Generating Adversarial Texts for Recurrent Neural Networks

被引:1
|
作者
Liu, Chang [1 ]
Lin, Wang [2 ]
Yang, Zhengfeng [1 ]
机构
[1] East China Normal Univ, Software Engn Inst, Shanghai, Peoples R China
[2] Zhejiang Sci Tech Univ, Sch Informat Sci & Technol, Hangzhou, Peoples R China
关键词
Adversarial text; Recurrent neural network; PGD; C&W;
D O I
10.1007/978-3-030-61609-0_4
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial examples have received increasing attention recently due to their significant values in evaluating and improving the robustness of deep neural networks. Existing adversarial attack algorithms have achieved good result for most images. However, those algorithms cannot be directly applied to texts as the text data is discrete in nature. In this paper, we extend two state-of-the-art attack algorithms, PGD and C&W, to craft adversarial text examples for RNN-based models. For Extend-PGD attack, it identifies the words that are important for classification by computing the Jacobian matrix of the classifier, to effectively generate adversarial text examples. For Extend-C&W attack, it utilizes L-1 regularization to minimize the alteration of the original input text. We conduct comparison experiments on two recurrent neural networks trained for classifying texts in two real-world datasets. Experimental results show that our Extend-PGD and Extend-C&W attack algorithms have advantages of attack success rate and semantics-preserving ability, respectively.
引用
收藏
页码:39 / 51
页数:13
相关论文
共 50 条
  • [1] Adversarial Dropout for Recurrent Neural Networks
    Park, Sungrae
    Song, Kyungwoo
    Ji, Mingi
    Lee, Wonsung
    Moon, Il-Chul
    [J]. THIRTY-THIRD AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FIRST INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE / NINTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2019, : 4699 - 4706
  • [2] SentiGAN: Generating Sentimental Texts via Mixture Adversarial Networks
    Wang, Ke
    Wan, Xiaojun
    [J]. PROCEEDINGS OF THE TWENTY-SEVENTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2018, : 4446 - 4452
  • [3] Wasserstein Generative Recurrent Adversarial Networks for Image Generating
    Zhang, Chunping
    Feng, Yong
    Qiang, Baohua
    Shang, Jiaxing
    [J]. 2018 24TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2018, : 242 - 247
  • [4] Generating watermarked adversarial texts
    Li, Mingjie
    Wu, Hanzhou
    Wang, Zichi
    Zhang, Xinpeng
    [J]. JOURNAL OF ELECTRONIC IMAGING, 2023, 32 (02)
  • [5] Dynamically Computing Adversarial Perturbations for Recurrent Neural Networks
    Deka, Shankar A.
    Stipanovic, Dusan M.
    Tomlin, Claire J.
    [J]. IEEE TRANSACTIONS ON CONTROL SYSTEMS TECHNOLOGY, 2022, 30 (06) : 2615 - 2629
  • [6] Recurrent Generative Adversarial Neural Networks for Compressive Imaging
    Mardani, Morteza
    Gong, Enhao
    Cheng, Joseph Y.
    Pauly, John
    Xing, Lei
    [J]. 2017 IEEE 7TH INTERNATIONAL WORKSHOP ON COMPUTATIONAL ADVANCES IN MULTI-SENSOR ADAPTIVE PROCESSING (CAMSAP), 2017,
  • [7] Audio Adversarial Examples Generation with Recurrent Neural Networks
    Chang, Kuei-Huan
    Huang, Po-Hao
    Yu, Honggang
    Jin, Yier
    Wang, Ting-Chi
    [J]. 2020 25TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE, ASP-DAC 2020, 2020, : 488 - 493
  • [8] Crafting Adversarial Input Sequences for Recurrent Neural Networks
    Papernot, Nicolas
    McDaniel, Patrick
    Swami, Ananthram
    Harang, Richard
    [J]. MILCOM 2016 - 2016 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2016, : 49 - 54
  • [9] A Method Generating Adversarial Mark Based on Convolutional Neural Networks
    Deng, Zhengjie
    Liu, Meijun
    Li, Xiyan
    [J]. PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND NETWORKS, VOL II, CENET 2023, 2024, 1126 : 447 - 456
  • [10] UnboundAttack: Generating Unbounded Adversarial Attacks to Graph Neural Networks
    Ennadir, Sofiane
    Alkhatib, Amr
    Nikolentzos, Giannis
    Vazirgiannis, Michalis
    Bostrom, Henrik
    [J]. COMPLEX NETWORKS & THEIR APPLICATIONS XII, VOL 1, COMPLEX NETWORKS 2023, 2024, 1141 : 100 - 111