
The possibility of designing user rating profiles to deliberately and maliciously manipulate the recommendation output of a collaborative filtering system was first raised in 2002. One scenario proposed was that an author, motivated to increase recommendations of his book, might create a set of false profiles that rate the book highly, in an effort to artificially promote the ratings given by the system to genuine users. Several attack models have been proposed and the performance of these attacks in terms of influencing the system predictions has been evaluated for a number of memory-based and model-based collaborative filtering algorithms. Moreover, strategies have been proposed to enhance the robustness of existing algorithms and new algorithms have been proposed with built-in attack resistance. This tutorial will review the work that has taken place in the last decade on robustness of recommendation algorithms and seek to examine the question of the importance of robustness in future research.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 19 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Top 10% | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Top 10% | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Top 10% |
