Skip to main navigation Skip to search Skip to main content

Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation

  • Yanni Xue
  • , Haojie Hao
  • , Jiakai Wang*
  • , Qiang Sheng
  • , Renshuai Tao
  • , Yu Liang
  • , Pu Feng
  • , Xianglong Liu
  • *Corresponding author for this work
  • Beihang University
  • Zhongguancun Laboratory
  • CAS - Institute of Computing Technology
  • Beijing Jiaotong University
  • Beijing University of Technology
  • Hefei Comprehensive National Science Center

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

While neural machine translation (NMT) models achieve success in our daily lives, they show vulnerability to adversarial attacks. Despite being harmful, these attacks also offer benefits for interpreting and enhancing NMT models, thus drawing increased research attention. However, existing studies on adversarial attacks are insufficient in both attacking ability and human imperceptibility due to their sole focus on the scope of language. This paper proposes a novel vision-fused attack (VFA) framework to acquire powerful adversarial text, i.e., more aggressive and stealthy. Regarding the attacking ability, we design the vision-merged solution space enhancement strategy to enlarge the limited semantic solution space, which enables us to search for adversarial candidates with higher attacking ability. For human imperceptibility, we propose the perception-retained adversarial text selection strategy to align the human text-reading mechanism. Thus, the finally selected adversarial text could be more deceptive. Extensive experiments on various models, including large language models (LLMs) like LLaMA and GPT-3.5, strongly support that VFA outperforms the comparisons by large margins (up to 81%/14% improvements on ASR/SSIM).

Original languageEnglish
Title of host publicationProceedings of the 33rd International Joint Conference on Artificial Intelligence, IJCAI 2024
EditorsKate Larson
PublisherInternational Joint Conferences on Artificial Intelligence
Pages6606-6614
Number of pages9
ISBN (Electronic)9781956792041
StatePublished - 2024
Event33rd International Joint Conference on Artificial Intelligence, IJCAI 2024 - Jeju, Korea, Republic of
Duration: 3 Aug 20249 Aug 2024

Publication series

NameIJCAI International Joint Conference on Artificial Intelligence
ISSN (Print)1045-0823

Conference

Conference33rd International Joint Conference on Artificial Intelligence, IJCAI 2024
Country/TerritoryKorea, Republic of
CityJeju
Period3/08/249/08/24

Fingerprint

Dive into the research topics of 'Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation'. Together they form a unique fingerprint.

Cite this