Bridge the Gap Between CV and NLP! A Gradient-based Textual Adversarial Attack Framework

对抗制 计算机科学 人工智能 梯度下降 水准点(测量) 机器学习 嵌入 基线(sea) 自然语言处理 人工神经网络 大地测量学 海洋学 地质学 地理
作者
Lifan Yuan,Yichi Zhang,Yangyi Chen,Wei Wei
标识
DOI:10.18653/v1/2023.findings-acl.446
摘要

Despite recent success on various tasks, deep learning techniques still perform poorly on adversarial examples with small perturbations. While optimization-based methods for adversarial attacks are well-explored in the field of computer vision, it is impractical to directly apply them in natural language processing due to the discrete nature of the text. To address the problem, we propose a unified framework to extend the existing optimization-based adversarial attack methods in the vision domain to craft textual adversarial samples. In this framework, continuously optimized perturbations are added to the embedding layer and amplified in the forward propagation process. Then the final perturbed latent representations are decoded with a masked language model head to obtain potential adversarial samples. In this paper, we instantiate our framework with an attack algorithm named Textual Projected Gradient Descent (T-PGD). We find our algorithm effective even using proxy gradient information. Therefore, we perform the more challenging transfer black-box attack and conduct comprehensive experiments to evaluate our attack algorithm with several models on three benchmark datasets. Experimental results demonstrate that our method achieves overall better performance and produces more fluent and grammatical adversarial samples compared to strong baseline methods. The code and data are available at https://github.com/Phantivia/T-PGD.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
寻道图强应助Geoer采纳,获得50
刚刚
刚刚
1秒前
zhao完成签到 ,获得积分10
1秒前
Lucia_yx发布了新的文献求助10
1秒前
jzhou88完成签到,获得积分0
1秒前
skyangar给skyangar的求助进行了留言
1秒前
andrew完成签到,获得积分10
1秒前
科研人发布了新的文献求助10
3秒前
3秒前
曾经忘幽完成签到,获得积分10
4秒前
鲸鱼姐姐完成签到 ,获得积分10
4秒前
4秒前
xing完成签到,获得积分20
4秒前
碰碰发布了新的文献求助10
5秒前
优雅同学发布了新的文献求助10
5秒前
flywo发布了新的文献求助10
5秒前
5秒前
你看完成签到 ,获得积分10
5秒前
thelime应助亦木澜采纳,获得10
6秒前
6秒前
坦率白萱完成签到,获得积分10
7秒前
科研通AI6.4应助噜噜大王采纳,获得10
7秒前
文无第一完成签到,获得积分20
7秒前
傲娇的芷烟完成签到,获得积分10
7秒前
健康快乐完成签到 ,获得积分10
7秒前
8秒前
8秒前
hsy完成签到,获得积分10
8秒前
8秒前
9秒前
科研mrxu完成签到,获得积分10
9秒前
爆米花应助王亚平采纳,获得10
9秒前
量子星尘发布了新的文献求助10
9秒前
曦曦呵呵完成签到,获得积分10
9秒前
9秒前
苏小猫完成签到,获得积分10
10秒前
11秒前
JamesPei应助flywo采纳,获得10
11秒前
oaim完成签到,获得积分10
11秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Relation between chemical structure and local anesthetic action: tertiary alkylamine derivatives of diphenylhydantoin 1000
Signals, Systems, and Signal Processing 610
Discrete-Time Signals and Systems 610
Principles of town planning : translating concepts to applications 500
Iron‐Sulfur Clusters: Biogenesis and Biochemistry 400
Healable Polymer Systems: Fundamentals, Synthesis and Applications 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6069817
求助须知:如何正确求助?哪些是违规求助? 7901659
关于积分的说明 16334711
捐赠科研通 5210799
什么是DOI,文献DOI怎么找? 2787043
邀请新用户注册赠送积分活动 1769855
关于科研通互助平台的介绍 1648020