paper-with-me

홈 › Papers

Why Should Adversarial Perturbations be Imperceptible? Rethink the Research Paradigm in Adversarial NLP

2022-10-19 · Yangyi Chen, Hongcheng Gao, Ganqu Cui, Fanchao Qi, Longtao Huang, Zhiyuan Liu, Maosong Sun

Textual adversarial samples play important roles in multiple subfields of NLP research, including security, evaluation, explainability, and data augmentation. However, most work mixes all these roles, obscuring the problem definitions and research goals of the security role that aims to reveal the practical concerns of NLP models. In this paper, we rethink the research paradigm of textual adversarial samples in security scenarios. We discuss the deficiencies in previous work and propose our suggestions that the research on the Security-oriented adversarial NLP (SoadNLP) should: (1) evaluate their methods on security tasks to demonstrate the real-world concerns; (2) consider real-world attackers' goals, instead of developing impractical methods. To this end, we first collect, process, and release a security datasets collection Advbench. Then, we reformalize the task and adjust the emphasis on different goals in SoadNLP. Next, we propose a simple method based on heuristic rules that can easily fulfill the actual adversarial goals to simulate real-world attack methods. We conduct experiments on both the attack and the defense sides on Advbench. Experimental results show that our method has higher practical value, indicating that the research paradigm in SoadNLP may start from our new benchmark. All the code and data of Advbench can be obtained at \url{https://github.com/thunlp/Advbench}.

📄 PDF Abstract BibTeX arXiv:2210.10683

Code (2)

thunlp/advbench 공식 구현 pytorch
yang-yan-yang-yan/sop

Tasks

Data Augmentation

Similar Papers 제목 키워드 기반

PGD-Imp: Rethinking and Unleashing Potential of Classic PGD with Dual Strategies for Imperceptible Adversarial Attacks

2024-12-15 · Jin Li, Zitong Yu, Ziqiang He, Z. Jane Wang 외

Imperceptible adversarial attacks have recently attracted increasing research interests. Existing methods typically incorporate external modules or loss terms other than a simple $l_p$-norm into the attack process to ach…

Rethinking Impersonation and Dodging Attacks on Face Recognition Systems

2024-01-17 · Fengfan Zhou, Qianyu Zhou, Bangjie Yin, Hui Zheng 외

Face Recognition (FR) systems can be easily deceived by adversarial examples that manipulate benign face images through imperceptible perturbations. Adversarial attacks on FR encompass two types: impersonation (targeted)…

Adversarial AttackFace Recognition

Rethinking Gradient-based Adversarial Attacks on Point Cloud Classification

2025-05-28 · Jun Chen, Xinke Li, Mingyue Xu, Tianrui Li 외

Gradient-based adversarial attacks have become a dominant approach for evaluating the robustness of point cloud classification models. However, existing methods often rely on uniform update rules that fail to consider th…

3D Point Cloud ClassificationPoint Cloud Classification

Attacking Perceptual Similarity Metrics

2023-05-15 · Abhijay Ghildyal, Feng Liu

Perceptual similarity metrics have progressively become more correlated with human judgments on perceptual similarity; however, despite recent advances, the addition of an imperceptible distortion can still compromise th…

Adversarial AttackExperimental Design

Is current research on adversarial robustness addressing the right problem?

2022-07-31 · Ali Borji

Short answer: Yes, Long answer: No! Indeed, research on adversarial robustness has led to invaluable insights helping us understand and explore different aspects of the problem. Many attacks and defenses have been propos…

Adversarial Robustness