Related Experiment Video
Updated: Jun 5, 2025

Augmenting Large Language Models via Vector Embeddings to Improve Domain-Specific Responsiveness
Published on: December 6, 2024
Strongly concealed adversarial attack against text classification models with limited queries
Yao Cheng1, Senlin Luo1, Yunwei Wan1
1School of Information and Electronics, Beijing Institute of Technology, Beijing 100081, PR China.
This study introduces a novel adversarial attack against text classification models, enhancing stealth and reducing query needs for long texts. The new method achieves high attack success rates while maintaining sample integrity.
Area of Science:
- Natural Language Processing
- Machine Learning Security
Background:
- Adversarial attacks on text classification models struggle with generating valid samples, especially for long texts, due to high query requirements and semantic inconsistencies.
- Existing methods often rely on confidence vector differences or thesaurus-based generation, leading to inefficiency and low attack success rates.
Purpose of the Study:
- To propose a parallel and highly stealthy adversarial attack against text classification models (AdATCM) that overcomes limitations of existing methods.
- To improve the generation of adversarial samples that are semantically consistent and grammatically correct, increasing attack success rates.
Main Methods:
- AdATCM employs a dual-task approach for attack and generation, utilizing contextual information to determine word importance for distractor selection without querying the target model.
- An objective function integrating KL divergence loss, cross-entropy loss, and adversarial loss is used to train the attack model.
- The method generates adversarial samples that align with the original sample distribution.
Main Results:
- The proposed AdATCM demonstrates a high success rate in adversarial attacks against text classification models.
- The method significantly reduces the number of queries required, particularly for long texts, enhancing efficiency.
- Experimental results confirm the strong concealment and effectiveness of the proposed attack strategy.
Conclusions:
- The AdATCM provides an effective and stealthy approach for adversarial attacks in black-box scenarios, addressing key challenges in text classification.
- This method offers a significant improvement over existing techniques, especially in resource-constrained environments with limited queries and long text inputs.
Related Concept Videos
Aggregates Classification
Petrographic classification groups aggregates based on common mineralogical characteristics. Some of the common mineral groups found in aggregates are...
Classification of Leukocytes
Neutrophils are the most abundant type of granular leukocytes, comprising 50-70% of all leukocytes. They feature small, evenly distributed granules and a...
Classification of Systems-II
Classification of Signals
A continuous-time signal holds a value at every instant in time, representing information seamlessly. In contrast, a discrete-time signal holds values only at specific moments, often denoted as x(n), where...
Classification of Systems-I
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
How Data are Classified: Categorical Data
Data are classified based on whether they are measurable or not. Categorical data cannot be measured; instead, it can be divided into categories. For example, if Y denotes a person's party affiliation, some examples of Y include...

