Skip to content
Book Open access

MaskPoison: Intent-Guided Poisoning Attacks on Sequential Recommendation via Masked Discrete Diffusion

Sep 2026 · Proceedings of the 20th ACM Conference on Recommender Systems · 0 citations · 26 references

Abstract

Sequential recommendation (SR) systems are widely deployed across modern online platforms, and have been shown to be vulnerable to poisoning attacks. Such attacks inject fabricated user sequences into training data to promote target items. Existing methods achieve stealthiness by enforcing surface-level similarity to genuine data, including matching item frequencies, local transition patterns, and co-occurrence statistics. This assumption holds in idealized, homogeneous settings where user behaviors are narrow and repetitive. In real-world platforms, however, users exhibit diverse and context-dependent behavioral intents. In such heterogeneous environments, surface-level mimicry fails to preserve the logical coherence of user intent, causing poisoned sequences to be detectable. We propose MaskPoison, an intent-guided poisoning framework that addresses this fundamental gap. Our method extracts intent anchors from real user sequences containing the target item. A masked discrete diffusion model then synthesizes poisoned sequences conditioned on these anchors as hard semantic constraints, ensuring alignment with the behavioral manifolds of genuine users. Extensive experiments demonstrate that MaskPoison outperforms existing attacks in both attack effectiveness and stealthiness, across homogeneous and heterogeneous recommendation scenarios alike. Our code is available at https://github.com/Zoezhouzzz/MaskPoison-Code.git.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.