Vol.3, No.2, 2021, pp.45-53, doi:10.32604/jai.2021.016305
A Generation Method of Letter-Level Adversarial Samples
  • Huixuan Xu1, Chunlai Du1, Yanhui Guo2,*, Zhijian Cui1, Haibo Bai1
1 School of Information Science and Technology, North China University of Technology, Beijing, 100144, China
2 Department of Computer Science, University of Illinois Springfield, Springfield, USA
* Corresponding Author: Yanhui Guo. Email:
Received 29 December 2020; Accepted 22 March 2021; Issue published 08 May 2021
In recent years, with the rapid development of natural language processing, the security issues related to it have attracted more and more attention. Character perturbation is a common security problem. It can try to completely modify the input classification judgment of the target program without people’s attention by adding, deleting, or replacing several characters, which can reduce the effectiveness of the classifier. Although the current research has provided various methods of perturbation attacks on characters, the success rate of some methods is still not ideal. This paper mainly studies the sample generation of optimal perturbation characters and proposes a characterlevel text adversarial sample generation method. The goal is to use this method to achieve the best effect on character perturbation. After sentiment classification experiments, this model has a higher perturbation success rate on the IMDB dataset, which proves the effectiveness and rationality of this method for text perturbation and provides a reference for future research work.
Perturbation attack; sentiment analysis; adversarial examples
Cite This Article
. , "A generation method of letter-level adversarial samples," Journal on Artificial Intelligence, vol. 3, no.2, pp. 45–53, 2021.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.