[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125271-en":3,"doc-seo-125271-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125271,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Reversible Jump Attack to Textual Classifiers with Modification Reduction","Recent research on adversarial examples highlights vulnerabilities in natural language processing models, where existing generation methods rely on deterministic hierarchical rules that do not target the most effective adversarial solutions. This work introduces two complementary algorithms: Reversible Jump Attack (RJA) for generating highly effective adversarial examples via randomized search-space expansion, and Metropolis–Hasting Modification Reduction (MMR) for improving imperceptibility. Extensive experiments show RJA–MMR achieves stronger attack performance while maintaining fluency and grammar correctness.","Reversible jump attack to textual classifiers with modification reduction  \nMingze Ni1 · Zhensu Sun2 · Wei Liu1  \nReceived: 18 January 2023 / Revised: 19 February 2024 / Accepted: 11 March 2024 /  \nPublished online: 22 April 2024 © The Author(s) 2024  \nAbstract  \nRecent studies on adversarial examples expose vulnerabilities of natural language processing models. Existing techniques for generating adversarial examples are typically driven by deterministic hierarchical rules that are agnostic to the optimal adversarial examples, a strategy that often results in adversarial samples with a suboptimal balance between magnitudes of changes and attack successes. To this end, in this research we propose two algorithms, Reversible Jump Attack (RJA) and Metropolis–Hasting Modification Reduction (MMR), to generate highly effective adversarial examples and to improve the imperceptibility of the examples, respectively. RJA utilizes a novel randomization mechanism to enlarge the search space and efficiently adapts to a number of perturbed words for adversarial examples. With these generated adversarial examples, MMR applies the Metropolis– Hasting sampler to enhance the imperceptibility of adversarial examples. Extensive experiments demonstrate that RJA-MMR outperforms current state-of-the-art methods in attack performance, imperceptibility, fluency and grammar correctness.  \nKeywords Textual attack · Adversarial learning · Natural language processing  \nEditor: Lijun Zhang.  \n* Wei Liu [wei.liu@uts.edu.au](wei.liu@uts.edu.au)  \nMingze Ni  \n[mingze.ni@student.uts.edu.au](mingze.ni@student.uts.edu.au)  \nZhensu Sun  \n[sunzhs@shanghaitech.edu.cn](sunzhs@shanghaitech.edu.cn)  \n1 School of Computer Science, University of Technology Sydney, 15 Broadway, Sydney, NSW 2007, Australia  \n2 School of Information Science and Technology, ShanghaiTech University, 393 Middle Huaxia Road, Shanghai 201210, China  \n1 Introduction  \nNLP models are known to be vulnerable in various applications, including machine translation (Ni et al., 2022 ; Cheng et al., 2020 ; Tan et al., 2020), sentiment analysis (Zanget al., 2020 ; Yang et al., 2021), and text summarization (Cheng et al., 2020) . Attackers can exploit these weaknesses, creating adversarial examples that compromise the performance of targeted NLP systems. This growing susceptibility presents significant security challenges for AI models.  \nTextual attacks on NLP models are classified into character (Iyyer et al., 2018b; Ribeiro et al., 2018), word (Alzantot et al., 2018 ; Jia et al., 2019), and sentence-level (Jia & Liang, 2017) attacks. Character-level attacks are easily countered due to noticeable misspellings (Ebrahimi et al., 2018), while sentence-level attacks often yield complex, hard-to-read text (Gan & Ng, 2019) . Word-level attacks are gaining preference for their effectiveness and subtlety, as they involve replacing words with carefully chosen substitutes (Zhang et al., 2020 ; Garg & Ramakrishnan, 2020 ; Liet al., 2020) . Consequently, our focus is on conducting word-level adversarial attacks.  \nCrafting optimal adversarial examples involves navigating the interplay of successful attacks, controlled imperceptibility. The predominant strategies for this can be classified into optimization algorithms and hierarchical search methods. Within the realm of optimization, Genetic Attack (GA) (Alzantot et al., 2018 ; Jia et al., 2019) and Particle Swarm Optimization (PSO) (Zang et al., 2020) stand out as evolutionary approaches, focusing on optimizing attack effectiveness within embedding spaces and sememe-based thesauri, respectively. However, these methods face two primary challenges: 1) low efficiency in the optimization process due to the expansive search space, such as GloVe (Pennington et al., 2014), and 2) Compromised semantic integrity, as even synonym-based word substitutions can cause sentence-level semantics inconsistency. On the other hand, Hierarchical search crafts adversarial examples by ord","cbCaivNhkNqaVYn5","https://ap.wps.com/l/cbCaivNhkNqaVYn5","pdf",3518257,1,31,"English","en",105,"# Abstract\n# Keywords\n# Introduction\n## Vulnerabilities of NLP models\n## Types of textual attacks\n## Limitations of existing approaches\n## Proposed RJA and MMR approach","[{\"question\":\"What problem does this research address in adversarial text generation?\",\"answer\":\"Existing methods often use deterministic hierarchical rules that yield adversarial examples with a poor trade-off between the magnitude of changes and attack success. The work targets generating more effective adversarial examples while improving imperceptibility.\"},{\"question\":\"What are RJA and MMR, and what does each contribute?\",\"answer\":\"RJA generates adversarial examples using a reversible-jump randomization mechanism to expand the search space and adapt to the number of perturbed words. MMR then applies a Metropolis–Hasting sampler to enhance the imperceptibility of the adversarial outputs.\"},{\"question\":\"How is the quality of adversarial candidates evaluated in RJA?\",\"answer\":\"RJA uses a target distribution regularized with a strong penalty on semantic (dis)similarity, and candidates are accepted based on an acceptance probability during iterative sampling.\"}]","Reversible Jump Attack to Textual Classifiers with Modification Reduction | PDF",1785897834,78,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"reversible-jump-attack-to-textual-classifiers-with-modification-reduction","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/reversible-jump-attack-to-textual-classifiers-with-modification-reduction/125271/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does this research address in adversarial text generation?","Question",{"text":75,"@type":76},"Existing methods often use deterministic hierarchical rules that yield adversarial examples with a poor trade-off between the magnitude of changes and attack success. The work targets generating more effective adversarial examples while improving imperceptibility.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What are RJA and MMR, and what does each contribute?",{"text":80,"@type":76},"RJA generates adversarial examples using a reversible-jump randomization mechanism to expand the search space and adapt to the number of perturbed words. MMR then applies a Metropolis–Hasting sampler to enhance the imperceptibility of the adversarial outputs.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the quality of adversarial candidates evaluated in RJA?",{"text":84,"@type":76},"RJA uses a target distribution regularized with a strong penalty on semantic (dis)similarity, and candidates are accepted based on an acceptance probability during iterative sampling.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]