paper-with-me

홈 › Papers

Word-level Textual Adversarial Attacking as Combinatorial Optimization

2019-10-27 · ACL 2020 6 · Yuan Zang, Fanchao Qi, Chenghao Yang, Zhiyuan Liu, Meng Zhang, Qun Liu, Maosong Sun

Adversarial attacks are carried out to reveal the vulnerability of deep neural networks. Textual adversarial attacking is challenging because text is discrete and a small perturbation can bring significant change to the original input. Word-level attacking, which can be regarded as a combinatorial optimization problem, is a well-studied class of textual attack methods. However, existing word-level attack models are far from perfect, largely because unsuitable search space reduction methods and inefficient optimization algorithms are employed. In this paper, we propose a novel attack model, which incorporates the sememe-based word substitution method and particle swarm optimization-based search algorithm to solve the two problems separately. We conduct exhaustive experiments to evaluate our attack model by attacking BiLSTM and BERT on three benchmark datasets. Experimental results demonstrate that our model consistently achieves much higher attack success rates and crafts more high-quality adversarial examples as compared to baseline methods. Also, further experiments show our model has higher transferability and can bring more robustness enhancement to victim models by adversarial training. All the code and data of this paper can be obtained on https://github.com/thunlp/SememePSO-Attack.

📄 PDF Abstract BibTeX arXiv:1910.12196

Code (1)

thunlp/SememePSO-Attack 공식 구현 pytorch

Tasks

Adversarial AttackCombinatorial OptimizationNatural Language InferenceSentiment AnalysisWord Embeddings

Methods 이 논문이 사용한 방법론

Linear Layer A Linear Layer is a projection $\mathbf{XW + b}$.
Sigmoid Activation 설명 없음
Tanh Activation 설명 없음
Residual Connection 설명 없음
Attention Dropout Attention Dropout is a type of dropout used in attention-based architectures, where elements are randomly dropped out of the…
Linear Warmup With Linear Decay Linear Warmup With Linear Decay is a learning rate schedule in which we increase the learning rate linearly for $n$ updates and then linearly decay afterwards.
Weight Decay 설명 없음
Refunds@Expedia|||How do I get a full refund from Expedia? “How do I get a full refund from Expedia? How do I get a full refund from Expedia? – Call ☎️ +1-(888) 829 (0881) or +1-805-330-4056 or +1-805-330-4056 for Quick Help &…

Similar Papers 제목 키워드 기반

Cross-Entropy Attacks to Language Models via Rare Event Simulation

2025-01-21 · Mingze Ni, Yongshun Gong, Wei Liu

Black-box textual adversarial attacks are challenging due to the lack of model information and the discrete, non-differentiable nature of text. Existing methods often lack versatility for attacking different models, suff…

Document ClassificationSaliency RankingSentence

Multi-granularity Textual Adversarial Attack with Behavior Cloning

2021-09-09 · EMNLP 2021 11 · Yangyi Chen, Jin Su, Wei Wei

Recently, the textual adversarial attack models become increasingly popular due to their successful in estimating the robustness of NLP models. However, existing works have obvious deficiencies. (1) They usually consider…

Adversarial AttackSentence

Efficient Combinatorial Optimization for Word-level Adversarial Textual Attack

2021-09-06 · Shengcai Liu, Ning Lu, Cheng Chen, Ke Tang

Over the past few years, various word-level textual attack approaches have been proposed to reveal the vulnerability of deep neural networks used in natural language processing. Typically, these approaches involve an imp…

Combinatorial Optimization

Towards Improving Adversarial Training of NLP Models

2021-09-01 · Findings (EMNLP) 2021 11 · Jin Yong Yoo, Yanjun Qi

Adversarial training, a method for learning robust deep neural networks, constructs adversarial examples during training. However, recent methods for generating NLP adversarial examples involve combinatorial search and e…

Domain GeneralizationSentence

Learning to Attack: Towards Textual Adversarial Attacking in Real-world Situations

2020-09-19 · Yuan Zang, Bairu Hou, Fanchao Qi, Zhiyuan Liu 외

Adversarial attacking aims to fool deep neural networks with adversarial examples. In the field of natural language processing, various textual adversarial attack models have been proposed, varying in the accessibility t…

Adversarial AttackNatural Language InferenceSentiment Analysistext-classification+1