arrow
Return

Parentheses insertion based sentence-level text adversarial attack

delete2025-02-08
delete1
PRE
AI
李昂 cover
李昂 (Ang Li)
X
Xinghao Yang
刘宝弟 (Baodi Liu)
陈鸿龙 (Honglong Chen)
陶大鹏 cover
陶大鹏 (Dapeng Tao)
DOI:10.1007/s00530-025-01678-9delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In modern multimedia systems, adversarial text attack is a vital way to expose the vulnerability of deep neural networks and improve their robustness. However, existing methods have some limitations. For example, character-level insertion attacks cause misspelling errors and word-level attacks tend to make limited lexical variations. Although sentence-level attacks can greatly enrich the variety of sentences, they are less effective towards fooling victim models and sometimes lead to the wrong representation. In this paper, we propose the Parentheses Insertion Sentence-level Text Adversarial Attack (PI) algorithm that crafts adversarial texts by filling frequently used parentheses. Specifically, we collect a parentheses set (Pset\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$P_{set}$$\end{document}) at the beginning where all the parentheses are meaningless to ensure the semantics of the sentence remain unchanged after the insertion. Then we utilize the beam search strategy to merge the selected parentheses in the appropriate text positions to improve the attack success rate (ASR). To evaluate the effectiveness of PI method, we conduct extensive experiments by attacking several popular models. Experimental results show that PI enhances the ASR performance compared to word-level and sentence-level baselines while preserving high semantic similarity and incurring minimal perturbation costs. Additionally, PI helps enhance the robustness of modern NLP models by adversarial training.
Keywords:
Natural language processing (NLP)
Adversarial text attack
Robustness
Deep neural networks

Journal

Multimedia Systems cover
Multimedia Systems
IF:
3.1
Papers:
2.7K
Citations:
2.7K

Organization

Y
Yunnan University
Scholars:
1.6W
Papers: 9.9K
Citations: 13
C
china university of petroleum
Scholars:
4.1W
Papers: 2.7W
Citations: 30