neurips_attack_recsys

haoyang

Neural Information Processing Systems 

A.1 Additional Motivational Observations A.1.1 Additional Results on Difficulty-agnostic Analysis Figure 1 shows additional results of TNA [11] and PAPU [51] on The results also verify the conclusion in the Sec 3.1.1: Also, we do not show the result of TrialAttack [45], since it satisfies the difficulty-property 1 that enables attackers to put more efforts on easy users (see Sec. 3.1.2). Additional Results on Diversity-agnostic Analysis Figure 1 shows additional results of TNA [11], PAPU [51], and TrialAttack [45] on ML-100K [14]. We follow the same experiment setting in Sec 3.2.1. As shown in Figure 1 (a) and (c), the fake users of TNA and PAPU form a cluster that is distributed in community 3 and community 1, respectively. Consequently, in Figure 1 (b) and (d), TNA and PAPU improve HR@50 on community 3 and 1, respectively, while keeping similar HR@50 on the other communities. Thus, they suffer from the diversity-deficit issue.