|
Zapiski Nauchnykh Seminarov POMI, 2023, Volume 530, Pages 80–95
(Mi znsl7434)
|
|
|
|
Adversarial attacks on language models: WordPiece filtration and ChatGPT synonyms
T. Ter-Hovhannisyan, H. Aleksanyan, K. Avetisyan Russian-Armenian University, ISP RAS, Yerevan, Armenia
Abstract:
Adversarial attacks on text have gained significant attention in recent years due to their potential to undermine the reliability of NLP models. We present novel black-box character- and word-level adversarial example generation approaches applicable to BERT-based models. The character-level approach is based on the idea of adding natural typos into a word according to its WordPiece tokenization. As for word-level approaches, we present three techniques that make use of synonymous substitute words created by ChatGPT and post-corrected to be in the appropriate grammatical form for the given context. Additionally, we try to minimize the perturbation rate taking into account the damage that each perturbation does to the model. By combining character-level approaches, word-level approaches, and the perturbation rate minimization technique, we achieve a state of the art attack rate. Our best approach works 30-65% faster than the previously best method, Tampers, and has a comparable perturbation rate. At the same time, proposed perturbations retain the semantic similarity between the original and adversarial examples and achieve a relatively low value of Levenshtein distance.
Key words and phrases:
adversarial attacks, character-level attacks, word-level attacks, ChatGPT synonyms, WordPiece.
Received: 06.09.2023
Citation:
T. Ter-Hovhannisyan, H. Aleksanyan, K. Avetisyan, “Adversarial attacks on language models: WordPiece filtration and ChatGPT synonyms”, Investigations on applied mathematics and informatics. Part II–2, Zap. Nauchn. Sem. POMI, 530, POMI, St. Petersburg, 2023, 80–95
Linking options:
https://www.mathnet.ru/eng/znsl7434 https://www.mathnet.ru/eng/znsl/v530/p80
|
Statistics & downloads: |
Abstract page: | 112 | Full-text PDF : | 53 | References: | 20 |
|