Return
AdvExpander: Generating Natural Language Adversarial Examples by Expanding Text
DOI:10.1109/TASLP.2021.3129339.png)
Abstract
En 中文
Adversarial examples are vital to expose vulnerability of machine learning models. Despite the success of the most popular word-level substitution-based attacks which substitute some words in the original examples, only substitution is insufficient to uncover all robustness issues of models. In this paper, we focus on perturbations beyond word-level substitution, and present AdvExpander, a method that crafts new adversarial examples by expanding text. We first utilize linguistic rules to determine which constituents to expand and what types of modifiers to expand with. We then expand each constituent by inserting an adversarial modifier searched from a pre-trained CVAE-based generative model. To ensure that our adversarial examples are label-preserving for text matching, we also constrain the modifications with a heuristic rule. Experiments on three classification tasks verify the effectiveness of AdvExpander and the validity of our adversarial examples. AdvExpander is significantly more effective than sentence-level attack baselines and is complementary to previous word substitution-based attacks, thus promising to reveal new robustness issues.
Keywords:
Bibliographies
Uniform resource locators
Standards
Databases
Speech processing
Sorting
Patents
Robustness
textual adversarial examples
text classification
text matching
Journal
I
IF:
5.1
Papers:
2.6K
Citations:
1.1W

