We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CL

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Computation and Language

Title: Certified Robustness to Text Adversarial Attacks by Randomized [MASK]

Abstract: Recently, few certified defense methods have been developed to provably guarantee the robustness of a text classifier to adversarial synonym substitutions. However, all existing certified defense methods assume that the defenders are informed of how the adversaries generate synonyms, which is not a realistic scenario. In this paper, we propose a certifiably robust defense method by randomly masking a certain proportion of the words in an input text, in which the above unrealistic assumption is no longer necessary. The proposed method can defend against not only word substitution-based attacks, but also character-level perturbations. We can certify the classifications of over 50% texts to be robust to any perturbation of 5 words on AGNEWS, and 2 words on SST2 dataset. The experimental results show that our randomized smoothing method significantly outperforms recently proposed defense methods across multiple datasets.
Comments: Under Review for TOPS
Subjects: Computation and Language (cs.CL)
Cite as: arXiv:2105.03743 [cs.CL]
  (or arXiv:2105.03743v3 [cs.CL] for this version)

Submission history

From: Jiehang Zeng [view email]
[v1] Sat, 8 May 2021 16:59:10 GMT (151kb,D)
[v2] Mon, 14 Jun 2021 08:30:40 GMT (151kb,D)
[v3] Sun, 25 Jul 2021 17:28:12 GMT (179kb,D)

Link back to: arXiv, form interface, contact.