25.3.4 Informed Attack Models
The low-knowledge attacks above work by approximating the average attack, concentrating on items that are expected to be rated because of their popularity. The
average attack in turn is a natural choice for an attacker with a basic intuition about
collaborative recommendation, namely that users will be compared on the basis of
similarity, so the incentive is to make the profiles similar to the average user. If, on
the other hand, the attacker has more detailed knowledge of the precise algorithm, a
more powerful attack can be mounted.