2017/07/23 by Robin Jia, Percy Liang, Jia, Robin +1 · 1 voice · 264 citations
Computer Science · Mathematics · #Adversarial Robustness in Machine Learning #Adversarial system #Adversary #Artificial intelligence #Comprehension #Computation and Language (cs.CL) #Computer science #Computer security #FOS: Computer and information sciences #Language model #Linguistics #Machine Learning (cs.LG) #Mathematics #Natural Language Processing Techniques #Natural language processing #Programming language #Reading (process) #Reading comprehension #Scheme (mathematics) #Topic Modeling #cs.CL #cs.LG
paper · pdf · doi:10.48550/arxiv.1707.07328
published in arXiv (Cornell University) (Cornell University) · EMNLP 2017
arxiv created 2017/07/23 · openalex publication_date 2017/07/23 · arxiv updated 2017/07/25 · openalex created_date 2025/10/10 · openalex updated_date 2026/08/06
Standard accuracy metrics indicate that reading comprehension systems are making rapid progress, but the extent to which these systems truly understand language remains unclear. To reward systems with real language understanding abilities, we propose an adversarial evaluation scheme for the Stanford Question Answering Dataset (SQuAD). Our method tests whether systems can answer questions about paragraphs that contain adversarially inserted sentences, which are automatically generated to distract computer systems without changing the correct answer or misleading humans. In this adversarial setting, the accuracy of sixteen published models drops from an average of 75% F1 score to 36%; when the adversary is allowed to add ungrammatical sequences of words, average accuracy on four models decreases further to 7%. We hope our insights will motivate the development of new models that understand language more precisely.