arXiv · 2501.11852
Cross-Entropy Attacks to Language Models via Rare Event Simulation
Abstract
Black-box textual adversarial attacks are challenging due to the lack of model information and the discrete, non-differentiable nature of text. Existing methods often lack versatility for attacking different models, suffer from limited attacking performance due to the inefficient optimization with word saliency ranking, and frequently sacrifice semantic integrity to achieve better attack outcomes. This paper introduces a novel approach to textual adversarial attacks, which we call Cross-Entropy Attacks (CEA), that uses Cross-Entropy optimization to address the above issues. Our CEA approach defines adversarial objectives for both soft-label and hard-label settings and employs CE optimization to identify optimal replacements. Through extensive experiments on document classification and language translation problems, we demonstrate that our attack method excels in terms of attacking performance, imperceptibility, and sentence quality.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Mingze Ni, Yongshun Gong, Wei Liu. 2025-01-21. Cross-Entropy Attacks to Language Models via Rare Event Simulation. https://arxiv.org/abs/2501.11852
Cite the original work for its findings. Save a collection to share your selection of sources.