







Adversarial Examples Generation Approach for Tendency Classification on Chinese Texts
Fund Project:

National Natural Science Foundation of China (61876134); National Key Research and Development Program of China (2016YFB0801100); Fundamental Research Funds for the Central Universities (2042018kf1028)

    Studies have shown that the adversarial example attack is that small perturbations are added on the input to make deep neural network (DNN) misbehave. Meanwhile, these attacks also exist in Chinese text sentiment orientation classification based on DNN and a method "WordHandling" is proposed to generate this kind of adversarial examples. This method designs a new algorithm aiming at calculating important words. Then the words are replaced with homonym to generate adversarial examples, which are used to conduct an adversarial example attack in black-box scenario. This study also verifies the effectiveness of the proposed method with real data set, i.e. Jingdong shopping and Ctrip hotel review, on long short-term memory network (LSTM) and convolutional neural network (CNN). The experimental results show that the adversarial examples in this study can mislead Chinese text orientation detection system well.

    [12] 卿斯汉.Android安全研究进展.软件学报,2016,27(01):45-71. http://www.jos.org.cn/1000-9825/4914.htm[doi:10.13328/j.cnki. jos.004914]
    [15] 马玉琨,毋立芳,简萌,刘方昊,杨洲.一种面向人脸活体检测的对抗样本生成算法.软件学报,2018,29(1):1-10. http://www.jos.org.cn/1000-9825/5568.htm[doi:10.13328/j.cnki.jos.005568]
  收稿日期:2018-05-31
  最后修改日期:2018-09-21
  在线发布日期: 2019-04-03
