REVIEW 3 cited by
One word at a time: adversarial attacks on retrieval models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Adversarial examples, generated by applying small perturbations to input features, are widely used to fool classifiers and measure their robustness to noisy inputs. However, little work has been done to evaluate the robustness of ranking models through adversarial examples. In this work, we present a systematic approach of leveraging adversarial examples to measure the robustness of popular ranking models. We explore a simple method to generate adversarial examples that forces a ranker to incorrectly rank the documents. Using this approach, we analyze the robustness of various ranking models and the quality of perturbations generated by the adversarial attacker across two datasets. Our findings suggest that with very few token changes (1-3), the attacker can yield semantically similar perturbed documents that can fool different rankers into changing a document's score, lowering its rank by several positions.
Forward citations
Cited by 3 Pith papers
-
Search results diversification in competitive search
The paper argues, via game theory and student ranking competitions, that diversity-based search ranking reduces 'mimicking the winner' herding, but the equilibrium proof and the empirical test are both flawed.
-
Attack-in-the-Chain: Bootstrapping Large Language Models for Attacks Against Black-box Neural Ranking Models
Attack-in-the-Chain uses chain-of-thought prompting to iteratively select anchor documents and allocate word-level perturbations, boosting target documents in black-box neural ranking models on MS MARCO and TREC DL19.
-
Reproducing HotFlip for Corpus Poisoning Attacks in Dense Retrieval
A reproducibility study speeds up HotFlip corpus poisoning 16x with query centroids and shows attack transfer is poor across retrievers while query-agnostic poisoning still hits Contriever.
Discussion (0). Continue with ORCID to comment.