CheatAgent: Attacking LLM-Empowered Recommender Systems via LLM Agent
This work investigates security vulnerabilities in LLM-augmented recommender systems (RecSys) under black-box settings—a previously unexplored threat scenario. Method: We propose the first adversarial attack framework leveraging an LLM-based agent, which identifies high-impact text insertion positions via position-aware mechanisms, generates semantically preserved and minimally perturbed adversarial texts, and iteratively refines prompts using black-box query feedback. Crucially, the LLM itself serves as the attack agent, enabling efficient, stealthy, and cross-model transferable attacks. Contribution/Results: Extensive experiments on three real-world datasets demonstrate that our framework significantly outperforms conventional reinforcement learning–based attacks: it achieves higher attack success rates, requires fewer API queries, and induces smaller textual perturbations. These results empirically expose previously underappreciated, substantive security and privacy risks inherent in LLM-RecSys architectures.