Agentic group attack improves fake profile shilling on recommender systems

An Efficient and Effective Agentic Group Shilling Attack on Recommender Systems

Cryptography and SecurityComputation and Language

Summary

Online platforms use recommender systems to suggest things you might like, but these systems can be tricked by fake accounts that promote certain items unfairly. The paper presents a new method called AGAS, where a coordinator manages a team of fake profiles that change roles to better promote a target item without being easily detected. This approach is more effective and efficient than previous attacks and also causes less disruption to normal recommendations. The authors suggest that defending against such attacks will require systems that can handle adaptive, coordinated fake profile campaigns.

What this means in practice

Authors

Quoc Viet Nguyen, Trinh Pham, Viet Huynh, Hongzhi Yin, Quoc Viet Hung Nguyen, Bay Vo, Thanh Tam Nguyen

Abstract

Recommender systems have become core infrastructure for modern online platforms, personalizing content at scale and strongly influencing what users see, click on, and purchase. However, this dependence on user interaction also exposes them to shilling attacks, where malicious actors can inject fake profiles to distort item rankings and control visibility. Existing attacks often rely on target-specific fine-tuning or fixed profile templates, making them either difficult to adapt to different victims or easier to detect. To overcome these limitations, we propose the Agentic Group Attack System (AGAS), a coordinated shilling framework where a central Coordinator directs a group of role-switching worker agents to adaptively promote a target item across different victim families. The Coordinator dynamically adjusts the strategy when progress stalls or suppression signals increase, while workers pursue a shared objective and switch between active and inactive roles to avoid repetitive patterns. Under the same attack budgets and evaluation protocols, AGAS consistently surpasses strong baselines in target promotion while better preserving benign recommendation quality, weakening representative detectors, and achieving higher efficiency than prior attacks. These findings also emphasize that defending recommender systems may require mechanisms that can handle adaptive shilling campaigns, not just isolated fake-profile injections. Our code is available at https://github.com/phkhanhtrinh23/AGAS.