FINEST: Stabilizing Recommendations by Rank-Preserving Fine-Tuning
Abstract: Modern recommender systems may output considerably different recommendations due to small perturbations in the training data. Changes in the data from a single user will alter the recommendations as well as the recommendations of other users. In applications like healthcare, housing, and finance, this sensitivity can have adverse effects on user experience. We propose a method to stabilize a given recommender system against such perturbations. This is a challenging task due to (1) the lack of a ``reference'' rank list that can be used to anchor the outputs; and (2) the computational challenges in ensuring the stability of rank lists with respect to all possible perturbations of training data. Our method, FINEST, overcomes these challenges by obtaining reference rank lists from a given recommendation model and then fine-tuning the model under simulated perturbation scenarios with rank-preserving regularization on sampled items. Our experiments on real-world datasets demonstrate that FINEST can ensure that recommender models output stable recommendations under a wide range of different perturbations without compromising next-item prediction accuracy.
- 2020. Reddit data dump. http://files.pushshift.io/reddit/.
- MSAP: Multi-Step Adversarial Perturbations on Recommender Systems Embeddings. FLAIRS 34 (Apr. 2021).
- A study of defensive methods to protect visual recommendation against adversarial manipulation of images. In SIGIR, ACM.
- A Formal Analysis of Recommendation Quality of Adversarially-trained Recommenders. In CIKM.
- Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In ICML. 274–283.
- Investigating the Robustness of Sequential Recommender Systems Against Training Data Perturbations: an Empirical Study. arXiv preprint arXiv:2307.13165 (2023).
- Latent cross: Making use of context in recurrent recommender systems. In Proceedings of the eleventh ACM international conference on web search and data mining. 46–54.
- Emily Black and Matt Fredrikson. 2021. Leave-one-out Unfairness. In Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency. 285–295.
- Novelty and diversity in recommender systems. In Recommender systems handbook. 603–646.
- Underspecification Presents Challenges for Credibility in Modern Machine Learning. Journal of Machine Learning Research (2020).
- Transformers4Rec: Bridging the Gap between NLP and Sequential/Session-Based Recommendation. In RecSys.
- TAaMR: Targeted Adversarial Attack against Multimedia Recommender Systems. In DSN-W.
- Enhancing the robustness of neural collaborative filtering systems under malicious attacks. IEEE Transactions on Multimedia 21, 3 (2018).
- Fairness in recommender systems. In Recommender systems handbook. 679–707.
- A survey on trustworthy recommender systems. arXiv preprint arXiv:2207.12515 (2022).
- Maxup: Lightweight adversarial training with data augmentation improves neural network training. In CVPR. 2474–2483.
- Explaining and Harnessing Adversarial Examples. In ICLR.
- Streaming session-based recommendation. In SIGKDD.
- Contextual and sequential user embeddings for large-scale music recommendation. In RecSys.
- F. Maxwell Harper and Joseph A. Konstan. 2015. The MovieLens Datasets: History and Context. ACM Trans. Interact. Intell. Syst., Article 19 (Dec. 2015), 19 pages.
- Adversarial personalized ranking for recommendation. In SIGIR.
- Balázs Hidasi and Domonkos Tikk. 2012. Fast ALS-based tensor factorization for context-aware recommendation from implicit feedback. In ECML PKDD.
- Reducing Model Churn: Stable Re-training of Conversational Agents. In Proceedings of the 23rd Annual Meeting of the Special Interest Group on Discourse and Dialogue. 14–25.
- Sepp Hochreiter and Jürgen Schmidhuber. 1997. Long short-term memory. Neural computation 9, 8 (1997).
- Paul Jaccard. 1912. The distribution of the flora in the alpine zone. 1. New phytologist 11, 2 (1912), 37–50.
- When people change their mind: Off-policy evaluation in non-stationary recommendation environments. In WSDM.
- Dietmar Jannach and Michael Jugovac. 2019. Measuring the business value of recommender systems. ACM Transactions on Management Information Systems (TMIS) 10, 4 (2019), 1–23.
- Churn Reduction via Distillation. In International Conference on Learning Representations.
- Wang-Cheng Kang and Julian McAuley. 2018. Self-attentive sequential recommendation. In 2018 IEEE international conference on data mining (ICDM). IEEE, 197–206.
- Maurice George Kendall. 1948. Rank correlation methods. (1948).
- Walid Krichene and Steffen Rendle. 2022. On sampled metrics for item recommendation. Commun. ACM 65, 7 (2022), 75–83.
- Predicting Dynamic Embedding Trajectory in Temporal Interaction Networks. In SIGKDD.
- Interactive path reasoning on graph for conversational recommendation. In SIGKDD.
- Alexander Levine and Soheil Feizi. 2020. Robustness certificates for sparse adversarial attacks by randomized ablation. In AAAI, Vol. 34. 4585–4593.
- Time interval aware self-attention for sequential recommendation. In Proceedings of the 13th international conference on web search and data mining. 322–330.
- Time Interval Aware Self-Attention for Sequential Recommendation. In WSDM.
- Dynamic graph collaborative filtering. In ICDM.
- Multi-Task Deep Neural Networks for Natural Language Understanding. In Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics. Association for Computational Linguistics, 4487–4496. https://www.aclweb.org/anthology/P19-1441
- Predictive multiplicity in classification. In International Conference on Machine Learning. PMLR, 6765–6774.
- Launch and iterate: Reducing prediction churn. Advances in Neural Information Processing Systems 29 (2016).
- TextAttack: A Framework for Adversarial Attacks, Data Augmentation, and Adversarial Training in NLP. In EMNLP.
- Rank List Sensitivity of Recommender Systems to Interaction Perturbations. In CIKM.
- IACN: Influence-Aware and Attention-Based Co-evolutionary Network for Recommendation. In PAKDD.
- Dae Hoon Park and Yi Chang. 2019. Adversarial sampling and training for semi-supervised information retrieval. In WWW.
- Personalized re-ranking for recommendation. In RecSys.
- Estimating Training Data Influence by Tracking Gradient Descent. NeurIPS.
- Certified robustness to label-flipping attacks via randomized smoothing. In ICML.
- Diversity Vs Relevance: A Practical Multi-objective Study in Luxury Fashion Recommendations. In SIGIR. 2405–2409.
- Defense-GAN: Protecting Classifiers Against Adversarial Attacks Using Generative Models. In ICLR.
- Brent Smith and Greg Linden. 2017. Two decades of recommender systems at Amazon. com. Ieee internet computing 21, 3 (2017), 12–18.
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender Systems. In ICDE.
- BERT4Rec: Sequential recommendation with bidirectional encoder representations from transformer. In CIKM.
- Abigail Swenor. 2022. Using Random Perturbations to Mitigate Adversarial Attacks on NLP Models. AAAI (2022), 13142–13143.
- Towards More Robust and Accurate Sequential Recommendation with Cascade-guided Adversarial Training. arXiv preprint arXiv:2304.05492 (2023).
- Adversarial training towards robust multimedia recommender system. TKDE 32, 5 (2019), 855–867.
- Jiaxi Tang and Ke Wang. 2018. Ranking distillation: Learning compact ranking models with high performance for recommender system. In Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining. 2289–2298.
- Revisiting Adversarially Learned Injection Attacks Against Recommender Systems. In RecSys.
- Attentive sequential models of latent intent for next item recommendation. In Proceedings of The Web Conference 2020. 2528–2534.
- Time to Shop for Valentine’s Day: Shopping Occasions and Sequential Recommendation in E-commerce. In Proceedings of the 13th International Conference on Web Search and Data Mining. 645–653.
- Adversarial Attack Generation Empowered by Min-Max Optimization. In Thirty-Fifth Conference on Neural Information Processing Systems.
- Trustworthy recommender systems. ACM Transactions on Intelligent Systems and Technology (2022).
- A Survey on the Fairness of Recommender Systems. ACM Journal of the ACM (JACM) (2022).
- Predictive Multiplicity in Probabilistic Classification. arXiv:2206.01131 (2022).
- A similarity measure for indefinite rankings. ACM TOIS (2010).
- Triple Adversarial Learning for Influence based Poisoning Attack in Recommender Systems. In SIGKDD.
- Fight Fire with Fire: Towards Robust Recommender Systems via Adversarial Poisoning Training. In SIGIR. 1074–1083.
- Bridging collaborative filtering and semi-supervised learning: a neural approach for poi recommendation. In SIGKDD.
- Location recommendation for location-based social networks. In SIGSPATIAL. 458–461.
- Adversarial collaborative neural network for robust recommendation. In SIGIR.
- Time-aware point-of-interest recommendation. In SIGIR.
- Graph-based point-of-interest recommendation with geographical and temporal influences. In CIKM.
- Black-Box Attacks on Sequential Recommenders via Data-Free Model Extraction. In RecSys.
- Defending substitution-based profile pollution attacks on sequential recommenders. In Proceedings of the 16th ACM Conference on Recommender Systems. 59–70.
- Practical Data Poisoning Attack against Next-Item Recommendation. In TheWebConf.
- Data Poisoning Attack against Recommender System Using Incomplete and Perturbed Data. In SIGKDD.
Paper Prompts
Sign up for free to create and run prompts on this paper using GPT-5.
Top Community Prompts
Collections
Sign up for free to add this paper to one or more collections.