 40th Annual AAAI Conference on Artificial Intelligence (AAAI‑26), Singapore, January 20-27
First Page
15752
Last Page
15760
Identifier
10.1609/aaai.v40i18.38606
Publisher
AAAI
City or Country
Singapore
Citation
SU, Jiajie; NAN, Zihan; MA, Yunshan; XIA, Xiaobo; FENG, Xiaohua; LIU, Weiming; CHEN, Xiang; ZHENG, Xiaolin; and CHEN, Chaochao.
Potent but stealthy: Rethink profile pollution against sequential recommendation via bi-level constrained reinforcement paradigm. (2026). Proceedings of the 40th Annual AAAI Conference on Artificial Intelligence (AAAI‑26), Singapore, January 20-27. 15752-15760.
Available at: https://ink.library.smu.edu.sg/sis_research/11276
Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.
Additional URL
https://doi.org/10.1609/aaai.v40i18.38606