Order Sensitivity in LLM-Based Recommenders Enables Input Reordering Attacks
A new arXiv preprint finds that large language models (LLMs) used as listwise rerankers in recommendation systems are vulnerable to input order manipulation. Attackers can promote irrelevant items into top-k recommendations simply by reordering the input list, with the effect quantified by a new metric (promo@k) reaching up to 0.57 in tested domains. The study also explores mitigation strategies, including architectural changes and regularization techniques.
Why it matters: This highlights a practical security vulnerability in LLM-powered recommendation systems that could affect the trustworthiness of AI-driven content ranking.
Full story at: arXiv Information Retrieval ↗