paper-with-me

홈 › Papers

A Curious Case of Searching for the Correlation between Training Data and Adversarial Robustness of Transformer Textual Models

2024-02-18 · Cuong Dang, Dung D. Le, Thai Le

Existing works have shown that fine-tuned textual transformer models achieve state-of-the-art prediction performances but are also vulnerable to adversarial text perturbations. Traditional adversarial evaluation is often done \textit{only after} fine-tuning the models and ignoring the training data. In this paper, we want to prove that there is also a strong correlation between training data and model robustness. To this end, we extract 13 different features representing a wide range of input fine-tuning corpora properties and use them to predict the adversarial robustness of the fine-tuned models. Focusing mostly on encoder-only transformer models BERT and RoBERTa with additional results for BART, ELECTRA, and GPT2, we provide diverse evidence to support our argument. First, empirical analyses show that (a) extracted features can be used with a lightweight classifier such as Random Forest to predict the attack success rate effectively, and (b) features with the most influence on the model robustness have a clear correlation with the robustness. Second, our framework can be used as a fast and effective additional tool for robustness evaluation since it (a) saves 30x-193x runtime compared to the traditional technique, (b) is transferable across models, (c) can be used under adversarial training, and (d) robust to statistical randomness. Our code is publicly available at \url{https://github.com/CaptainCuong/RobustText_ACL2024}.

📄 PDF Abstract BibTeX arXiv:2402.11469

Code (1)

captaincuong/robusttext_acl2024 공식 구현 pytorch

Tasks

Adversarial RobustnessAdversarial Text

Methods 이 논문이 사용한 방법론

Refunds@Expedia|||How do I get a full refund from Expedia? “How do I get a full refund from Expedia? How do I get a full refund from Expedia? – Call ☎️ +1-(888) 829 (0881) or +1-805-330-4056 or +1-805-330-4056 for Quick Help &…
Attention 설명 없음
WordPiece 설명 없음
Linear Warmup With Linear Decay Linear Warmup With Linear Decay is a learning rate schedule in which we increase the learning rate linearly for $n$ updates and then linearly decay afterwards.
Dropout Dropout is a regularization technique for neural networks that drops a unit (along with connections) at training time with a specified probability $p$ (a common value is…
Linear Layer A Linear Layer is a projection $\mathbf{XW + b}$.
Weight Decay 설명 없음
BPE Byte Pair Encoding, or BPE, is a subword segmentation algorithm that encodes rare and unknown words as sequences of subword units. The intuition is that various word…

Similar Papers 제목 키워드 기반

The growth and form of knowledge networks by kinesthetic curiosity

2020-06-04 · Dale Zhou, David M. Lydon-Staley, Perry Zurn, Danielle S. Bassett

Throughout life, we might seek a calling, companions, skills, entertainment, truth, self-knowledge, beauty, and edification. The practice of curiosity can be viewed as an extended and open-ended search for valuable infor…

FormModel-based Reinforcement LearningPhilosophy

The Curious Case of Metonymic Verbs: A Distributional Characterization

2013-03-01 · WS 2013 3 · Jason Utt, Aless Lenci, ro, Sebastian Pad{\'o} 외

Word Embeddings vs Word Types for Sequence Labeling: the Curious Case of CV Parsing

2015-06-01 · WS 2015 6 · Melanie Tosik, Carsten Lygteskov Hansen, Gerard Goossen, Mihai Rotaru
Word Embeddings

Leakage of Dataset Properties in Multi-Party Machine Learning

2020-06-12 · Wanrong Zhang, Shruti Tople, Olga Ohrimenko

Secure multi-party machine learning allows several parties to build a model on their pooled data to increase utility while not explicitly sharing data with each other. We show that such multi-party computation can cause …

AttributeBIG-bench Machine Learning

Efficient Beamforming for Mobile mmWave Networks

2019-12-23 · Sara Khosravi, Hossein S. Ghadikolaei, Marina Petrova

We design a lightweight beam-searching algorithm for mobile millimeter-wave systems. We construct and maintain a set of path skeletons, i.e., potential paths between a user and the serving base station to substantially e…