{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,18]],"date-time":"2026-04-18T16:39:43Z","timestamp":1776530383854,"version":"3.51.2"},"reference-count":60,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Analytical Center through the RF Government","award":["70-2021-00145"],"award-info":[{"award-number":["70-2021-00145"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/access.2022.3148413","type":"journal-article","created":{"date-parts":[[2022,2,12]],"date-time":"2022-02-12T00:27:51Z","timestamp":1644625671000},"page":"17966-17976","source":"Crossref","is-referenced-by-count":19,"title":["A Differentiable Language Model Adversarial Attack on Text Classifiers"],"prefix":"10.1109","volume":"10","author":[{"given":"Ivan","family":"Fursov","sequence":"first","affiliation":[{"name":"Skolkovo Institute of Science and Technology, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexey","family":"Zaytsev","sequence":"additional","affiliation":[{"name":"Skolkovo Institute of Science and Technology, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6794-2567","authenticated-orcid":false,"given":"Pavel","family":"Burnyshev","sequence":"additional","affiliation":[{"name":"Skolkovo Institute of Science and Technology, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ekaterina","family":"Dmitrieva","sequence":"additional","affiliation":[{"name":"HSE University, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nikita","family":"Klyuchnikov","sequence":"additional","affiliation":[{"name":"Skolkovo Institute of Science and Technology, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrey","family":"Kravchenko","sequence":"additional","affiliation":[{"name":"University of Oxford, Oxford, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8689-7514","authenticated-orcid":false,"given":"Ekaterina","family":"Artemova","sequence":"additional","affiliation":[{"name":"Huawei Noah&#x2019;s Ark Laboratory, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1139-0457","authenticated-orcid":false,"given":"Evgenia","family":"Komleva","sequence":"additional","affiliation":[{"name":"Skolkovo Institute of Science and Technology, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8424-0690","authenticated-orcid":false,"given":"Evgeny","family":"Burnaev","sequence":"additional","affiliation":[{"name":"Skolkovo Institute of Science and Technology, Moscow, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00893"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3374217"},{"key":"ref5","article-title":"Towards a robust deep neural network in texts: A survey","author":"Wang","year":"2019","journal-title":"arXiv:1902.07285"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.16"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3201243"},{"key":"ref8","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref9","article-title":"Towards crafting text adversarial samples","author":"Samanta","year":"2017","journal-title":"arXiv:1707.02812"},{"key":"ref10","article-title":"Deep text classification can be fooled","author":"Liang","year":"2017","journal-title":"arXiv:1704.08006"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/601"},{"key":"ref13","article-title":"Generating natural language adversarial examples on a large scale with generative models","author":"Ren","year":"2020","journal-title":"arXiv:2003.10388"},{"key":"ref14","article-title":"Gradient-based adversarial attacks on categorical sequence models via traversing an embedded world","author":"Fursov","year":"2020","journal-title":"arXiv:2003.04173"},{"key":"ref15","first-page":"3825","article-title":"Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Yan"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-1078"},{"key":"ref17","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. ICLR","author":"Szegedy"},{"key":"ref18","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/872"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1165"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.263"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.coling-main.585"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.500"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.498"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1559"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1610"},{"key":"ref28","first-page":"1298","article-title":"Paws: Paraphrase adversaries from word scrambling","volume-title":"Proc. Conf. North Amer. Chapter Assoc. Comput. Linguistics, Human Lang. Technol. (Long and Short Papers)","volume":"1","author":"Zhang"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1336"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1425"},{"issue":"43","key":"ref31","first-page":"1","article-title":"Greedy attack and gumbel attack: Generating adversarial examples for discrete data","volume":"21","author":"Yang","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1139"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/K18-1047"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6356"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.245"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1561"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5767"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.319"},{"key":"ref40","article-title":"OpenAttack: An open-source textual adversarial attack toolkit","author":"Zeng","year":"2020","journal-title":"arXiv:2009.09191"},{"key":"ref41","first-page":"3881","article-title":"Improved variational autoencoders for text modeling using dilated convolutions","author":"Yang","year":"2017","journal-title":"ICML"},{"key":"ref42","first-page":"5998","article-title":"Attention is all you need","volume-title":"Proc. NeurIPS","author":"Vaswani"},{"key":"ref43","volume-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018"},{"key":"ref44","article-title":"Categorical reparametrization with gumble-softmax","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Jang"},{"key":"ref45","article-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"ref46","article-title":"Categorical reparameterization with gumbel-softmax","author":"Jang","year":"2016"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330701"},{"key":"ref48","article-title":"Roberta: A robustly optimized bert pretraining approach","author":"Liu","year":"2019"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401045"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23138"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"ref53","article-title":"Character-level convolutional networks for text classification","author":"Zhang","year":"2015"},{"key":"ref54","article-title":"Schema-guided dialogue state tracking task at DSTC8","author":"Rastogi","year":"2020","journal-title":"arXiv:2002.01359"},{"key":"ref55","first-page":"1631","article-title":"Recursive deep models for semantic compositionality over a sentiment treebank","volume-title":"Proc. Conf. Empirical Methods Natural Lang. Process.","author":"Socher"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.3115\/1219840.1219855"},{"key":"ref57","article-title":"Adversarial attacks and defenses in images, graphs and text: A review","author":"Xu","year":"2019","journal-title":"arXiv:1909.08072"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-demos.14"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/n16-1014"},{"key":"ref60","first-page":"1815","article-title":"Generating informative and diverse conversational responses via adversarial information maximization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9668973\/09712314.pdf?arnumber=9712314","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,17]],"date-time":"2024-01-17T22:53:39Z","timestamp":1705532019000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9712314\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":60,"URL":"https:\/\/doi.org\/10.1109\/access.2022.3148413","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}