TAaMR
Targeted Adversarial Attack against Multimedia Recommender Systems
Research Questions
- Can targeted adversarial attacks against images of a low recommended category of products be exploited to modify the recommendation lists of multimedia recommender systems in terms of probability of being more recommended?
- What are the effects of adversarial perturbations against these attacked images for human-perceptions?

Definition of the Targeted Adversarial Attack
Let be a set of classes for a classifier . Let be the source class such that , and be a target class with . A Targeted Adversarial Attack finds the adversarial examples as following:
\begin{align*} min_{d\leq\epsilon}d(x,x^*)\\{such\ that\ F(x^*) = t} \end{align*}
