Skip to main navigation Skip to search Skip to main content

Attack-words Guided Sentence Generation for Textual Adversarial Attack

  • Huan Zhang
  • , Yushun Xie
  • , Ziqi Zhu
  • , Jingling Sun
  • , Chao Li
  • , Zhaoquan Gu
  • Guangzhou University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deep neural networks are vulnerable to carefully crafted adversarial examples and many adversarial attack methods have been proposed in computer vision tasks, such as image classification, object detection, etc. Generating adversarial examples for textual tasks is more challenging since the lexical correctness, grammatical correctness and semantics similarity should be maintained. In this paper, we introduce an attack-words guided sentence generation (AGSG) method to attack text classification models. We first determine words' attack ability by the ensemble strategy, then we add perturbation by inserting a short attack sentence. We conduct extensive experiments on two popular datasets IMDB and Amazon Comments against TextCNN, LSTM and RCNN models. The results show that the AGSG method greatly reduces the classification accuracy with a low word substitution rate. Specifically, the accuracy is reduced by 94.5% and 90.1% when disturbance rate is 13.3% and 25.1% for IMDB and Amazon Comments respectively. The similarity evaluation study shows that our adversarial attack method guarantees semantic similarity and grammatical correctness. Compared with two baseline adversarial attack methods, the AGSG method can generate adversarial texts that are harder for humans to perceive.

Original languageEnglish
Title of host publicationProceedings - 2021 IEEE 6th International Conference on Data Science in Cyberspace, DSC 2021
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages280-287
Number of pages8
ISBN (Electronic)9781665418157
DOIs
StatePublished - 2021
Externally publishedYes
Event6th IEEE International Conference on Data Science in Cyberspace, DSC 2021 - ShenZhen, China
Duration: 9 Oct 202111 Oct 2021

Publication series

NameProceedings - 2021 IEEE 6th International Conference on Data Science in Cyberspace, DSC 2021

Conference

Conference6th IEEE International Conference on Data Science in Cyberspace, DSC 2021
Country/TerritoryChina
CityShenZhen
Period9/10/2111/10/21

Keywords

  • Adversarial examples
  • deep learning
  • sentence generation
  • text categorization

Fingerprint

Dive into the research topics of 'Attack-words Guided Sentence Generation for Textual Adversarial Attack'. Together they form a unique fingerprint.

Cite this