[2104.13733] Gradient-based Adversarial Attacks against Text Transformers
We propose the first general-purpose gradient-based attack against transformer models. Instead of searching for a single adversarial example, we search for a distribution of adversarial examples parameterized by a continuous-valued matrix, hence enabling gradient-based optimization. We empirically demonstrate that our white-box attack attains state-of-the-art attack performance on a variety of natural language tasks. Furthermore, we show that a powerful black-box transfer attack, enabled by sampling from the adversarial distribution, matches or exceeds existing methods, while only requiring hard-label outputs.
We propose the first general-purpose gradient-based attack against transformer models. Instead of searching for a single adversarial example, we search for a distribution of adversarial examples parameterized by a continuous-valued matrix, hence enabling gradient-based optimization. We empirically demonstrate that our white-box attack attains state-of-the-art attack performance on a variety of natural language tasks. Furthermore, we show that a powerful black-box transfer attack, enabled by sampling from the adversarial distribution, matches or exceeds existing methods, while only requiring ha
Explore this link on the map →related reading
- Adversarial Attacks on LLMs | Lil'Loglilianweng.github.io
- Adversarial Attacks on Aligned Language Models | Gray Swan Researchgrayswan.ai
- Transformer Explainer: LLM Transformer Model Visually Explainedpoloclub.github.io
- A Mathematical Framework for Transformer Circuitstransformer-circuits.pub
- GitHub - SoyGema/pulling_ace · GitHubgithub.com
- Transformers from Scratche2eml.school
- The Annotated Transformernlp.seas.harvard.edu
- [2307.15043] Universal and Transferable Adversarial Attacks on Aligned Language Modelsarxiv.org
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailmentarxiv.org
- [1908.07125] Universal Adversarial Triggers for Attacking and Analyzing NLParxiv.org
- The Annotated Transformernlp.seas.harvard.edu
- [2209.02128] Evaluating the Susceptibility of Pre-Trained Language Models via Handcrafted Adversarial Examplesarxiv.org