2020/10/06 by Alvin Chan, Yi Tay, Chan, Alvin +5
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Artificial Intelligence (cs.AI) #Computation and Language (cs.CL) #FOS: Computer and information sciences #Neural and Evolutionary Computing (cs.NE) #Topic Modeling
paper · pdf · doi:10.48550/arxiv.2010.02684
openalex publication_date 2020/10/06 · openalex created_date 2020/10/15 · openalex updated_date 2026/07/28
This paper demonstrates a fatal vulnerability in natural language inference (NLI) and text classification systems. More concretely, we present a 'backdoor poisoning' attack on NLP models. Our poisoning attack utilizes conditional adversarially regularized autoencoder (CARA) to generate poisoned training samples by poison injection in latent space. Just by adding 1% poisoned data, our experiments show that a victim BERT finetuned classifier's predictions can be steered to the poison target class with success rates of >80% when the input hypothesis is injected with the poison signature, demonstrating that NLI and text classification systems face a huge security risk.