Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity

📅 2026-08-04
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of multi-agent collaborative filtering systems to security threats arising from data-driven dynamics and connectivity structures in natural language interactions, where robustness mechanisms remain poorly understood. Within the AgentCF framework, this work pioneers the adaptation of multi-agent system (MAS) attack and defense strategies to large language model–based collaborative filtering. By systematically modulating two connectivity dimensions—user candidate set size and item catalog concentration—the effectiveness of adversarial and defensive methods is rigorously evaluated. The analysis uncovers a non-monotonic temporal influence of connectivity on attack efficacy, reveals an asymmetry in the roles of user and item agents, and demonstrates that static epidemiological metrics can efficiently assess system robustness. The implementation is open-sourced to facilitate future research.
📝 Abstract
Multi-agent collaborative filtering (CF) systems coordinate autonomous LLM-powered user and item agents through natural-language interaction to refine preferences and generate recommendations. These systems inherit vulnerabilities from both their data-driven nature and their multi-agent interactions, which manifest in distinct ways. Understanding how connectivity modulates vulnerability in these systems could facilitate the development of more robust recommendation pipelines. In this work, we adapt attacks and defenses from the general multi-agent systems (MAS) literature to the agent-based CF setting, evaluating them under systematically varied connectivity in the AgentCF framework, where CF connectivity is characterized along two axes: (i) candidate count (the number of item candidates per turn per user, measuring user-side interaction density) and (ii) catalog concentration (the degree of item catalog overlap across users). Our contributions include: (1) Adaptation: we reproduce MAS-inspired attacks and defenses in the agentic CF domain, confirming partial transferability of original observations. (2) Characterization: we characterize how the two aspects of connectivity shape attack and defense outcomes, revealing role asymmetries between user and item agents, non-monotonic temporal dynamics in attack efficacy, and divergent patterns across dissemination and extraction attack goals. Additionally, as an exploratory extension, we assess the applicability of epidemic-inspired static metrics in ranking CF configurations by expected attack outcome, potentially enabling cost-efficient robustness assessment. Implementation is available at https://github.com/anjunhu/ConnACF
Problem

Research questions and friction points this paper is trying to address.

multi-agent collaborative filtering
connectivity
vulnerability
adversarial attacks
recommendation systems
Innovation

Methods, ideas, or system contributions that make the work stand out.

multi-agent collaborative filtering
connectivity
adversarial attacks
robustness
agent-based recommendation
🔎 Similar Papers
No similar papers found.
A
Anjun Hu
University of Oxford
H
Hanting Xie
Amazon
S
Saranya Govindan
Amazon
J
Jas Kandola
Amazon
Kurt Cutajar
Kurt Cutajar
Amazon