publications
publications by categories in reversed chronological order. generated by jekyll-scholar.
- R&RImpact of Data Privacy Regulations on Recommender Systems PerformanceLiben Chen, Meizi Zhou, Yicheng Song, and Gediminas AdomaviciusConditional Acceptance at Information Systems Research
Data privacy regulations empower consumers to control the collection of their personal data. A significant consequence of these regulations is their effect on various data-driven business solutions, especially on personalization technologies and recommender systems. We investigate the potential impacts of diverse real-world data privacy practices (that can be adopted by firms in response to various data privacy regulations) on the recommender systems performance. We also examine how these impacts vary across different personalization contexts and applications. In particular, we distinguish between scenarios where the user population exhibits more stable vs. more dynamic (i.e., changing) preferences, as these scenarios often represent distinctly different recommendation settings. We use a simulation framework, carefully seeded with real-world data, for a comprehensive evaluation of the recommender system performance under numerous scenarios, such as different recommendation algorithms, different data privacy practices, different degrees of users’ preference dynamics, etc. Extensive computational experiments uncover several robust performance patterns for different data privacy practices and highlight substantial differences between recommendation settings with stable vs. changing user preferences. Furthermore, building upon the comprehensive findings from our computational experiments, we propose flexible, parameterizable data privacy practice designs based on the notion of revelation protection. The proposed approach is designed to provide an effective balance between personalization performance and privacy considerations, as demonstrated using extensive simulation experiments. The findings of this study have significant implications for the design of privacy-aware recommender systems in the context of contemporary data privacy regulations. The findings can also be informative to policymakers for understanding the practical implications of various data privacy practices and for designing future policies.
- R&REchoes of Manipulation: The Reinforcing Effect of Preference Bias on External Perturbations in Recommender SystemsLiben Chen, Meizi Zhou, Jingjing Zhang, and Gediminas AdomaviciusUnder Second-Round Review at INFORMS Journal on Computing
Preference bias is a well-established phenomenon in recommender systems (RS), where the system-predicted rating that the user observes as part of the item recommendation (i.e., before consuming the item) ends up systematically impacting the self-reported preference rating that a user provides as feedback after consuming the item. This paper investigates how user preference bias amplifies and prolongs the adverse effects of external perturbations (e.g., shilling attacks) in RS. While prior research has treated preference bias and external manipulations as separate phenomena, we demonstrate through a series of agent-based simulation experiments that their interaction produces self-reinforcing adverse effects. Specifically, we simulate perturbation scenarios where a small subset of items is temporarily promoted through artificial rating inflation. We systematically vary user preference bias levels, the proportion of perturbed users and items, and the duration of perturbation across multiple experimental conditions. Our experiments reveal that even small-scale and transient perturbations can have lasting consequences on RS performance, especially when user preference bias is strong. Perturbed items continue to dominate recommendation lists long after the external shock ends, as biased user feedback reinforces and sustains their artificial prominence. This creates prolonged degradation of predictive accuracy as well as reduced relevance and diversity of consumed items. Importantly, the adverse effects are consistently present across different recommendation algorithms and rating datasets. We also find that unpopular and content-wise common items are especially susceptible to these adverse effects. We further demonstrate these adverse effects under different perturbation strategies. These findings have significant implications for RS design, as they underscore the potential limitations of traditional perturbation defenses (i.e., that may overlook the role of user preference bias) and highlight the need for bias-aware robustness and mitigation frameworks.
- URSelf-Consistent Machine Learning: An Ensemble Smoothing Approach Based on Prediction ConfidenceLiben Chen, Mochen Yang, and Gediminas AdomaviciusUnder Review at Machine Learning
Suppose a machine learning (ML) model is re-trained after the arrival of some new data; however, all the new data instances are such that the model’s prior predictions for them were perfectly accurate. Are the predictions of the updated model consistent with its prior predictions? Such self-consistency of an ML system is an important factor for users’ acceptance of and trust in the ML systems. In this study, we design an ensemble approach for improving the self-consistency of the ML system, based on a smoothing technique. Smoothing adds a pseudo-labeled dataset with the model’s own predictions into the original training data with an explicit goal of improving self-consistency. Our ensemble approach uses smoothing in a prediction-confidence-aware manner and significantly outperforms generic smoothing methods in terms of both self-consistency and predictive performance. This study contributes to understanding the nuances of self-consistency enhancement in ML systems and provides practical insights for designing more robust and trustworthy decision support systems.
- WIPRecommending on a Data Diet: Attribution-Based Data Minimization for Privacy-Aware Recommender SystemsLiben Chen and Gediminas AdomaviciusSymposium on Statistical Challenges in Electronic Commerce Research (SCECR) 2026
Modern data privacy regulations, such as the GDPR, codify the principle of data minimization, which mandates that personal data be limited to what is necessary for a system’s purpose. For recommender systems (RS), which routinely collect granular user behavioral traces at scale, translating this abstract legal mandate into an operational policy leads to an important challenge: how to retain only necessary user data to preserve recommendation quality while minimizing privacy risk. This study formalizes data minimization for RS as a multi-objective optimization over the space of policies that retain or remove individual user-item interactions. We propose Attribution-Based Data Minimization (ABDM), a modular framework that decomposes each system-level outcome into per-interaction attribution scores via two parallel pipelines: a Shapley-based estimator for privacy risk contribution and a data-attribution estimator for recommendation quality contribution, and greedily removes interactions that strongly contribute to privacy risk but not recommendation quality. Across two benchmark datasets and three representative recommenders, ABDM dominates both naive and strong baselines consistently, offering a principled, effective solution to data minimization in RS.
- WIPAre LLM-Based Generative Recommenders Robust to Adversarial Manipulations?Liben Chen, Xuan Bi, and Gediminas AdomaviciusSummer Workshop on AI for Business (SWAIB) 2026
Large language model-based generative recommenders (LLM-based GenRec) have rapidly emerged as a new paradigm for sequential recommendation, delivering state-of-the-art performance and large-scale industrial deployment. Yet little is known about their adversarial robustness. This paper provides one of the first systematic studies of that question through the lens of profile pollution: a minimal black-box attack that appends one or a few adversarial items to a user’s interaction history at inference time, without access to model parameters, gradients, or the full user profile. We show that LLM-based GenRec is highly vulnerable: even a single randomly injected item can reduce top-1 recommendation accuracy by more than 60%, with stronger attacks further degrading the quality of the full recommendation list. Two mechanisms drive this fragility: the attack exploits the model’s strong recency bias to hijack top-ranked recommendations, and adversarial influence then amplifies through the generative process (i.e., autoregressive decoding), propagating damage beyond the top rank into the entire recommendation list. Based on these understandings, we propose a two-stage detect-and-mitigate defense that flags users whose recent history appears foreign and adaptively down-weights attention to suspicious terminal items. Across multiple LLM-based GenRec architectures and attack strengths, the framework recovers a substantial share of the lost recommendation quality, while selective mitigation (enabled by detection) reduces the false-positive cost of indiscriminate mitigation, especially when attack prevalence is low. Altogether, our results reveal a previously understudied robustness risk in LLM-based GenRec and offer an effective, plug-and-play inference-time defense framework.
- WIPReliable Policy-Based Governance of Automated/Augmented Decision-Making SystemsLiben Chen, Mochen Yang, and Gediminas AdomaviciusWorking Project
- WIPSelf-Managed Privacy, Privacy Externality, and Privacy MirageLiben Chen and Gediminas AdomaviciusWorking Project