[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125061-en":3,"doc-seo-125061-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125061,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Attacking neural machine translations via hybrid attention learning","Deep-learning NLP systems face adversarial vulnerabilities, yet neural machine translation (NMT) attacks and robustness have received limited study. This work addresses the gap by targeting word-level adversarial examples, where existing methods struggle to balance attack success with text perturbation concealment. A novel Hybrid Attentive Attack locates language-specific, sequence-focused vulnerable words and applies semantic-aware substitutions using a pretrained Mask Language Model. Experiments on three strong translation models show the highest attacking performance among compared strategies with few perturbed words.","Attacking neural machine translations via hybrid attention learning  \nMingze Ni1 · Ce Wang2 · Tianqing Zhu1 · Shui Yu1 · Wei Liu1  \nReceived: 6 April 2022 / Revised: 28 July 2022 / Accepted: 13 September 2022 /  \nPublished online: 20 October 2022 © The Author(s) 2022  \nAbstract  \nDeep-learning based natural language processing (NLP) models are proven vulnerable to adversarial attacks. However, there is currently insufficient research that studies attacks to neural machine translations (NMTs) and examines the robustness of deep-learning based NMTs. In this paper, we aim to fill this critical research gap. When generating word-level adversarial examples in NLP attacks, there is a conventional trade-off in existing methods between the attacking performance and the amount of perturbations. Although some literature has studied such a trade-off and successfully generated adversarial examples with a reasonable amount of perturbations, it is still challenging to generate highly successful translation attacks while concealing the changes to the texts. To this end, we propose a novel Hybrid Attentive Attack method to locate language-specific and sequence-focused words, and make semantic-aware substitutions to attack NMTs. We evaluate the effectiveness of our attack strategy by attacking three high-performing translation models. The experimental results show that our method achieves the highest attacking performance compared with other existing attacking strategies.  \nKeywords Adversarial learning · Neural machine translation · Attention models  \nEditors: João Gama, Alípio Jorge and Salvador García.  \n* Wei Liu [wei.liu@uts.edu.au](wei.liu@uts.edu.au)  \nMingze Ni  \n[mingze.ni@student.uts.edu.au](mingze.ni@student.uts.edu.au)  \nCe Wang  \n[wce@pku.edu.cn](wce@pku.edu.cn)  \nTianqing Zhu  \n[tianqing.zhu@uts.edu.au](tianqing.zhu@uts.edu.au)  \nShui Yu  \n[shui.yu@uts.edu.au](shui.yu@uts.edu.au)  \n1 School of Computer Science, University of Technology Sydney, Sydney, Australia  \n2 Peking University, Beijing, China  \n1 Introduction  \nNatural language processing (NLP) models are crucial for numerous AI-related applications, including sentiment analysis (Li et al., 2021 ; Xue et al., 2022), knowledge tracing (Song et al., 2021, 2022), question answering (Berant et al., 2013), and machine translation (Luong et al., 2017 ; Dzmitry Bahdanau & Bengio, 2015) . These models exploit contextual information in textual sequences which make them vulnerable to text perturbation. Among the NLP tasks, NMTs can also be sensitive to adversarial examples, such as malicious tampering and input typos, as the sequence-to-sequence mapping relies on both the accuracy of individual word translation and contextual correlation within a sentence. Therefore, asa practical application that can be broadly applied for commercial purposes, the robustness of NMTs against adversarial attacks is highly desired, posing the necessity of studying NMT-targeted attacks.  \nExisting attack methods to NLP models can be generally divided into character-level and word-level attacks. Character-level attacks, which manipulate informational letters within a word to attack the victim NLP model with incorrectly spelled examples, have been explored and proven effective in both white-box and black-box settings (Belinkov & Bisk, 2017 ; Ebrahimi et al., 2018) . However, character-level attacks can be easily defended by spelling auto-correction methods. In contrast, word-level attack methods hold that an adversary should locate the vulnerable words and manipulate them, such as swapping, inserting, deleting, and substituting, to deceive the NLP models (Cheng et al., 2019 ; Alzantot et al., 2018) . However, word-level attacks to NLP models usually have a trade-off where the attacking performance depends on the number of perturbed words (Michel et al., 2019) . Despite of the constant efforts on improving NLP attack methods, it is still challenging to strike such a balance between the number of perturbed ","cbCaikuOIVSrMtGe","https://ap.wps.com/l/cbCaikuOIVSrMtGe","pdf",2261962,1,26,"English","en",105,"# Introduction\n# Related Work\n## Word-level attacks to NLP models","[{\"question\":\"How are adversarial substitutions generated to preserve semantics?\",\"answer\":\"The method applies a pretrained Mask Language Model to perform semantic-aware substitutions on the identified victim words.\"}]","Attacking neural machine translations via hybrid attention learning | PDF",1785896415,66,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"attacking-neural-machine-translations-via-hybrid-attention-learning","",{"@graph":36,"@context":77},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/attacking-neural-machine-translations-via-hybrid-attention-learning/125061/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"How are adversarial substitutions generated to preserve semantics?","Question",{"text":75,"@type":76},"The method applies a pretrained Mask Language Model to perform semantic-aware substitutions on the identified victim words.","Answer","https://schema.org",{"og:url":52,"og:type":79,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":81,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,120,123,127],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":98,"slug":130},19,"General","general"]