首页|基于改进蚁群算法的对抗样本生成模型

基于改进蚁群算法的对抗样本生成模型

扫码查看
传统的文本生成对抗方法主要采用位置置换、字符替换等方式,耗费时间较长且效果较差.针对以上问题,该文提出一种基于改进蚁群算法的对抗样本生成模型IGAS(Improved ant colony algorithm to Generate Adversarial Sample),利用蚁群算法的特点生成对抗样本,并利用类形字进行优化.首先,构建城市节点群,利用样本中的词构建城市节点群;然后对原始输入样本,利用改进的蚁群算法生成对抗样本;再针对生成结果,通过构建的中日类形字典进行字符替换,生成最终的对抗样本;最后在黑盒模式下进行对抗样本攻击实验.实验在情感分类、对话摘要生成、因果关系抽取等多种领域验证了该方法的有效性.
Adversarial Sample Generation Based on Improved Ant Colony Algorithm
The classical adversarial sample generation methods mainly use positional substitution and character sub-stitution,defected by the heavy computation and inferior effect.This paper proposes an adversarial sample genera-tion model based on an improved ant colony algorithm,which optimize the adversarial sample by the class word.Firstly,urban agglomeration nodes are constructed by using the words in the samples.Then,the modified ant colo-ny algorithm is used to generate antagonistic samples from the original input samples.And according to the genera-ted result,the final antagonistic sample is generated by character substitution in the constructed Sino-Japanese class dictionary.Finally,the experiment against sample attack is carried out in black-box mode.Experiments verify the effectiveness of this method in many fields including sentiment classification,conversation summary generation,and causality extraction.

ant colony algorithmcountermeasure sample generationtypefacesblack-box attack

刘文娟、吴厚月、张顺香

展开 >

安徽理工大学计算机科学与工程学院,安徽淮南 232001

蚌埠学院计算机与信息工程学院,安徽蚌埠 233030

合肥综合性国家科学中心人工智能研究院,安徽合肥 230088

蚁群算法 对抗样本生成 类形字 黑盒攻击

国家自然科学基金安徽省属高校协同创新项目

62076006GXXT-2021-008

2024

中文信息学报
中国中文信息学会,中国科学院软件研究所

中文信息学报

CSTPCDCHSSCD北大核心
影响因子:0.8
ISSN:1003-0077
年,卷(期):2024.38(8)