acceptodds
Under review as a conference paper at ICLR 2027

Adaptive Admission Attacks on Semantic-ID Generative Recommenders: Detectability, Payload Size, and Downstream Promotion

Abstract

Admission-time defenses screen newly logged interaction histories before a recommender is retrained, and are typically judged by how cleanly they separate a known attack from randomly resampled benign users. We show that this evaluation can substantially overstate security. Studying semanticID generative recommendation, we define attack success jointly as passing admission and promoting a target item after retraining, and construct a staged family of non-neural shilling attacks that adapts payload, profile length, item popularity, and transition structure to the gate, culminating in an oracle search against its score. On Amazon Beauty, a gate jointly constraining four cohort statistics rejects every high-payload construction, although adapted attacks evade each staged single-statistic gate; diagonal covariance and calibrated marginal gates make identical decisions on these attacks, so this robustness stems from redundancy rather than correlation modeling. Direct search does find admitted attacks, but only at low payloads: accepted cohorts with 7, 16, and 24 target carriers promote the target to 0.00%, 0.11–0.38%, and 1.4% of eligible users, versus 5–14% for the rejected m = 67 attacks, and the same frontier appears on a second catalog. Admitted cohorts are more harmful for a medium-frequency target (3.6–3.9%) and under a non-generative SASRec recommender (4.7–6.6%). This high-payload protection, however, holds only under favorable evaluation. The same gate has a 0.11% false-positive rate on randomly resampled organic cohorts yet flags 26 of 33 time-ordered windows of genuine users, and attacks rejected in at least 95% of windows when they form half of a cohort pass almost always at a quarter or less, and still promote the target once admitted. We attribute both failures to cohort aggregation, which tightens calibration on exchangeable resamples while diluting each attacker’s contribution, and argue that cohort-level admission defenses must be evaluated against adaptive attackers, temporally ordered benign traffic, and mixed cohorts. Code will be provided after acceptance.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.