Agentic group attack improves fake profile shilling on recommender systems
An Efficient and Effective Agentic Group Shilling Attack on Recommender Systems
Cryptography and SecurityComputation and Language
Summary
Online platforms use recommender systems to suggest things you might like, but these systems can be tricked by fake accounts that promote certain items unfairly. The paper presents a new method called AGAS, where a coordinator manages a team of fake profiles that change roles to better promote a target item without being easily detected. This approach is more effective and efficient than previous attacks and also causes less disruption to normal recommendations. The authors suggest that defending against such attacks will require systems that can handle adaptive, coordinated fake profile campaigns.
What this means in practice
- •For online platform security teams: Improve detection and defense strategies against adaptive, coordinated shilling attacks targeting recommendation algorithms.
- •For e-commerce service operators: Understand the vulnerabilities in their recommendation systems to better safeguard product rankings from manipulative fake profiles.
Authors
Quoc Viet Nguyen, Trinh Pham, Viet Huynh, Hongzhi Yin, Quoc Viet Hung Nguyen, Bay Vo, Thanh Tam Nguyen
Abstract
Recommender systems have become core infrastructure for modern online platforms, personalizing content at scale and strongly influencing what users see, click on, and purchase. However, this dependence on user interaction also exposes them to shilling attacks, where malicious actors can inject fake profiles to distort item rankings and control visibility. Existing attacks often rely on target-specific fine-tuning or fixed profile templates, making them either difficult to adapt to different victims or easier to detect. To overcome these limitations, we propose the Agentic Group Attack System (AGAS), a coordinated shilling framework where a central Coordinator directs a group of role-switching worker agents to adaptively promote a target item across different victim families. The Coordinator dynamically adjusts the strategy when progress stalls or suppression signals increase, while workers pursue a shared objective and switch between active and inactive roles to avoid repetitive patterns. Under the same attack budgets and evaluation protocols, AGAS consistently surpasses strong baselines in target promotion while better preserving benign recommendation quality, weakening representative detectors, and achieving higher efficiency than prior attacks. These findings also emphasize that defending recommender systems may require mechanisms that can handle adaptive shilling campaigns, not just isolated fake-profile injections. Our code is available at https://github.com/phkhanhtrinh23/AGAS.