Skip to main navigation Skip to search Skip to main content

Semantic Stealth: Crafting Covert Adversarial Patches for Sentiment Classifiers Using Large Language Models

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Deep learning models have been shown to be vulnerable to adversarial attacks, in which perturbations to their inputs cause the model to produce incorrect predictions. As opposed to adversarial attacks in computer vision, where small changes introduced to pixel values can drastically alter a model’s output while remaining imperceptible to humans, text-based attacks are difficult to conceal due to the discrete nature of tokens. Consequently, unconstrained gradient-based attacks often produce adversarial examples that lack semantic meaning, rendering them detectable through visual inspection or perplexity filters. In contrast to methods that rely on gradient-based optimization in the embedding space, we propose an approach that leverages a Large Language Model’s ability to generate grammatically correct and semantically meaningful text to craft adversarial patches that seamlessly blend in with the original input text. These patches can be used to alter the behavior of a target model, such as a text classifier. Since our approach does not rely on gradient backpropagation, it only requires access to the target model’s confidence scores, making it a grey-box attack. We demonstrate the feasibility of our approach using open-source LLMs, including Intel’s Neural Chat, Llama2, and Mistral-Instruct, to generate adversarial patches capable of altering the predictions of a distilBERT model fine-tuned on the IMDB reviews dataset for sentiment classification.

Original languageEnglish
Title of host publicationAISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with
Subtitle of host publicationCCS 2024
PublisherAssociation for Computing Machinery, Inc
Pages42-52
Number of pages11
ISBN (Electronic)9798400712289
DOIs
StatePublished - Nov 22 2024
Event16th ACM Workshop on Artificial Intelligence and Security, AISec 2024, co-located with CCS 2024 - Salt Lake City, United States
Duration: Oct 14 2024Oct 18 2024

Publication series

NameAISec 2024 - Proceedings of the 2024 Workshop on Artificial Intelligence and Security, Co-Located with: CCS 2024

Conference

Conference16th ACM Workshop on Artificial Intelligence and Security, AISec 2024, co-located with CCS 2024
Country/TerritoryUnited States
CitySalt Lake City
Period10/14/2410/18/24

Keywords

  • adversarial attack
  • adversarial patches
  • large language model
  • sentiment classification
  • transformer-based model

Fingerprint

Dive into the research topics of 'Semantic Stealth: Crafting Covert Adversarial Patches for Sentiment Classifiers Using Large Language Models'. Together they form a unique fingerprint.

Cite this