about
Code-Mixing on Sesame Street: Dawn of the Adversarial Polyglots (arxiv.org)
2 points by StatsAreFun 24 days ago | hide | past | pdf | discuss on HN

In plain words: They build two ways to scramble a sentence by swapping in words or phrases from another language, using dictionary lookups and translations to keep the meaning, to test multilingual text-understanding models. The phrase-level trick fooled the strongest tested model 89.75% of the time, cutting its accuracy from 79.85 to 8.18.

Abstract

Multilingual models have demonstrated impressive cross-lingual transfer performance. However, test sets like XNLI are monolingual at the example level. In multilingual communities, it is common for polyglots to code-mix when conversing with each other. Inspired by this phenomenon, we present two strong black-box adversarial attacks (one word-level, one phrase-level) for multilingual models that push their ability to handle code-mixed sentences to the limit. The former uses bilingual dictionaries to propose perturbations and translations of the clean example for sense disambiguation. The latter directly aligns the clean example with its translations before extracting phrases as perturbations. Our phrase-level attack has a success rate of 89.75% against XLM-R-large, bringing its average accuracy of 79.85 down to 8.18 on XNLI. Finally, we propose an efficient adversarial training scheme that trains in the same number of steps as the original model and show that it improves model accuracy.

Samson Tan, Shafiq Joty
arXiv:2103.09593 · cs.CL, cs.AI, cs.CY, cs.LG, cs.NE · submitted Mar 17, 2021 · updated Jun 5, 2021
abstract · pdf · html · To be presented at NAACL-HLT 2021. Abstract also published in the Rising Stars Track of the Workshop on Computational Approaches to Linguistic Code-Switching (CALCS 2021)

add comment on HN