Yifan Hu, Dongwon Lee, Jooyoung Lee, Thai Le, Kevin Yen
We lifted 1 functions out of this paper's own repositories and ran 1 of them in a sandbox. "Ran" means the function executed on a synthesized input and returned a value. It is not a reproduction of the paper's results.
| Repository | Role | Ran |
|---|---|---|
| lethaiq/perturbations-in-the-wild | canonical | 1 of 1 |
| Function | Status | Where it lives |
|---|---|---|
| matchcodex | Ran | lethaiq/perturbations-in-the-wild/anthro_lib.py code served (permissive licence) · get_code("def386829cf6eefd") |
Some links come from the archived Papers with Code dataset (CC BY-SA 4.0): attribution and licence.
We proposes a novel algorithm, ANTHRO, that inductively extracts over 600K human-written text perturbations in the wild and leverages them for realistic adversarial attack. Unlike existing character-based attacks which often deductively hypothesize a set of manipulation strategies, our work is grounded on actual observations from real-world texts. We find that adversarial texts generated by AN-THRO achieve the best trade-off between (1) attack success rate, (2) semantic preservation of the original text, and (3) stealthiness-i.e. indistinguishable from human writings hence harder to be flagged as suspicious. Specifically, our attacks accomplished around 83% and 91% attack success rates on BERT and RoBERTa, respectively. Moreover, it outperformed the TextBugger baseline with an increase of 50% and 40% in terms of semantic preservation and stealthiness when evaluated by both layperson and professional human workers. ANTHRO can further enhance a BERT classifier's performance in understanding different variations of human-written toxic texts via adversarial training when compared to the Perspective API. Source code will be published at github.com/lethaiq/ perturbations-in-the-wild.
The same record, over MCP at https://syntology.ai/mcp:
get_harvested_code_for_paper("2203.10346")
get_code_for_paper("2203.10346")
have("2203.10346")
Connect an agent — have() is free.