Modeling and Studying Fairness in Recommender Systems as a Data Manipulation Problem
Fairness-targeted shilling attacks in collaborative filtering
Description
Modern recommender systems are data-intensive pipelines, so fairness depends not only on the recommendation algorithm but also on the training data it learns from. We study this data-level vulnerability through fairness-targeted shilling attacks, where adversaries inject fake user profiles to manipulate fairness in collaborative filtering recommenders. We model the attack as an attempt to alter consumer-side group fairness between privileged and unprivileged users, using disparate impact over relevance- and exposure-based benefits. We instantiate this setting with interpretable profile-injection strategies adapted from classic shilling heuristics and evaluate them across five datasets, multiple attack budgets, 13 recommendation algorithms, and both conventional and fairness-aware settings. Our results show that profile injection is a concrete threat to fairness in recommendation, that effective attacks must exploit group-specific behavioral patterns, and that fairness-aware models may become more vulnerable under such interventions.
This paper has been accepted at EDBT 2027, taking place in Lille, France.