Priyansh Singhal, Sumit Maheshwari · ACM Conference on Recommender Systems (RecSys) 2026 · 2026
DOI: 10.1145/3773078.3831802
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Conversational recommender systems (CRS) pursue ever-deeper personalization, dissolving the separation between system and user that earlier paradigms maintained, by modeling individual preferences, memories, and emotional states through sustained dialogue. This paper argues that this trajectory carries a safety liability intrinsic to personalization itself. Benign, organically accumulated user context degrades safety alignment across frontier LLMs through intent legitimation, memory-induced sycophancy, and cross-domain leakage, none of which require adversarial input. The vulnerability is compounded by a formal property of RLHF training that amplifies sycophantic tendencies, meaning the base LLMs on which CRS are built already carry a predisposition that personalization deepens. Emotionally vulnerable users are disproportionately affected, with population-level evidence of increasing emotional dependency and safety performance that degrades as user emotional intensity increases. This position paper traces the field’s evolution toward conversational personalization, then presents mechanistic and real-world evidence that the CRS research objective and the alignment community’s safety vulnerability are structurally identical. We further ask whether better alignment, architectural decoupling, or scale can resolve it. We argue that the CRS community is well positioned to lead the development of personalization approaches that are safety-aware by design rather than safety-compromised by default.
No comments yet — start the discussion below.