Text Adversarial Defense via Granular-Ball Sample Enhancement

被引:0
|
作者
Wang, Zeli [1 ]
Li, Jian [1 ]
Xia, Shuyin [1 ]
Lin, Longlong [2 ]
Wang, Guoyin [1 ]
机构
[1] Chongqing Univ Posts & Telecommun, Minist Educ, Key Lab Cyberspace Big Data Intelligent Secur, Chongqing, Peoples R China
[2] Southwest Univ, Coll Comp & Informat Sci, Chongqing, Peoples R China
基金
中国国家自然科学基金;
关键词
Natural processing language; Adversarial defense; Clustering; Adversarial training; Sample enhancement;
D O I
10.1145/3652583.3658083
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep learning has achieved outstanding performance in natural language processing, but actuality has witnessed its fragility against adversarial attacks. Synonyms-based attacks are most disastrous since their generated samples approximate raw inputs. Several countermeasures have been proposed in the literature, but the defense effectiveness is unsatisfactory because of the clumsy single-granularity synonyms clustering. To mitigate this dilemma, we propose a Granular-Ball Sample Enhancement-based defense Framework (GBSEF) for text adversarial attacks. Specifically, GBSEF first adopts an effective general synonyms clustering algorithm, which can adaptively adjust the granularity of synonym sets (i.e., granular-balls) for diverse datasets. Regarding each ball as a dot, the function consisting of most dots well fits the original data distribution, resulting in the relationships among words being well presented by the granular-balls. GBSEF then replaces each input word with the center vector of its subordinate ball, to construct robust samples preserving syntax and semantic information simultaneously. Finally, GBSEF combines a random substitution mechanism with granular-balls. This way can prompt GBSEF to take full advantage of the multi-granularity feature of granular-balls, to get more diverse valid samples. GBSEF obtains great performance through training on these samples. Abundant evaluations demonstrate the robustness and effectiveness of GBSEF against adversarial attacks, albeit with a slight performance decrease under normal scenarios without attacks. Meanwhile, GBSEF has good transferability against adversarial samples. Compared with state-of-art defense countermeasures, under multiple attacks on four neural network models (i.e., CNN, LSTM, Bi-LSTM, BERT), GBSEF always outperforms existing baselines.
引用
收藏
页码:348 / 356
页数:9
相关论文
共 50 条
  • [1] A framework of granular-ball generation for classification via granularity tuning
    Pan, Jialong
    Lang, Guangming
    Xiao, Qimei
    Yang, Tian
    APPLIED INTELLIGENCE, 2025, 55 (01)
  • [2] Open Continual Feature Selection via Granular-Ball Knowledge Transfer
    Cao, Xuemei
    Yang, Xin
    Xia, Shuyin
    Wang, Guoyin
    Li, Tianrui
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (12) : 8967 - 8980
  • [3] GBCT: Efficient and Adaptive Clustering via Granular-Ball Computing for Complex Data
    Xia, Shuyin
    Shi, Bolun
    Wang, Yifan
    Xie, Jiang
    Wang, Guoyin
    Gao, Xinbo
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2025,
  • [4] GB-GAIN: Granular-ball conditional generative adversarial imputation networks for incomplete data
    Hao, Zepu
    Pei, Shenglei
    Han, Qinghao
    Ai, Runqi
    PROCEEDINGS OF THE 2024 6TH INTERNATIONAL CONFERENCE ON BIG DATA ENGINEERING, BDE 2024, 2024, : 48 - 53
  • [5] Granular-Ball Three-Way Decision
    Yang, Xin
    Li, Yanhua
    Xia, Shuyin
    Lian, Xiaoyu
    Wang, Guoyin
    Li, Tianrui
    ROUGH SETS, IJCRS 2023, 2023, 14481 : 283 - 295
  • [6] Detecting anomalies with granular-ball fuzzy rough sets
    Su, Xinyu
    Yuan, Zhong
    Chen, Baiyang
    Peng, Dezhong
    Chen, Hongmei
    Chen, Yingke
    INFORMATION SCIENCES, 2024, 678
  • [7] GBTWSVM: Granular-Ball Twin Support Vector Machine
    Zhao, Lixi
    Zhang, Zhifei
    Liu, Wenjun
    Lang, Guangming
    ROUGH SETS, PT I, IJCRS 2024, 2024, 14839 : 238 - 251
  • [8] An Efficient Spectral Clustering Algorithm Based on Granular-Ball
    Xie, Jiang
    Kong, Weiyu
    Xia, Shuyin
    Wang, Guoyin
    Gao, Xinbo
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (09) : 9743 - 9753
  • [9] GBSVM: An Efficient and Robust Support Vector Machine Framework via Granular-Ball Computing
    Xia, Shuyin
    Lian, Xiaoyu
    Wang, Guoyin
    Gao, Xinbo
    Chen, Jiancu
    Peng, Xiaoli
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024,
  • [10] Granular-Ball Fuzzy Set and Its Implement in SVM
    Xia, Shuyin
    Lian, Xiaoyu
    Wang, Guoyin
    Gao, Xinbo
    Hu, Qinghua
    Shao, Yabin
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (11) : 6293 - 6304