Skip to main navigation Skip to search Skip to main content

Adversarial examples for Chinese text classification

  • Yushun Xie
  • , Zhaoquan Gu*
  • , Bin Zhu
  • , Le Wang
  • , Weihong Han
  • , Lihua Yin
  • *Corresponding author for this work
  • Guangzhou University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deep neural networks (DNNs) have been widely adopted in various areas such as image recognition and natural language processing. However, many works show that DNNs for image classification are vulnerable to adversarial examples, which are generated by adding small-magnitude perturbations to the original inputs. In this paper, we show that DNNs for Chinese text classification are also vulnerable to adversarial examples. We propose a marginal attack method to generate adversarial examples that could fool the DNNs. This method adopts the Naïve Bayes principle to filter sensitive words and it only adds a small number of sensitive words at the end of the original text. The generated adversarial example could fool a variety of Chinese text classification DNNs, such that the text would be classified to incorrect category with high probability. We conduct extensive experiments to evaluate the attack performance and the results show that the success ratio of the attacks could reach almost 100% by adding only five sensitive words.

Original languageEnglish
Title of host publicationProceedings - 2020 IEEE 5th International Conference on Data Science in Cyberspace, DSC 2020
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages238-245
Number of pages8
ISBN (Electronic)9781728195582
DOIs
StatePublished - Jul 2020
Externally publishedYes
Event5th IEEE International Conference on Data Science in Cyberspace, DSC 2020 - Hong Kong, China
Duration: 27 Jul 202029 Jul 2020

Publication series

NameProceedings - 2020 IEEE 5th International Conference on Data Science in Cyberspace, DSC 2020

Conference

Conference5th IEEE International Conference on Data Science in Cyberspace, DSC 2020
Country/TerritoryChina
CityHong Kong
Period27/07/2029/07/20

Keywords

  • Adversarial Exmaple
  • Chinese text classification
  • Deep Learning
  • Marginal Attack

Fingerprint

Dive into the research topics of 'Adversarial examples for Chinese text classification'. Together they form a unique fingerprint.

Cite this