pisco_log
banner

Syllable-level Input Defence for Low-resource Text via Pseudo-perplexity Purification

Shiping Han

Abstract


Deployed low-resource language text classification models face security threats from adversarial attacks, and retraining them incurs
high costs. Therefore, we have been studying and building an adversarial attack and defence system for low-resource language text. Given that
it is the basis for the system, we put forward a model-agnostic, syllable-level input-level defence based on pseudo-perplexity detection and
mask reconstruction. By estimating external masked language models, we can know if there is a disturbance. Then, the suspicious syllables
are corrected in a multi-dimensional restricted candidate space to modify the text and reduce the pseudo-perplexity of the whole sentence as
much as possible. Therefore, the input is clean and the parameters of the victim model do not change. Based on the experiment results of the
TNCC-title and TU_SA datasets, the proposed defence can be stably restored from all kinds of attacks, and it has a small change rate and high
semantic fidelity. A Practical and Deployable Approach to Enhance the Robustness of Low-Resource Language Text Classification Systems is
Presented in this paper.

Keywords


Low-resource language text classification; Adversarial attacks; Input-level defence; Pseudo-perplexity

Full Text:

PDF

Included Database


References


[1] Cao X, Dawa D, Qun N, et al. Pay Attention to the Robustness of Chinese Minority Language Models! Syllable-level Adversarial Attack

on Tibetan Script [C]. Proc Workshop Trustworthy Nat Lang Process, 2023: 35-46.

[2] Yang Z, Xu Z, Cui Y, et al. CINO: A Chinese Minority Pre-trained Language Model [C]. Proc Int Conf Comput Linguist, 2022: 3937-

3949.

[3] Sun Y, Liu S, Deng J, et al. TiBERT: Tibetan Pre-trained Language Model [C]. IEEE Int Conf Syst Man Cybern, 2022: 2956-2961.

[4] Li L, Song D, Qiu X. Text Adversarial Purification as Defence against Adversarial Attacks [C]. Proc Annu Meet Assoc Comput Linguist,

2023: 338-350.

[5] Cao X, Qun N, Gesang Q, et al. Multi-Granularity Tibetan Textual Adversarial Attack Method Based on Masked Language Model [C].

Companion Proc ACM Web Conf, 2024: 1672-1680.

[6] Cao X, Gesang Q, Sun Y, et al. TSCheater: Generating High-Quality Tibetan Adversarial Texts via Visual Similarity [C]. Proc IEEE Int

Conf Acoust Speech Signal Process, 2025.




DOI: http://dx.doi.org/10.70711/aitr.v4i4.10158

Refbacks

  • There are currently no refbacks.