Balancing Imperceptible and Aggressive Poisoning Attack for Recommender Systems: A Simple Multinomial Diffusion Model

Jun Zhu et al.

ACM Transactions on Information Systems2026https://doi.org/10.1145/3797026article
ABDC C
Weight
0.50

What the paper says

Online platforms’ openness makes recommender systems (RSs) susceptible to data poisoning attacks, where malicious user profiles are injected into the training dataset to distort recommendation outcomes. However, existing poisoning attack methods often struggle to achieve an optimal effectiveness on both imperceptibility and aggressiveness. To address this issue, we propose a novel poisoning attack method for RSs, named MDPAttack, which consists of three key modules, each focusing on imperceptibility and aggressiveness. Specifically, we first train a Multinomial Diffusion Model (MDM) to model discrete rating data, effectively minimizing information loss during data processing and thereby enhancing the imperceptibility of the generated profiles. Then, we combine the influence function with the Fast Gradient Sign Method (FGSM) to iteratively improve the aggressiveness of poisoning profiles by leveraging template profiles. Finally, these two properties are seamlessly integrated within the MDPAttack framework. Extensive experiments on both classic and modern deep learning-based RSs demonstrate that MDPAttack generates highly imperceptible profiles while maintaining attack performance comparable to state-of-the-art methods.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1145/3797026

Or copy a formatted citation

@article{jun2026,
  title        = {{Balancing Imperceptible and Aggressive Poisoning Attack for Recommender Systems: A Simple Multinomial Diffusion Model}},
  author       = {Jun Zhu et al.},
  journal      = {ACM Transactions on Information Systems},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1145/3797026},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Balancing Imperceptible and Aggressive Poisoning Attack for Recommender Systems: A Simple Multinomial Diffusion Model

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.