Abstract
In masked language model (MLM) based attacks, candidate adversarial examples are flexibly generated according to the context, but how to balance imperceptibility and success rate of attacks remains a challenge. To pursue imperceptibility, external semantic constraints are imposed on candidate word generation, whereby the search space is restricted and the success rate of attacks drops. To address this issue, a semantically improved adversarial attack denoted by SAM-CP is proposed by generating high-quality candidate words satisfying the semantic constraints. In particular, linguistic constraints are adopted so that high-quality semantic candidates can be generated as fine-tuning labels instead of manual annotation. Extensive experimental results on three open-source datasets demonstrate that SAM-CP significantly improves the semantic consistency of generated adversarial samples by adopting different MLMs, respectively. Without compromising text quality, the ability to use SAM-CP to deceive state-of-the-art text classifiers is evaluated. Visit https://github.com/HugoTianX/SAM-CP for details and codes.
| Original language | English |
|---|---|
| Title of host publication | Proceedings - 2025 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2025 |
| Editors | Marcello Cinque, Domenico Cotroneo, Luigi De Simone, Matthias Eckhart, Patrick P. C. Lee, Saman Zonouz |
| Publisher | IEEE |
| Pages | 171-182 |
| Number of pages | 12 |
| ISBN (Electronic) | 9798331512019 |
| ISBN (Print) | 9798331512026 |
| DOIs | |
| Publication status | Published - 23 Jun 2025 |
| Event | The 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2025 - Naples, Italy Duration: 23 Jun 2025 → 26 Jun 2025 https://dsn2025.github.io/cpaccepted.html |
Publication series
| Name | International Conference on Dependable Systems and Networks (DSN) |
|---|
Conference
| Conference | The 55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2025 |
|---|---|
| Abbreviated title | DSN 2025 |
| Country/Territory | Italy |
| City | Naples |
| Period | 23/06/25 → 26/06/25 |
| Internet address |
User-Defined Keywords
- Adversarial example
- context preservation
- masked language model
- semantic constraint
- text quality