{"id":"https://openalex.org/W4414035031","doi":"https://doi.org/10.1145/3705328.3748158","title":"Privacy Risks of LLM-Empowered Recommender Systems: An Inversion Attack Perspective","display_name":"Privacy Risks of LLM-Empowered Recommender Systems: An Inversion Attack Perspective","publication_year":2025,"publication_date":"2025-09-06","ids":{"openalex":"https://openalex.org/W4414035031","doi":"https://doi.org/10.1145/3705328.3748158"},"language":"en","primary_location":{"id":"doi:10.1145/3705328.3748158","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3705328.3748158","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Nineteenth ACM Conference on Recommender Systems","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3705328.3748158","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5018847319","display_name":"Yubo Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I56590836","display_name":"Monash University","ror":"https://ror.org/02bfwt286","country_code":"AU","type":"education","lineage":["https://openalex.org/I56590836"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Yubo Wang","raw_affiliation_strings":["Monash University, Melbourne, Australia"],"raw_orcid":"https://orcid.org/0009-0006-6088-9907","affiliations":[{"raw_affiliation_string":"Monash University, Melbourne, Australia","institution_ids":["https://openalex.org/I56590836"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056445370","display_name":"Min Tang","orcid":"https://orcid.org/0009-0000-1088-8523"},"institutions":[{"id":"https://openalex.org/I56590836","display_name":"Monash University","ror":"https://ror.org/02bfwt286","country_code":"AU","type":"education","lineage":["https://openalex.org/I56590836"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Min Tang","raw_affiliation_strings":["Monash University, Melbourne, Australia"],"raw_orcid":"https://orcid.org/0009-0000-1088-8523","affiliations":[{"raw_affiliation_string":"Monash University, Melbourne, Australia","institution_ids":["https://openalex.org/I56590836"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Nuo Shen","orcid":"https://orcid.org/0009-0001-8363-0125"},"institutions":[{"id":"https://openalex.org/I56590836","display_name":"Monash University","ror":"https://ror.org/02bfwt286","country_code":"AU","type":"education","lineage":["https://openalex.org/I56590836"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Nuo Shen","raw_affiliation_strings":["Monash University, Melbourne, Australia"],"raw_orcid":"https://orcid.org/0009-0001-8363-0125","affiliations":[{"raw_affiliation_string":"Monash University, Melbourne, Australia","institution_ids":["https://openalex.org/I56590836"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103162802","display_name":"Shujie Cui","orcid":"https://orcid.org/0000-0001-8124-6800"},"institutions":[{"id":"https://openalex.org/I56590836","display_name":"Monash University","ror":"https://ror.org/02bfwt286","country_code":"AU","type":"education","lineage":["https://openalex.org/I56590836"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Shujie Cui","raw_affiliation_strings":["Monash University, Melbourne, Australia"],"raw_orcid":"https://orcid.org/0000-0001-8124-6800","affiliations":[{"raw_affiliation_string":"Monash University, Melbourne, Australia","institution_ids":["https://openalex.org/I56590836"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100372965","display_name":"Weiqing Wang","orcid":"https://orcid.org/0000-0002-9578-819X"},"institutions":[{"id":"https://openalex.org/I56590836","display_name":"Monash University","ror":"https://ror.org/02bfwt286","country_code":"AU","type":"education","lineage":["https://openalex.org/I56590836"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Weiqing Wang","raw_affiliation_strings":["Monash University, Melbourne, Australia"],"raw_orcid":"https://orcid.org/0000-0002-9578-819X","affiliations":[{"raw_affiliation_string":"Monash University, Melbourne, Australia","institution_ids":["https://openalex.org/I56590836"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5018847319"],"corresponding_institution_ids":["https://openalex.org/I56590836"],"apc_list":null,"apc_paid":null,"fwci":2.9051,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.92740523,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"812","last_page":"821"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10203","display_name":"Recommender Systems and Techniques","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10203","display_name":"Recommender Systems and Techniques","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9921000003814697,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/recommender-system","display_name":"Recommender system","score":0.8016111850738525},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7744914293289185},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.656008243560791},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.5734113454818726},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.40522414445877075},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.39549437165260315},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.2590579092502594},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.18871775269508362}],"concepts":[{"id":"https://openalex.org/C557471498","wikidata":"https://www.wikidata.org/wiki/Q554950","display_name":"Recommender system","level":2,"score":0.8016111850738525},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7744914293289185},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.656008243560791},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.5734113454818726},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.40522414445877075},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.39549437165260315},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.2590579092502594},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.18871775269508362},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3705328.3748158","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3705328.3748158","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Nineteenth ACM Conference on Recommender Systems","raw_type":"proceedings-article"},{"id":"pmh:oai:monash.edu:openaire/c73fd5cd-c655-4f02-97cd-03957b5829e8","is_oa":true,"landing_page_url":"https://research.monash.edu/en/publications/c73fd5cd-c655-4f02-97cd-03957b5829e8","pdf_url":"https://researchmgt.monash.edu/ws/files/767281009/736349507-oa.pdf","source":{"id":"https://openalex.org/S4306402625","display_name":"Monash University Research Portal (Monash University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I56590836","host_organization_name":"Monash University","host_organization_lineage":["https://openalex.org/I56590836"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Wang, Y, Tang, M, Shen, N, Cui, S & Wang, W 2025, Privacy Risks of LLM-Empowered Recommender Systems : An Inversion Attack Perspective. in C de Gemmis & S Pera (eds), Proceedings of the 19th ACM Conference on Recommender Systems. Association for Computing Machinery (ACM), New York NY USA, pp. 812-821, ACM Conference on Recommender Systems 2025, Prague, Czechia, 22/09/25. https://doi.org/10.1145/3705328.3748158","raw_type":"contributionToPeriodical"}],"best_oa_location":{"id":"doi:10.1145/3705328.3748158","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3705328.3748158","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the Nineteenth ACM Conference on Recommender Systems","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4828062937","display_name":null,"funder_award_id":"DE250100032","funder_id":"https://openalex.org/F4320334704","funder_display_name":"Australian Research Council"}],"funders":[{"id":"https://openalex.org/F4320334704","display_name":"Australian Research Council","ror":"https://ror.org/05mmh0f86"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":22,"referenced_works":["https://openalex.org/W2042281163","https://openalex.org/W2051267297","https://openalex.org/W2054141820","https://openalex.org/W2105953200","https://openalex.org/W2116206254","https://openalex.org/W2219888463","https://openalex.org/W2535690855","https://openalex.org/W2972646741","https://openalex.org/W3031339255","https://openalex.org/W3084695837","https://openalex.org/W4205991051","https://openalex.org/W4296591867","https://openalex.org/W4386728930","https://openalex.org/W4386728933","https://openalex.org/W4389520346","https://openalex.org/W4394994587","https://openalex.org/W4396734745","https://openalex.org/W4401863692","https://openalex.org/W4401863964","https://openalex.org/W4403967201","https://openalex.org/W4404792952","https://openalex.org/W4407403520"],"related_works":["https://openalex.org/W2899084033","https://openalex.org/W4390273403","https://openalex.org/W4386781444","https://openalex.org/W2150182025","https://openalex.org/W3092950680","https://openalex.org/W3197542405","https://openalex.org/W2056712470","https://openalex.org/W3125580266","https://openalex.org/W4288390103","https://openalex.org/W4317039510"],"abstract_inverted_index":{"The":[0,162,196],"large":[1],"language":[2],"model":[3],"(LLM)":[4],"powered":[5],"recommendation":[6,93,132],"paradigm":[7],"has":[8],"been":[9],"proposed":[10,105],"to":[11,23,43,74,172],"address":[12],"the":[13,61,89,97,148,160,173],"limitations":[14],"of":[15,92,114,147,159],"traditional":[16],"recommender":[17],"systems":[18],"(RecSys),":[19],"which":[20],"often":[21],"struggle":[22],"handle":[24],"cold-start":[25],"users":[26],"or":[27],"items":[28,150],"with":[29],"new":[30],"IDs.":[31],"Despite":[32],"its":[33],"effectiveness,":[34],"this":[35,57],"study":[36,64],"uncovers":[37],"that":[38,46,78,135,166],"LLM-empowered":[39,69,194],"RecSys":[40],"are":[41],"vulnerable":[42],"reconstruction":[44,113],"attacks":[45,67],"can":[47,143],"expose":[48,188],"both":[49],"system":[50],"and":[51,84,100,126,128,151,155,183,190],"user":[52],"privacy.":[53],"To":[54],"thoroughly":[55],"examine":[56],"threat,":[58],"we":[59,142],"present":[60],"first":[62],"systematic":[63],"on":[65,180],"inversion":[66],"targeting":[68],"RecSys,":[70],"wherein":[71],"adversaries":[72],"attempt":[73],"reconstruct":[75],"original":[76],"prompts":[77,116],"contain":[79],"personal":[80],"preferences,":[81],"interaction":[82],"histories,":[83],"demographic":[85],"attributes":[86],"by":[87],"exploiting":[88],"output":[90],"logits":[91],"models.":[94],"We":[95],"reproduce":[96],"vec2text":[98],"framework":[99],"optimize":[101],"it":[102],"using":[103],"our":[104,136],"method":[106,137],"-":[107],"Similarity-Guided":[108],"Refinement,":[109],"enabling":[110],"more":[111],"accurate":[112],"textual":[115],"from":[117],"model-generated":[118],"logits.":[119],"Extensive":[120],"experiments":[121,163],"across":[122],"two":[123,129],"domains":[124],"(movies":[125],"books)":[127],"representative":[130],"LLM-based":[131],"models":[133],"demonstrate":[134],"achieves":[138],"high-fidelity":[139],"reconstructions.":[140],"Specifically,":[141],"recover":[144],"nearly":[145],"65%":[146],"user-interacted":[149],"correctly":[152],"infer":[153],"age":[154],"gender":[156],"in":[157,193],"87%":[158],"cases.":[161],"also":[164],"reveal":[165],"privacy":[167,191],"leakage":[168],"is":[169,200],"largely":[170],"insensitive":[171],"victim":[174],"model's":[175],"performance":[176],"but":[177],"highly":[178],"dependent":[179],"domain":[181],"consistency":[182],"prompt":[184],"complexity.":[185],"These":[186],"findings":[187],"critical":[189],"vulnerabilities":[192],"RecSys.":[195],"code":[197],"for":[198],"reproduction":[199],"provided":[201],"below:":[202],"https://github.com/xuemingxxx/Attack_RecSys/":[203]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
