Poison Attacks against Text Datasets with Conditional Adversarially Regularized Autoencoder
arXiv:2010.02684
Abstract
This paper demonstrates a fatal vulnerability in natural language inference (NLI) and text classification systems. More concretely, we present a 'backdoor poisoning' attack on NLP models. Our poisoning attack utilizes conditional adversarially regularized autoencoder (CARA) to generate poisoned training samples by poison injection in latent space. Just by adding 1% poisoned data, our experiments show that a victim BERT finetuned classifier's predictions can be steered to the poison target class with success rates of >80% when the input hypothesis is injected with the poison signature, demonstrating that NLI and text classification systems face a huge security risk.
Accepted in EMNLP-Findings 2020, Camera Ready Version
References in corpus (5)
- Conditional Generative Adversarial Nets
- Semi-Supervised Learning with Deep Generative Models
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Adversarial Examples for Evaluating Reading Comprehension Systems
- Poison as a Cure: Detecting & Neutralizing Variable-Sized Backdoor Attacks in Deep Neural Networks