Towards a unified framework for imperceptible textual attacks
摘要
Despite the great success of Deep Neural Networks (DNNs) in the field of natural language processing (NLP), they are increasingly facing tremendous threats from textual attacks in two kinds: adversarial attacks and backdoor attacks. Both of them are able to manipulate DNNs into producing the designated target label. By searching the optimal replacement in the massive space of possible candidates, current textual attacks deal with each input sample one at a time. However, attacking in this manner is time consuming, and the generated samples suffer from low semantic consistency and language fluency. To address this issue, we design a unified framework for targeted adversarial attacks and backdoor attacks, which employs a masked language model to produce imperceptible poisoned samples directly. We conduct extensive experiments on three benchmark datasets for three different NLP model architectures. Experimental results reveal that the proposed framework can achieve the state-of-the-art attacking performance for backdoor attacks with a substantial improvement, and a more pronounced improvements for targeted adversarial attacks, while concurrently maintaining the high linguistic quality of generated samples.