Deceiving Google's Perspective API Built for Detecting Toxic Comments
arXiv:1702.08138
Abstract
Social media platforms provide an environment where people can freely engage in discussions. Unfortunately, they also enable several problems, such as online harassment. Recently, Google and Jigsaw started a project called Perspective, which uses machine learning to automatically detect toxic language. A demonstration website has been also launched, which allows anyone to type a phrase in the interface and instantaneously see the toxicity score [1]. In this paper, we propose an attack on the Perspective toxic detection system based on the adversarial examples. We show that an adversary can subtly modify a highly toxic phrase in a way that the system assigns significantly lower toxicity score to it. We apply the attack on the sample phrases provided in the Perspective website and show that we can consistently reduce the toxicity scores to the level of the non-toxic phrases. The existence of such adversarial examples is very harmful for toxic detection systems and seriously undermines their usability.
4 pages
Cited by in corpus (12)
- Blocking Transferability of Adversarial Examples in Black-Box Learning Systems
- Weight Poisoning Attacks on Pre-trained Models
- A large-scale crowdsourced analysis of abuse against women journalists and politicians on Twitter
- Conversational Networks for Automatic Online Moderation
- Towards Robust Toxic Content Classification
- On Evaluation of Adversarial Perturbations for Sequence-to-Sequence Models
- Adversarial Attacks and Defense on Texts: A Survey
- Learning to Attack: Towards Textual Adversarial Attacking in Real-world Situations
- Robust Encodings: A Framework for Combating Adversarial Typos
- White-to-Black: Efficient Distillation of Black-Box Adversarial Attacks
- Visual Attack and Defense on Text
- Context-Sensitive Malicious Spelling Error Correction