Social Science Research Council Research AMP Just Tech
Citation

With a Little Help From My Friends: Collective Manipulation in Risk-Controlling Recommender Systems

Author:
De Toni, Giovanni; Consonni, Cristian; Purificato, Erasmo; Gómez, Emilia; Lepri, Bruno
Year:
2026

Recommendation systems have become central gatekeepers of online information, shaping what users see across a wide range of activities. In response, users increasingly organize and coordinate their behaviour to steer algorithmic outcomes toward diverse goals, such as promoting relevant content or limiting harmful material. These collective actions typically operate through platform affordances – such as likes, reviews, or ratings – that allow users to provide feedback to the system. However, the same mechanisms can also be leveraged for adversarial purposes, including coordinated manipulation or political influence campaigns. This concern is central for affordances explicitly designed as safety mechanisms, such as the “Not Interested” signal in recommender systems, whose vulnerability to coordinated behaviour remains largely unexplored. Recently proposed risk-controlling recommender systems build directly on these feedback signals using binary user input (e.g., “Not Interested”) to provably bound the amount of unwanted content in users’ feeds using conformal risk control. We argue that their reliance on aggregate feedback signals makes them inherently susceptible to coordinated adversarial user behaviour. In this paper, we empirically demonstrate, using data from a large-scale online video-sharing platform, that a small coordinated group (comprising only 1% of the user population) can induce up to a 20% degradation in nDCG for non-adversarial users, by exploiting the affordances provided by risk-controlling recommender systems. We evaluate several simple and realistic attack strategies that require little to no knowledge of the underlying recommendation algorithm. Our findings also reveal that coordinated users are unable to selectively suppress the exposure of specific target groups solely through reporting. Lastly, we describe a mitigation strategy that shifts guarantees from the group level to the user level, showing empirically how it can reduce the impact of adversarial coordinated behaviour while ensuring personalized safety for individuals.