PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 22, 2026Electronics0 citationsOpen Access

Robust and Adaptive Dual-Defense Framework Against Data Poisoning Attacks in Recommendation Systems

XDXiaocui DangPNPriyadarsi NandaHXHeng Xu

Key Points

  • The research aims to develop a framework that mitigates the effects of data poisoning on recommendation systems while maintaining their performance.
  • Proposing a dual-defense framework combining active robust loss and GAN-based detection.
  • Applying the framework to matrix factorization and large language model pipelines.
  • Conducting experiments on various real-world datasets at different poison rates.
  • The method outperformed existing defenses in reducing attack success.
  • Maintained the quality of recommendations despite the presence of data poisoning.
  • Showed compatibility with federated learning environments.

Abstract

Deep learning-based recommendation systems are highly vulnerable to data poisoning attacks, where adversaries manipulate user interactions to degrade model integrity. We hypothesize that combining an active robust loss with a passive GAN-based detection will significantly reduce poisoning impact in recommendation systems without sacrificing utility. We propose a robust and adaptive dual-defense framework: the active defense integrates a crafted loss function to mitigate poisoning effects while maintaining model performance. The passive defense employs a Generative Adversarial Network (GAN)-based detection model to identify and filter poisoned data, enhancing detection accuracy and system security. The framework supports classical matrix factorization (MF) model and large language model (LLM)-based pipelines and scales to large datasets. Extensive experiments across multiple real-world datasets at varying poison rates show that our method outperforms representative defenses, consistently reducing attack success without sacrificing recommendation quality. The framework also admits a federated instantiation, where robust training and GAN-based detection run on clients and only privacy-preserving summaries are aggregated. The proposed method significantly improves the robustness and adaptability of recommendation systems under data poisoning attacks.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Dang et al. (2026) studied this question.

synapsesocial.com/papers/69e865476e0dea528dde9c8bhttps://doi.org/10.3390/electronics15081726
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Balancing Imperceptible and Aggressive Poisoning Attack for Recommender Systems: A Simple Multinomial Diffusion Model2026
  2. 2DuAda: Adaptive Targeted Model Poisoning Attack Framework via Dummy User Simulation on Federated Recommendation2025 · 3 citations
  3. 3Poisoning Attacks and Defenses in Recommender Systems: A Survey2024 · 2 citations
  4. 4A GAN-Based Data Poisoning Attack Against Federated Learning Systems and Its Countermeasure2024
  5. 5Poisoning Decentralized Collaborative Recommender System and Its Countermeasures2024