← Latest papers
🤖 machine learning

Sharpness-Aware Poisoning: Enhancing Transferability of Injective Attacks on Recommender Systems

To enhance the transferability of injective attacks on recommender systems, this paper proposes **Sharpness-Aware Poisoning (SharpAP)**, a method that utilizes sharpness-aware minimization to optimize poisoned data against an approximately worst-case victim model, thereby mitigating overfitting to surrogate models and improving attack success across diverse model architectures.

Original authors: Junsong Xie, Yonghui Yang, Pengyang Shao, Le Wu

Published 2026-04-27
📖 4 min read☕ Coffee break read

Original authors: Junsong Xie, Yonghui Yang, Pengyang Shao, Le Wu

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The "Master Mimic" Problem: How to Trick a System You’ve Never Seen

Imagine you are a professional prankster trying to trick a high-tech security system into letting you into a VIP club. The problem? You don’t know exactly which security system the club uses. One club might use a fingerprint scanner, another uses facial recognition, and a third uses a voice sensor.

Most pranksters (the "attackers" in this paper) pick one system they know well—let's say a fingerprint scanner—and spend all their time practicing how to trick that specific one. They become masters at faking a fingerprint. But the moment they walk into a club that uses facial recognition, their "fake fingerprint" is useless. They failed because they practiced too hard for one specific lock and didn't prepare for the idea of a lock.

In the world of Recommender Systems (like the algorithms that suggest movies on Netflix or products on Amazon), this is called a Transferability Problem.


The Paper’s Discovery: The "Overfitting" Trap

The researchers found that current "poisoning attacks" (where bad actors create fake user profiles to make certain items look popular) are too "narrow-minded."

If an attacker uses a "Surrogate Model" (a practice dummy) to design their fake profiles, they end up creating profiles that are perfect for that dummy but terrible for the real system. They have "overfitted" to the practice dummy. It’s like studying only one specific math textbook for a final exam; if the teacher changes the wording of the questions, you're stuck.

The Solution: SharpAP (The "Worst-Case Scenario" Trainer)

The authors proposed a new method called SharpAP (Sharpness-Aware Poisoning). Instead of practicing against a single, easy-to-please dummy, SharpAP uses a much smarter training method.

The Analogy: The "Grumpy Judge" Method
Imagine you are practicing a speech.

  • The Old Way: You practice in front of a friend who smiles and nods at everything you say. You become very good at making that friend happy, but you haven't actually improved your speech.
  • The SharpAP Way: You practice in front of a "Grumpy Judge." This judge is designed to find every tiny flaw in your speech. Every time you think you’ve done well, the judge says, "What if I were even harder to please? What if I hated your tone even more?"

By constantly trying to satisfy the "worst-case version" of the judge, you are forced to make your speech incredibly robust, clear, and powerful. If you can satisfy the grumpiest, most difficult version of the judge, you will easily impress any regular person who walks into the room later.

How it Works (The "Tri-Level" Trick)

In technical terms, they turned a two-step process into a three-step "tri-level" optimization:

  1. The Mimic: First, they train a model to act like a normal user.
  2. The Grump (The New Part): They intentionally "shake" or "perturb" that model to find its weakest, most difficult point (the "sharpness"). They look for the version of the model that is hardest to trick.
  3. The Masterpiece: They design the fake user profiles specifically to work against that "Grumpy" version.

Why Does This Matter?

The researchers tested this on real-world data (like movie and book datasets) and found that SharpAP is a much better "universal key."

Because the fake profiles were designed to work against a "worst-case" scenario, they "transferred" much better to different types of recommendation systems. Whether the system was a simple math-based model or a complex AI-driven graph model, the SharpAP profiles still managed to trick them.

In short: Instead of practicing to beat one specific lock, SharpAP teaches the attacker how to beat the very concept of a lock.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →