Pith. sign in

REVIEW 1 cited by

Fast Adversarial Training against Textual Adversarial Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2401.12461 v1 pith:FXLCELF4 submitted 2024-01-23 cs.CL cs.AI

classification cs.CLcs.AI
keywords adversarialtrainingperturbationrobustnesssingle-stepascentattacksdefense
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Many adversarial defense methods have been proposed to enhance the adversarial robustness of natural language processing models. However, most of them introduce additional pre-set linguistic knowledge and assume that the synonym candidates used by attackers are accessible, which is an ideal assumption. We delve into adversarial training in the embedding space and propose a Fast Adversarial Training (FAT) method to improve the model robustness in the synonym-unaware scenario from the perspective of single-step perturbation generation and perturbation initialization. Based on the observation that the adversarial perturbations crafted by single-step and multi-step gradient ascent are similar, FAT uses single-step gradient ascent to craft adversarial examples in the embedding space to expedite the training process. Based on the observation that the perturbations generated on the identical training sample in successive epochs are similar, FAT fully utilizes historical information when initializing the perturbation. Extensive experiments demonstrate that FAT significantly boosts the robustness of BERT models in the synonym-unaware scenario, and outperforms the defense baselines under various attacks with character-level and word-level modifications.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Defensive Dual Masking for Robust Adversarial Defense

    cs.CL 2024-12 conditional novelty 3.0 of 10

    Defensive Dual Masking inserts and replaces tokens with [MASK] at training and inference, reporting higher adversarial accuracy than prior defenses on AGNews and MR.

Pith tools