Preview of the new IC2 website. It is not public yet and is hidden from search engines.

Publications

Poison attacks against text datasets with conditional adversarially regularized autoencoder

A Chan, Y Tay, YS Ong, A Zhang. Cited by 65

Web IntelligenceIntegrative, Rapid, Data Analysis

Abstract

This paper demonstrates a fatal vulnerability in natural language inference (NLI) and text classification systems.More concretely, we present a 'backdoor poisoning' attack on NLP models.Our poisoning attack utilizes conditional adversarially regularized autoencoder (CARA) to generate poisoned training samples by poison injection in latent space.Just by adding 1% poisoned data, our experiments show that a victim BERT finetuned classifier's predictions can be steered to the poison target class with success rates of > 80% when the input hypothesis is injected with the poison signature, demonstrating that NLI and text classification systems face a huge security risk.

Authors: Alvin Chan, Yi Tay, Yew-Soon Ong, Aston Zhang

DOI · Full text · Google Scholar