PGAN: Penalized GANs with Latent Perturbation for Robust Shilling Attack Generation in Recommender Systems

preprint OA: closed
Full text JSON View at publisher
AI-generated deep summary by claude@2026-07, 2026-07-06 · read from full text

This paper studies how to generate robust shilling attack profiles against recommender systems using a Penalized GAN with latent space perturbations (PGAN). Using real-world recommender datasets, the authors stabilize discriminator training with a gradient penalty and improve robustness and diversity by applying controlled noise perturbations in the generator’s latent space, then evaluate performance with metrics including Hit Ratio@K, Prediction Shift, and attack success rate. PGAN is reported to outperform traditional statistical and baseline GAN-based attack methods and to produce profiles with realism assessed via similarity analysis with genuine users; it reports HR@10 values of 0.2051 on MovieLens and 0.2076 on Amazon. The paper does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Abstract Shilling attacks pose a significant threat to the integrity and reliability of recommender systems by injecting fake user profiles to promote or demote targeted items. Existing generative approaches often suffer from unstable training dynamics and limited realism in the synthesized profiles. In this paper, we propose PGAN, a novel Penalized Generative Adversarial Network enhanced with latent space perturbations to generate high-quality, diverse, and undetectable shilling attack profiles. PGAN incorporates a gradient penalty to stabilize discriminator training and applies controlled noise perturbations in the generator’s latent space to improve robustness and attack diversity. We evaluate PGAN on real-world datasets and show that it consistently outperforms traditional statistical attacks and baseline GAN-based models across multiple evaluation metrics, such as Hit Ratio@K, Prediction Shift, and attack success rate. Experimental results also confirm the realism of the generated profiles through similarity analysis with genuine users. Our proposed model could surpass traditional and state-of-the-art methods, with HR@10 of 0.2051 and 0.2076 on MovieLens and Amazon datasets, respectively.
Full text 11,415 characters · extracted from preprint-html · click to expand
PGAN: Penalized GANs with Latent Perturbation for Robust Shilling Attack Generation in Recommender Systems | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article PGAN: Penalized GANs with Latent Perturbation for Robust Shilling Attack Generation in Recommender Systems Dina Nawara, Rasha Kashef This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-6395334/v1 This work is licensed under a CC BY 4.0 License Status: Published Journal Publication published 22 Aug, 2025 Read the published version in Discover Computing → Version 1 posted 4 You are reading this latest preprint version Abstract Shilling attacks pose a significant threat to the integrity and reliability of recommender systems by injecting fake user profiles to promote or demote targeted items. Existing generative approaches often suffer from unstable training dynamics and limited realism in the synthesized profiles. In this paper, we propose PGAN, a novel Penalized Generative Adversarial Network enhanced with latent space perturbations to generate high-quality, diverse, and undetectable shilling attack profiles. PGAN incorporates a gradient penalty to stabilize discriminator training and applies controlled noise perturbations in the generator’s latent space to improve robustness and attack diversity. We evaluate PGAN on real-world datasets and show that it consistently outperforms traditional statistical attacks and baseline GAN-based models across multiple evaluation metrics, such as Hit Ratio@K, Prediction Shift, and attack success rate. Experimental results also confirm the realism of the generated profiles through similarity analysis with genuine users. Our proposed model could surpass traditional and state-of-the-art methods, with HR@10 of 0.2051 and 0.2076 on MovieLens and Amazon datasets, respectively. Shilling Attacks Recommender Systems GCN GAN Perturbations Gradient Penalty Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Published Journal Publication published 22 Aug, 2025 Read the published version in Discover Computing → Version 1 posted Editorial decision: Revision requested 24 Apr, 2025 Editor assigned by journal 23 Apr, 2025 Submission checks completed at journal 23 Apr, 2025 First submitted to journal 07 Apr, 2025 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-6395334","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":440178828,"identity":"56eca956-f58b-4147-aaf3-6fba4e410e0b","order_by":0,"name":"Dina Nawara","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA70lEQVRIiWNgGAWjYDCCwwgm4wOStTAbHABRbIS0HEAw2SSI0sJ3nPfgB8Yddon9sw8/q/5QcU/OXL756GYeBjt5XFokD/MlSzCeSU6ccS7N7MaBM8XGlm1sabd5GJING3BoMTjMYyDB2Mac23CGwezGwbaExA3HeMyAWg4w4tFi/IOxrT53/hn2bwXIWuzxaDED2nI4d8MZHjMGZC2JuLRIArVYJLYdr994hqdY4syZBGODY2lpN+cYJCfj0sJ3/ozxjY9t1cZyZ9g3fqioSJAzOHz42I03FXa2uLSAQQIWB+NTPwpGwSgYBaOAEAAAfGlaNGpISqAAAAAASUVORK5CYII=","orcid":"","institution":"Toronto Metropolitan University","correspondingAuthor":true,"prefix":"","firstName":"Dina","middleName":"","lastName":"Nawara","suffix":""},{"id":440178829,"identity":"46f9703d-7935-4b99-af71-e18d34fca8a1","order_by":1,"name":"Rasha Kashef","email":"","orcid":"","institution":"Toronto Metropolitan University","correspondingAuthor":false,"prefix":"","firstName":"Rasha","middleName":"","lastName":"Kashef","suffix":""}],"badges":[],"createdAt":"2025-04-07 14:38:19","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-6395334/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-6395334/v1","draftVersion":[],"editorialEvents":[{"content":"https://doi.org/10.1007/s10791-025-09702-2","type":"published","date":"2025-08-22T16:29:18+00:00"}],"editorialNote":"","failedWorkflow":false,"files":[{"id":89847609,"identity":"a19a182c-64eb-4a23-8ba1-cdad2fcaa276","added_by":"auto","created_at":"2025-08-25 16:43:48","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1180845,"visible":true,"origin":"","legend":"","description":"","filename":"PGANPenalizedGANswithLatentPerturbationforRobustShillingAttackGenerationinRecommenderSystems.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6395334/v1_covered_7897993d-b22a-4f04-afad-32d1f14ccfcd.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"PGAN: Penalized GANs with Latent Perturbation for Robust Shilling Attack Generation in Recommender Systems","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":true,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"discover-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"","sideBox":"Learn more about [Discover Computing](https://link.springer.com/journal/10791)","snPcode":"10791","submissionUrl":"https://submission.springernature.com/new-submission/10791/3","title":"Discover Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Discover Series","inReviewEnabled":true,"inReviewRevisionsEnabled":true},"keywords":"Shilling Attacks, Recommender Systems, GCN, GAN, Perturbations, Gradient Penalty","lastPublishedDoi":"10.21203/rs.3.rs-6395334/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-6395334/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eShilling attacks pose a significant threat to the integrity and reliability of recommender systems by injecting fake user profiles to promote or demote targeted items. Existing generative approaches often suffer from unstable training dynamics and limited realism in the synthesized profiles. In this paper, we propose PGAN, a novel Penalized Generative Adversarial Network enhanced with latent space perturbations to generate high-quality, diverse, and undetectable shilling attack profiles. PGAN incorporates a gradient penalty to stabilize discriminator training and applies controlled noise perturbations in the generator’s latent space to improve robustness and attack diversity. We evaluate PGAN on real-world datasets and show that it consistently outperforms traditional statistical attacks and baseline GAN-based models across multiple evaluation metrics, such as Hit Ratio@K, Prediction Shift, and attack success rate. Experimental results also confirm the realism of the generated profiles through similarity analysis with genuine users. Our proposed model could surpass traditional and state-of-the-art methods, with HR@10 of 0.2051 and 0.2076 on MovieLens and Amazon datasets, respectively.\u003c/p\u003e","manuscriptTitle":"PGAN: Penalized GANs with Latent Perturbation for Robust Shilling Attack Generation in Recommender Systems","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-04-15 01:09:02","doi":"10.21203/rs.3.rs-6395334/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2025-04-24T10:43:30+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2025-04-23T14:41:39+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2025-04-23T14:40:12+00:00","index":"","fulltext":""},{"type":"submitted","content":"Discover Computing","date":"2025-04-07T14:30:28+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"discover-computing","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"","sideBox":"Learn more about [Discover Computing](https://link.springer.com/journal/10791)","snPcode":"10791","submissionUrl":"https://submission.springernature.com/new-submission/10791/3","title":"Discover Computing","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"stoa","reportingPortfolio":"Discover Series","inReviewEnabled":true,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"82d11eb2-20ef-4672-9333-15702e7e9585","owner":[],"postedDate":"April 15th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"published-in-journal","subjectAreas":[],"tags":[],"updatedAt":"2025-08-25T16:39:51+00:00","versionOfRecord":{"articleIdentity":"rs-6395334","link":"https://doi.org/10.1007/s10791-025-09702-2","journal":{"identity":"discover-computing","isVorOnly":false,"title":"Discover Computing"},"publishedOn":"2025-08-22 16:29:18","publishedOnDateReadable":"August 22nd, 2025"},"versionCreatedAt":"2025-04-15 01:09:02","video":"","vorDoi":"10.1007/s10791-025-09702-2","vorDoiUrl":"https://doi.org/10.1007/s10791-025-09702-2","workflowStages":[]},"version":"v1","identity":"rs-6395334","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-6395334","identity":"rs-6395334","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00