Adversarial example generation via genetic algorithm
Shasha Zhou, Ke Li, Geyong Min · Proceedings of the Genetic and Evolutionary Computation Conference Companion · 2022
In recent years, some studies showed that deep neural networks (DNNs) are vulnerable to being attacked by small perturbated examples. To satisfy the lexical, grammatical, and semantic constrain, some works proposed using black-box population-based optimization algorithms to attack neural networks in natural language processing. However, they are inefficient enough because they do not consider the characteristics of the text itself. Also, they are slow to close to the decision boundary. In this paper, we propose a more efficient attention based genetic algorithm adversarial attack method, called AGA. We use attention mechanism to pay more attention to the important tokens and utilize the multi-membered strategy to accelerate the search procedure. The result shows that our attack achieves a higher success rate with less than 136% of the number of queries than the existing methods.