NORMA eResearch @NCI Library

Hybrid Recommender Systems in the Age of Adversarial Attacks: Assessing Vulnerabilities and Defenses

Rane, Nikhil Bhaskar (2025) Hybrid Recommender Systems in the Age of Adversarial Attacks: Assessing Vulnerabilities and Defenses. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (567kB) | Preview

Abstract

Recommender systems are essential in today’s digital platforms, which serve personalized content recommendations for better user experience in a variety of industry sectors (e.g. e-commerce, entertainment, social media etc.). These systems are based mainly on two filters: Collaborative Filtering (CF) and Content-Based Filtering (CBF). CF is based on history to predict user preferences, while CBF is based on properties of items to make recommendations. However, none of these techniques is free of limitations. In particular, collaborative filtering faces the cold-start problem when there is insufficient data for new users or items. On the other hand, content-based filtering may be too specific and recommendations become too uniform. Hybrid recommender systems such as combining CF and CBF have been proposed in recent years to address the challenges while considering both CF and CBF to achieve the strengths of both on more accurate and diverse recommendations.

However, hybrids are also susceptible. With the deepening of their integration into decision making, they are vulnerable to adversarial attacks. These attacks corrupt the input data to deliberately affect the performance of the system. In particular, white-box attacks, such as Fast Gradient Sign Method (FGSM), and projected gradient descent (PGD) can change input to create biased or wrong recommendations. An increasing number of such attacks require an understanding the behavior of hybrid systems under adversarial setting.

In this work, we study the robustness of hybrid recommender systems through the FGSM and PGD adversarial attacks and analyse the performance drop in real-world settings. In the light of adversarial testing, it is anticipated that hybrid systems can be studied more in detail to be made robust, so that their efficiency and effectiveness will not be affected by any possible attacks. The results will have an impact on the improvement of security countermeasures, leading to improved trust in recommendations and for users to trust recommender systems in different domains.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Basilio, Jorge
UNSPECIFIED
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning
Divisions: School of Computing > Master of Science in Data Analytics
Depositing User: Ciara O'Brien
Date Deposited: 24 Aug 2026 12:25
Last Modified: 24 Aug 2026 12:25
URI: https://norma.ncirl.ie/id/eprint/9606

Actions (login required)

View Item View Item