Efficient Detection of Shillings Attacks in Collaborative Filtering Recommendation Systems using Hybrid Deep Learning: A CNN-based Model and Architecture
Bibliographic record
Abstract
Recommendation systems are widely used in various areas to personalize recommendations to users. However, they are vulnerable to shilling attacks in which malicious users try to promote their products or diminish their competitors. Therefore, detecting shilling attacks can significantly improve the quality of recommender systems. With the increasing complexity of attacks and changes in attackers' behaviour, more advanced approaches are required to find the hidden patterns in data. This thesis proposes a CNN-based hybrid model and architecture that integrates self-learning and flexible aspects of CNN with other supervised learning methods to enhance shillings attacks detection on collaborative filtering recommendation systems. We also introduce a new metric, the F-compatible score, to measure the compatibility ratio of merging the CNN with any other classifier in a given aggregate. This measure helps in monitoring the enhancement level of the detection results of shilling attacks. Two different approaches are proposed in this thesis, user-based, and item-based. The experimental analysis used three benchmark datasets: the Movie-Lens 100K, Netflix, and Movie-Lens 1M. A comprehensive comparative analysis is also completed to assess the performance of both individual-based and hybrid-based detection models. Experimental results show that the proposed hybrid models performed well on most attack profiles and reached an F1-score of up to 99%. We concluded that the superiority of hybrid models over individual models depends on the sparsity level of data and the divergence of results.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.001 | 0.001 |
| Meta-epidemiology (narrow) | 0.001 | 0.000 |
| Meta-epidemiology (broad) | 0.001 | 0.001 |
| Bibliometrics | 0.001 | 0.000 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.001 | 0.001 |
| Open science | 0.001 | 0.001 |
| Research integrity | 0.001 | 0.001 |
| Insufficient payload (model declined to judge) | 0.001 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".