In plain words: It checks how swapping each input character would shift the classifier's score, then flips the one that hurts most. Just a few such swaps sharply cut accuracy, and training on them makes the model sturdier against later attacks.
Abstract · HotFlip: White-Box Adversarial Examples for Text Classification
We propose an efficient method to generate white-box adversarial examples to trick a character-level neural classifier. We find that only a few manipulations are needed to greatly decrease the accuracy. Our method relies on an atomic flip operation, which swaps one token for another, based on the gradients of the one-hot input vectors. Due to efficiency of our method, we can perform adversarial training which makes the model more robust to attacks at test time. With the use of a few semantics-preserving constraints, we demonstrate that HotFlip can be adapted to attack a word-level classifier as well.
Javid Ebrahimi, Anyi Rao, Daniel Lowd, Dejing Dou
arXiv:1712.06751 · cs.CL, cs.LG · submitted Dec 19, 2017 · updated May 24, 2018
abstract · pdf · html