Generating Natural Language Adversarial Examples on a Large Scale with Generative Models

被引:5
|
作者
Ren, Yankun [1 ]
Lin, Jianbin [1 ]
Tang, Siliang [2 ]
Zhou, Jun [1 ]
Yang, Shuang [1 ]
Qi, Yuan [1 ]
Ren, Xiang [3 ]
机构
[1] Ant Financial Serv Grp, Hangzhou, Peoples R China
[2] Zhejiang Univ, Hangzhou, Peoples R China
[3] Univ Southern Calif, Los Angeles, CA 90007 USA
关键词
D O I
10.3233/FAIA200340
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Today text classification models have been widely used. However, these classifiers are found to be easily fooled by adversarial examples. Fortunately, standard attacking methods generate adversarial texts in a pair-wise way, that is, an adversarial text can only be created from a real-world text by replacing a few words. In many applications, these texts are limited in numbers, therefore their corresponding adversarial examples are often not diverse enough and sometimes hard to read, thus can be easily detected by humans and cannot create chaos at a large scale. In this paper, we propose an end to end solution to efficiently generate adversarial texts from scratch using generative models, which are not restricted to perturbing the given texts. We call it unrestricted adversarial text generation. Specifically, we train a conditional variational autoencoder (VAE) with an additional adversarial loss to guide the generation of adversarial examples. Moreover, to improve the validity of adversarial texts, we utilize discrimators and the training framework of generative adversarial networks (GANs) to make adversarial texts consistent with real data. Experimental results on sentiment analysis demonstrate the scalability and efficiency of our method. It can attack text classification models with a higher success rate than existing methods, and provide acceptable quality for humans in the meantime.
引用
收藏
页码:2156 / 2163
页数:8
相关论文
共 50 条
  • [31] Generating Watermarked Speech Adversarial Examples
    Wang, Yumin
    Ye, Jingyu
    Wu, Hanzhou
    PROCEEDINGS OF ACM TURING AWARD CELEBRATION CONFERENCE, ACM TURC 2021, 2021, : 254 - 260
  • [32] Generating Adversarial Examples With Shadow Model
    Zhang, Rui
    Xia, Hui
    Hu, Chunqiang
    Zhang, Cheng
    Liu, Chao
    Xiao, Fu
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (09) : 6283 - 6289
  • [33] Journal policy on large language generative models
    Sessler, Daniel I.
    Turan, Alparslan
    JOURNAL OF CLINICAL ANESTHESIA, 2024, 96
  • [34] Generative Relevance Feedback with Large Language Models
    Mackie, Iain
    Chatterjee, Shubham
    Dalton, Jeffrey
    PROCEEDINGS OF THE 46TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2023, 2023, : 2026 - 2031
  • [35] Large Language Models are Not Models of Natural Language: They are Corpus Models
    Veres, Csaba
    IEEE ACCESS, 2022, 10 : 61970 - 61979
  • [36] Adversarial transformation network with adaptive perturbations for generating adversarial examples
    Zhang, Guoyin
    Da, Qingan
    Li, Sizhao
    Sun, Jianguo
    Wang, Wenshan
    Hu, Qing
    Lu, Jiashuai
    INTERNATIONAL JOURNAL OF BIO-INSPIRED COMPUTATION, 2022, 20 (02) : 94 - 103
  • [37] Generating Adversarial Examples With Distance Constrained Adversarial Imitation Networks
    Tang, Pengfei
    Wang, Wenjie
    Lou, Jian
    Xiong, Li
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (06) : 4145 - 4155
  • [38] Extending generative models of large scale networks
    Lofdahl, Corey
    Stickgold, Eli
    Skarin, Bruce
    Stewart, Ian
    6TH INTERNATIONAL CONFERENCE ON APPLIED HUMAN FACTORS AND ERGONOMICS (AHFE 2015) AND THE AFFILIATED CONFERENCES, AHFE 2015, 2015, 3 : 3868 - 3875
  • [39] Generating mobility networks with generative adversarial networks
    Mauro, Giovanni
    Luca, Massimiliano
    Longa, Antonio
    Lepri, Bruno
    Pappalardo, Luca
    EPJ DATA SCIENCE, 2022, 11 (01)
  • [40] Generating mobility networks with generative adversarial networks
    Giovanni Mauro
    Massimiliano Luca
    Antonio Longa
    Bruno Lepri
    Luca Pappalardo
    EPJ Data Science, 11