Must-read Papers on Textual Adversarial Attack and Defense
This list is currently maintained by Chenghao Yang at UChicago.
Other previous main contributors including Fanchao Qi, and Yuan Zang when they were at THUNLP.
We thank all the great contributors very much.
Each paper is attached to one or more following labels indicating how much information the attack model knows about the victim model: gradient
(=white
, all information), score
(output decision and scores), decision
(only output decision) and blind
(nothing)
blind
[pdf]gradient
[pdf] [code]score
[pdf]gradient
[pdf] [code]blind
[pdf] [code]gradient
[pdf] [code]blind
[pdf] [data]score
[pdf]blind
[pdf] [dataset]gradient
score
[pdf] [code]decision
[pdf] [code]score
[pdf] [code&data]decision
[pdf] [dataset]blind
[pdf] [code&data]decision
[pdf] [code]score
decision
blind
[pdf] [code]score
[pdf] [code]decision
[pdf][code]score
[pdf][code]decision
[pdf][code]decision
[pdf][code]decision
[pdf] [code]score
[pdf][code]gradient
[pdf] [code]gradient
[pdf] [code]score
[pdf] [code]score
[pdf] [code]score
[pdf]score
[pdf] [code]score
[pdf] [code]score
[pdf] [code]blind
[pdf] [code]decision
[pdf] [code]gradient
[pdf] [code]score
[pdf] [code]score
[pdf] [code]blind
[pdf] [code]decision
[pdf] [code]score
[pdf]score
[pdf] [code]score
[pdf] [code]score
[pdf] [code]gradient
score
[pdf] [code]decision
[pdf]score
[pdf] [code]score
[pdf] [code]score
[pdf] [code]score
[pdf]score
[pdf] [code]gradient
score
[pdf] [code]gradient
[pdf]gradient
[pdf]score
[pdf] [code]blind
[pdf] [dataset]gradient
score
[pdf]gradient
[pdf] [code]gradient
[pdf]gradient
[pdf]score
blind
[pdf] [code]blind
[pdf] [code]blind
[pdf] [code&data]blind
[pdf] [code]score
[pdf] [code]gradient
[pdf] [code]blind
[pdf] [code&data]blind
[pdf]blind
[pdf] [code]blind
[pdf] [code]score
[pdf] [code]gradient
[pdf] [code]score
[pdf] [code]blind
[pdf] [code]gradient
[pdf] [code] [website]gradient
score
[pdf]score
[pdf]gradient
[pdf] [code]blind
[pdf] [code&data]gradient
[pdf] [code]We thank all the contributors to this list. And more contributions are very welcome.