对文本分类模型的强烈隐蔽的对抗性攻击,查询有限
Yao Cheng1, Senlin Luo1, Yunwei Wan1
1School of Information and Electronics, Beijing Institute of Technology, Beijing 100081, PR China.
概括
这项研究引入了一种针对文本分类模型的新型对抗性攻击,增强了隐形性并减少了对长文本的查询需求. 新方法实现了高攻击成功率,同时保持了样本完整性.
科学领域:
- 自然语言处理自然语言处理.
- 机器学习安全 机器学习安全
背景情况:
- 对文本分类模型的对抗性攻击难以生成有效的样本,特别是对于长文本,由于高查询要求和语义不一致性.
- 现有的方法通常依赖于信任矢量差异或基于词典的生成,导致效率低下和攻击成功率低.
研究的目的:
- 提出对文本分类模型 (AdATCM) 的并行和高度隐蔽的对抗性攻击,克服现有方法的局限性.
- 改进产生语义一致和语法正确的对抗样本,提高攻击成功率.
主要方法:
- AdATCM采用攻击和生成的双重任务方法,利用上下文信息来确定分心选择的单词重要性,而无需查询目标模型.
- 一个整合KL分歧损失,交叉损失和对抗损失的目标函数用于训练攻击模型.
- 该方法产生与原始样本分布一致的对抗样本.
主要成果:
- 拟议的AdATCM在对文字分类模型的对抗性攻击中表现出高的成功率.
- 该方法显著减少了所需的查询数量,特别是在长文本中,提高了效率.
- 实验结果证实了拟议的攻击策略的强大隐蔽和有效性.
结论:
- 在黑子场景中,AdATCM为对抗性攻击提供了有效和隐蔽的方法,解决了文本分类中的关键挑战.
- 这种方法比现有的技术有了显著的改进,特别是在资源有限的环境中,查询有限,文本输入长.
相关概念视频
Aggregates Classification
303
Aggregate classification is generally based on its size, petrographic characteristics, weight, and source. Size classification ranges from coarse to fine aggregates, defined by the size of the particles. Coarse aggregates are particles that do not pass through ASTM sieve No. 4, and aggregates that pass through the sieve are fine aggregates.
Petrographic classification groups aggregates based on common mineralogical characteristics. Some of the common mineral groups found in aggregates are...
Petrographic classification groups aggregates based on common mineralogical characteristics. Some of the common mineral groups found in aggregates are...
303
Classification of Leukocytes
1.7K
Leukocytes are classified into two groups based on the presence or absence of cytoplasmic granules. Granular leukocytes, which contain granules, belong to the myeloid lineage and are divided into three subtypes: neutrophils, eosinophils, and basophils. These cells are roughly spherical and characterized by the granules in their cytoplasm.
Neutrophils are the most abundant type of granular leukocytes, comprising 50-70% of all leukocytes. They feature small, evenly distributed granules and a...
Neutrophils are the most abundant type of granular leukocytes, comprising 50-70% of all leukocytes. They feature small, evenly distributed granules and a...
1.7K
Classification of Systems-II
134
Continuous-time systems have continuous input and output signals, with time measured continuously. These systems are generally defined by differential or algebraic equations. For instance, in an RC circuit, the relationship between input and output voltage is expressed through a differential equation derived from Ohm's law and the capacitor relation,
134
Classification of Signals
401
In signal processing, signals are classified based on various characteristics: continuous-time versus discrete-time, periodic versus aperiodic, analog versus digital, and causal versus noncausal. Each category highlights distinct properties crucial for understanding and manipulating signals.
A continuous-time signal holds a value at every instant in time, representing information seamlessly. In contrast, a discrete-time signal holds values only at specific moments, often denoted as x(n), where...
A continuous-time signal holds a value at every instant in time, representing information seamlessly. In contrast, a discrete-time signal holds values only at specific moments, often denoted as x(n), where...
401
Classification of Systems-I
169
Linearity is a system property characterized by a direct input-output relationship, combining homogeneity and additivity.
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
Homogeneity dictates that if an input x(t) is multiplied by a constant c, the output y(t) is multiplied by the same constant. Mathematically, this is expressed as:
169
How Data are Classified: Categorical Data
31.6K
A variable, usually notated by capital letters such as X and Y, is a characteristic or measurement that can be determined for each member of a population. Data are the actual values of variables. They may be numbers, or they may be words. Datum is a single value.
Data are classified based on whether they are measurable or not. Categorical data cannot be measured; instead, it can be divided into categories. For example, if Y denotes a person's party affiliation, some examples of Y include...
Data are classified based on whether they are measurable or not. Categorical data cannot be measured; instead, it can be divided into categories. For example, if Y denotes a person's party affiliation, some examples of Y include...
31.6K


