Generating Textual Adversaries with Minimal Perturbation

Generating Textual Adversaries with Minimal Perturbation
复制标题

DOI:
10.48550/arxiv.2211.06571
复制
发表时间:
2022-11
期刊:
--
影响因子:
--
通讯作者:
Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan
Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan
中科院分区:
其他
文献类型:
--
作者:
Xingyi Zhao;Lu Zhang;Depeng Xu;Shuhan Yuan

文献摘要

相似文献

在最近的研究中,已经提出了许多针对文本数据的词级对抗攻击方法。然而,由于大量的搜索空间组成的候选词的组合,现有的方法面临的问题,保持文本的语义时,制作对抗对手。在本文中,我们开发了一种新的攻击策略,以找到与原始文本具有高相似性的敌对文本,同时引入最小的扰动。其理论基础是,我们期望具有小扰动的对抗文本能够更好地保留原始文本的语义。实验结果表明,与现有的攻击方法相比,我们的方法在四个基准数据集上获得了更高的成功率和更低的扰动率。
Many word-level adversarial attack approaches for textual data have been proposed in recent studies. However, due to the massive search space consisting of combinations of candidate words, the existing approaches face the problem of preserving the semantics of texts when crafting adversarial counterparts. In this paper, we develop a novel attack strategy to find adversarial texts with high similarity to the original texts while introducing minimal perturbation. The rationale is that we expect the adversarial texts with small perturbation can better preserve the semantic meaning of original texts. Experiments show that, compared with state-of-the-art attack approaches, our approach achieves higher success rates and lower perturbation rates in four benchmark datasets.