We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.LG

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo ScienceWISE logo

Computer Science > Machine Learning

Title: Improved and Efficient Text Adversarial Attacks using Target Information

Abstract: There has been recently a growing interest in studying adversarial examples on natural language models in the black-box setting. These methods attack natural language classifiers by perturbing certain important words until the classifier label is changed. In order to find these important words, these methods rank all words by importance by querying the target model word by word for each input sentence, resulting in high query inefficiency. A new interesting approach was introduced that addresses this problem through interpretable learning to learn the word ranking instead of previous expensive search. The main advantage of using this approach is that it achieves comparable attack rates to the state-of-the-art methods, yet faster and with fewer queries, where fewer queries are desirable to avoid suspicion towards the attacking agent. Nonetheless, this approach sacrificed the useful information that could be leveraged from the target classifier for that sake of query efficiency. In this paper we study the effect of leveraging the target model outputs and data on both attack rates and average number of queries, and we show that both can be improved, with a limited overhead of additional queries.
Comments: Accepted in the International Conference on Learning Representations (ICLR) workshop on Robust and Reliable Machine Learning in the Real World (RobustML)
Subjects: Machine Learning (cs.LG); Artificial Intelligence (cs.AI); Computation and Language (cs.CL); Cryptography and Security (cs.CR)
MSC classes: I.5.0, I.2.0
Cite as: arXiv:2104.13484 [cs.LG]
  (or arXiv:2104.13484v2 [cs.LG] for this version)

Submission history

From: Mahmoud Hossam [view email]
[v1] Tue, 27 Apr 2021 21:25:55 GMT (344kb,D)
[v2] Sun, 2 May 2021 08:49:09 GMT (344kb,D)

Link back to: arXiv, form interface, contact.