Pith. sign in

REVIEW 5 cited by

Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1907.11932 v6 pith:U2ZLWHGV submitted 2019-07-27 cs.CL cs.AIcs.LG

classification cs.CLcs.AIcs.LG
keywords textadversarialmodelsexamplesnaturalbaselinebertclassification
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Machine learning algorithms are often vulnerable to adversarial examples that have imperceptible alterations from the original counterparts but can fool the state-of-the-art models. It is helpful to evaluate or even improve the robustness of these models by exposing the maliciously crafted adversarial examples. In this paper, we present TextFooler, a simple but strong baseline to generate natural adversarial text. By applying it to two fundamental natural language tasks, text classification and textual entailment, we successfully attacked three target models, including the powerful pre-trained BERT, and the widely used convolutional and recurrent neural networks. We demonstrate the advantages of this framework in three ways: (1) effective---it outperforms state-of-the-art attacks in terms of success rate and perturbation rate, (2) utility-preserving---it preserves semantic content and grammaticality, and remains correctly classified by humans, and (3) efficient---it generates adversarial text with computational complexity linear to the text length. *The code, pre-trained target models, and test examples are available at https://github.com/jind11/TextFooler.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Beyond Weaponization: NLP Security for Medium and Lower-Resourced Languages in Their Own Right

    cs.CL 2025-07 conditional novelty 6.0 of 10

    An empirical study showing that smaller monolingual language models are more vulnerable to adversarial attacks than larger multilingual models across 70 languages, though multilinguality alone does not guarantee security.

  2. What You Read Isn't What You Hear: Linguistic Sensitivity in Deepfake Speech Detection

    cs.LG 2025-05 conditional novelty 6.0 of 10

    Small semantic-preserving changes to transcripts, passed through text-to-speech, significantly reduce the accuracy of both open-source and commercial audio anti-spoofing detectors.

  3. Confidence Elicitation: A New Attack Vector for Large Language Models

    cs.LG 2025-02 conditional novelty 6.0 of 10

    Confidence elicitation, asking a model to verbalize its uncertainty, can be used as a soft-label signal to craft stronger black-box word-substitution attacks on LLMs.

  4. Talking Like a Phisher: LLM-Based Attacks on Voice Phishing Classifiers

    cs.CR 2025-07 reject novelty 5.0 of 10

    LLM-rewritten vishing transcripts lower the accuracy of TF-IDF-based ML classifiers trained on the KorCCViD Korean voice-phishing dataset, though the reported accuracy drops are overstated by inconsistent evaluation sets.

  5. The Science of Evaluating Foundation Models

    cs.CL 2025-02 conditional novelty 3.0 of 10

    A survey-and-checklist proposal that organizes LLM evaluation into an ABCD framework (Algorithm, Big Data, Computation, Domain Expertise) for context-aware, documented assessment.

Pith tools