{"id":"https://openalex.org/W4292947416","doi":"https://doi.org/10.48550/arxiv.2208.10251","title":"Rethinking Textual Adversarial Defense for Pre-trained Language Models","display_name":"Rethinking Textual Adversarial Defense for Pre-trained Language Models","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4292947416","doi":"https://doi.org/10.48550/arxiv.2208.10251"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2208.10251","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2208.10251","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100449263","display_name":"Jiayi Wang","orcid":"https://orcid.org/0000-0002-7785-3381"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Jiayi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055860272","display_name":"Rongzhou Bao","orcid":"https://orcid.org/0000-0003-0108-2143"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bao, Rongzhou","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070962435","display_name":"Zhuosheng Zhang","orcid":"https://orcid.org/0000-0002-4183-3645"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Zhuosheng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5100457332","display_name":"Hai Zhao","orcid":"https://orcid.org/0000-0002-3392-2584"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhao, Hai","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":59},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9842,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9842,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.9392,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness","score":0.49572814}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9721127},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6925883},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.53640205},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.49572814},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.43180576},{"id":"https://openalex.org/C2777530160","wikidata":"https://www.wikidata.org/wiki/Q41796","display_name":"Sentence","level":2,"score":0.4229708},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.32137722},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2208.10251","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2208.10251","pdf_url":"http://arxiv.org/pdf/2208.10251","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2208.10251","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2208.10251","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.52,"display_name":"Peace, justice, and strong institutions"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4310988119","https://openalex.org/W4297672492","https://openalex.org/W4288019534","https://openalex.org/W4246396837","https://openalex.org/W3191453585","https://openalex.org/W3176240006","https://openalex.org/W3126451824","https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W1561927205"],"abstract_inverted_index":{"Although":[0],"pre-trained":[1],"language":[2],"models":[3],"(PrLMs)":[4],"have":[5],"achieved":[6],"significant":[7],"success,":[8],"recent":[9],"studies":[10],"demonstrate":[11],"that":[12,52,115,131,175,211,257],"PrLMs":[13,38,119,262],"are":[14,58],"vulnerable":[15],"to":[16,39,87,93,162,223],"adversarial":[17,21,34,56,90,99,143,165,207,216,233,249,255],"attacks.":[18],"By":[19],"generating":[20],"examples":[22,57,234,256],"with":[23,187,244],"slight":[24],"perturbations":[25],"on":[26,71,146,221],"different":[27],"levels":[28],"(sentence":[29],"/":[30,32],"word":[31],"character),":[33],"attacks":[35,110,217],"can":[36,61,136],"fool":[37],"generate":[40,94],"incorrect":[41],"predictions,":[42],"which":[43,60,113,157],"questions":[44],"the":[45,105,116,160,169,197,203,225,229,245],"robustness":[46,117],"of":[47,82,108,118,134,141,205,215],"PrLMs.":[48],"However,":[49],"we":[50,76,129,151],"find":[51,130],"most":[53],"existing":[54,109],"textual":[55,142,164,206],"unnatural,":[59],"be":[62,236],"easily":[63,237],"distinguished":[64],"by":[65],"both":[66],"human":[67],"and":[68,97,149,209,227,239,241,247,263],"machine.":[69],"Based":[70,145],"a":[72,78,85,138,153],"general":[73],"anomaly":[74,147],"detector,":[75],"propose":[77],"novel":[79],"metric":[80],"(Degree":[81],"Anomaly)":[83],"as":[84,122,124],"constraint":[86],"enable":[88],"current":[89],"attack":[91],"approaches":[92],"more":[95,220,265],"natural":[96],"imperceptible":[98],"examples.":[100,144],"Under":[101],"this":[102],"new":[103],"constraint,":[104],"success":[106],"rate":[107],"drastically":[111],"decreases,":[112],"reveals":[114],"is":[120,158,252],"not":[121],"fragile":[123],"they":[125],"claimed.":[126],"In":[127],"addition,":[128],"four":[132],"types":[133],"randomization":[135],"invalidate":[137],"large":[139],"portion":[140],"detector":[148],"randomization,":[150,230],"design":[152],"universal":[154,177],"defense":[155,166,178],"framework,":[156],"among":[159],"first":[161],"perform":[163],"without":[167],"knowing":[168],"specific":[170,189],"attack.":[171],"Empirical":[172],"results":[173],"show":[174],"our":[176],"framework":[179],"achieves":[180],"comparable":[181],"or":[182],"even":[183],"higher":[184,193],"after-attack":[185],"accuracy":[186,195],"other":[188],"defenses,":[190],"while":[191],"preserving":[192],"original":[194],"at":[196],"same":[198],"time.":[199],"Our":[200],"work":[201],"discloses":[202],"essence":[204],"attacks,":[208],"indicates":[210],"(1)":[212],"further":[213],"works":[214],"should":[218],"focus":[219],"how":[222],"overcome":[224],"detection":[226],"resist":[228],"otherwise":[231],"their":[232],"would":[235],"detected":[238],"invalidated;":[240],"(2)":[242],"compared":[243],"unnatural":[246],"perceptible":[248],"examples,":[250],"it":[251],"those":[253],"undetectable":[254],"pose":[258],"real":[259],"risks":[260],"for":[261,267],"require":[264],"attention":[266],"future":[268],"robustness-enhancing":[269],"strategies.":[270]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4292947416","counts_by_year":[],"updated_date":"2025-03-04T15:57:57.248001","created_date":"2022-08-24"}