arrow
Return

SHAPAttack: Shapley-Guided Multigranularity Adversarial Attack Against Text Transformers

delete2024-05-01
delete0
PRE
AI
J
Jiahui Shi *
李林静 (Linjing Li)
D
Daniel Zeng
DOI:10.1109/MIS.2024.3379377delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Despite the great success of text transformers, recent studies have revealed their vulnerability to textual adversarial attacks. Existing attack methods are limited to a single granularity and often suffer from a low attack success rate and a high query cost. To mitigate these issues, we propose a Shapley-guided multigranularity adversarial attack (SHAPAttack) that generates adversarial examples (AEs). SHAPAttack expands the perturbation space by combining granularities at both the word and phrase levels, which enhances the diversity of the generated AEs. To improve attack efficiency and reduce the query cost, SHAPAttack adopts a query-free constituent importance ranking method guided by the Shapley value to measure the importance of each constituent. We conduct extensive experiments on three benchmark datasets across three text transformers. The experimental results demonstrate that SHAPAttack outperforms strong baselines in terms of both attack success rate and model queries, indicating the effectiveness and efficiency of the proposed method.
Keywords:
Perturbation methods
Transformers
Intelligent systems
Security
Task analysis
Games
Text categorization
Text analysis
Query processing
Benchmark testing
Adversarial machine learning
Ranking (statistics)

Journal

IEEE Intelligent Systems cover
IEEE Intelligent Systems
IF:
6.1
Papers:
1.6K
Citations:
4.5K

Organization

C
chinese academy of sciences
Scholars:
56.5W
Papers: 44.9W
Citations: 704