Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
AGAS — LLM-driven agentic group shilling attack framework that manipulates black-box collaborative-filtering recommender rankings using adaptive multi-role strategies while evading detection. | Kitploit
Tools/GitHubGitHub/phkhanhtrinh23/agas
Machine LearningPapers & ResearchLearning & EducationAI SecurityAdversarial Attack
GitHubphkhanhtrinh23/agas

AGAS

LLM-driven agentic group shilling attack framework that manipulates black-box collaborative-filtering recommender rankings using adaptive multi-role strategies while evading detection.

View Repository
2713 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

An Efficient and Effective Agentic Group Shilling Attack on Recommender Systems

This is the official code to the paper: "An Efficient and Effective Agentic Group Shilling Attack on Recommender Systems". This paper introduces AGAS, which is an LLM-driven shilling attack against black-box collaborative-filtering recommenders. One Coordinator orchestrates a pool of fake-user workers over a sequence of rounds. In each round, the Coordinator picks one of eight strategies and assigns a role to every worker. Workers then decide which items to rate using their own ReAct-style reasoning loop.

AGAS pipeline


1. Repo overview

agent_attack_rs/
  bash/                           # Reviewer-friendly shell scripts (RQ1–RQ5)
  prompts/                        # Coordinator + per-role prompt templates
  scripts/run_agas.py             # Single entry point (--dataset --victim ...)
  src/agas/
    roles.py                      # Role enum {PR, SN, CA, IN} (paper symbols)
    signals.py                    # WorkerSignals (τ, γ, φ) + EnvSignals (ρ, Δρ, η, ξ, a)
    strategies.py                 # 8-strategy enum
    agents/                       # Coordinator + Worker policies
    simulation/                   # Episode runner (= AGAS algorithm outer loop)
    llm/                          # OpenAI / Ollama
    recsys/                       # Surrogate + 11-victim backends
    data/                         # Dataset loaders + preprocessing pipeline
  tests/                          # Pytest suite

2. Method recap

AGAS instantiates four worker roles (paper symbols in roles.py):

SymbolLong nameWhat it does
PRProfilerSafe filler-item ratings to probe the platform and build bridge pools.
SNSniperPayload role; direct target push or bridge-item promotion.
CACamouflageurStealth role; rebuilds trust with benign-looking activity.
INInactiveNo action this round (cool-down or quarantine).

Each round the Coordinator chooses exactly one of eight strategies from strategies.py (see method_strategies.tex):

  1. Victim Probe (S1_VICTIM_PROBE)
  2. Bridge Building (S2_BRIDGE_BUILDING, graph victims only)
  3. Warm-up (S3_WARM_UP)
  4. First Push (S4_FIRST_PUSH)
  5. Silent Slowdown (S5_SILENT_SLOWDOWN)
  6. Profile Cleanup (S6_PROFILE_CLEANUP)
  7. Safe Replacement (S7_SAFE_REPLACEMENT)
  8. Main Attack (S8_MAIN_ATTACK)

The Coordinator drives those decisions from two signal groups (signals.py):

  • Worker signals τ_{t,w}, γ_{t,w}, φ_{t,w} — trust, risk, and a structural validator. Update equations match method_coordinator.tex exactly (eq:trust_update, eq:risk_update, eq:risk_decay, eq:profile_validator).
  • Environment signals ρ^{(t)}, Δρ^{(t)}, η_t, ξ_t = (q_t, s_t), a_t — rank, rank-movement, acceptance rate, suppression signal, alert flag. The suspicion score q_t is the 0.2-weighted sum of the five normalised terms (d̂_t, δ̂_t, m̂_t, ŝ_t, g_t) from eq:round_suppression_terms and eq:round_suppression_score.

Round loop (ASCII)

                ┌─────────────────────────────────────────────────┐
   t=0…T-1 ──►  │ 1. Observe ρ^{(t)}, update memory m_t           │
                │ 2. Update τ, γ, φ, η, ξ, a                       │
                │ 3. Coordinator picks Strategy ∈ {S1…S8}          │
                │    and assigns Role ∈ {PR, SN, CA, IN} per worker│
                │ 4. Workers act (filler / bridge / target items)  │
                │ 5. Validate + accept actions → ΔR̃^{(t+1)}        │
                │ 6. Refit / query victim → ρ^{(t+1)}              │
                └─────────────────────────────────────────────────┘
                          │
                          ▼
                   t* = argmin_t ρ^{(t)}, return R* = [R ; R̃^{(≤t*)}]

The outer loop is implemented in src/agas/simulation/episode.py and mirrors algorithms/agas_end_to_end.tex.

3. Environment

ComponentRequirementTested with
Python≥ 3.103.13.5
PyTorch≥ 2.1 (targets only)2.11.0+cu128
CUDAoptional12.8
NumPy≥ 1.242.4.2
Pandas≥ 2.03.0.1
SciPy≥ 1.101.17.0
scikit-learn≥ 1.31.8.0
openai SDK≥ 1.122.21.0

PyTorch and CUDA are only required for the deep-learning victim models ([targets] extra). The core AGAS loop and the rule-based / surrogate paths run on CPU with no GPU dependency.

4. Install

pip install -e .
# If you want to use the deep-learning victim models (LightGCN, NeuMF, …)
pip install -e '.[targets]'

Required environment variables:

VariablePurposeDefault
OPENAI_API_KEYOpenAI Responses API key for the Coordinator / worker LLMs.(unset → fallback)
OPENAI_MODELModel name passed to OpenAI.gpt-5.1

4. Datasets

The paper evaluates on six public CF benchmarks (see experiment.tex):

Short nameSourceUsersItemsInteractionsDownloadPlace raw files in
ML-100KMovieLens 100K9431,682100,000GroupLensdata/ml-100k/
ML-1MMovieLens 1M6,0403,7061,000,209GroupLensdata/ml-1m/
Genome 2021MovieLens Tag Genome 202137,94184,6612,000,000 (capped)GroupLensdata/genome2021/
NetflixNetflix Prize342,44517,4342,000,000 (capped)Kaggledata/netflix/
DoubanDouban Movie28,05749,1768,085,679HKUSTdata/douban/
AmazonAmazon Reviews 2018998,65330,9642,000,000 (capped)UCSDdata/amazon/

After dropping the raw downloads into data/<dataset>/, run:

python scripts/preprocess_all.py --data-root data --output-root processed

Each dataset is rewritten into canonical interactions.csv + items.csv files under processed/<dataset>/. The smoke tests use the much smaller ml-latest-small sample that ships with MovieLens.

Download Tool