{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:24:17Z","timestamp":1780586657522,"version":"3.54.1"},"reference-count":84,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,5]]},"DOI":"10.1109\/sp46214.2022.9833641","type":"proceedings-article","created":{"date-parts":[[2022,7,27]],"date-time":"2022-07-27T19:28:05Z","timestamp":1658950085000},"page":"1987-2004","source":"Crossref","is-referenced-by-count":61,"title":["Bad Characters: Imperceptible NLP Attacks"],"prefix":"10.1109","author":[{"given":"Nicholas","family":"Boucher","sequence":"first","affiliation":[{"name":"University of Cambridgem, Computer Science &#x0026; Technology"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ilia","family":"Shumailov","sequence":"additional","affiliation":[{"name":"University of Cambridge and Vector Institute"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ross","family":"Anderson","sequence":"additional","affiliation":[{"name":"University of Cambridge and University of Edinburgh"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nicolas","family":"Papernot","sequence":"additional","affiliation":[{"name":"University of Cambridge and Vector Institute"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","article-title":"Generating natural adversarial examples","author":"zhao","year":"2018","journal-title":"International Conference on Learning Representations"},{"key":"ref57","article-title":"Windows developer documentation: Unicode","year":"2018"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-1170"},{"key":"ref56","article-title":"Apple developer documentation: Core text","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23138"},{"key":"ref59","article-title":"Google&#x2019;s neural machine translation system: Bridging the gap between human and machine translation","author":"wu","year":"2016"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1316"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.3115\/1557769.1557821"},{"key":"ref53","article-title":"&#x2018;Right-to-Left Override&#x2019; Aids Email Attacks","author":"krebs","year":"2011"},{"key":"ref52","article-title":"Unicode Bidirectional Algorithm","year":"2020","journal-title":"The Unicode Consortium"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"ref55","article-title":"Pango","year":"2021"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"ref54","article-title":"International components for unicode","year":"2021"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1314"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.319"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00024"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2011.12.023"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355587"},{"key":"ref46","article-title":"PayPal alert! Beware the &#x2019;Paypai&#x2019; scam","author":"sullivan","year":"2000"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/eCrime51433.2020.9493251"},{"key":"ref48","first-page":"24","article-title":"Cutting through the confusion: A measurement study of homograph attacks","author":"holgers","year":"2006","journal-title":"Proceedings of the Annual Conference on USENIX &#x2019;06 Annual Technical Conference ser ATEC &#x2019;06"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/503124.503156"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.16"},{"key":"ref41","first-page":"311","article-title":"Bleu: a method for automatic evaluation of machine translation","author":"papineni","year":"2002","journal-title":"Proceedings of the 40th Annual Meeting on Association for Computational Linguistics  - ACL '02"},{"key":"ref44","article-title":"Unicode Security Considerations","year":"2014","journal-title":"The Unicode Consortium"},{"key":"ref43","article-title":"The Unicode Standard, Version 13.0","year":"2020"},{"key":"ref49","article-title":"CAPEC-632: Homograph Attack via Homoglyphs (Version 3.4)","year":"2015","journal-title":"MITRE Common Attack Pattern Enumeration and Classification 632"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W17-1101"},{"key":"ref9","article-title":"Synthetic and natural noise both break neural machine translation","volume":"abs 1711 2173","author":"belinkov","year":"2017","journal-title":"CoRR"},{"key":"ref4","article-title":"Evasion with unicode format characters","author":"knight","year":"2018","journal-title":"SpamAssassin - Dev"},{"key":"ref3","article-title":"Google translate","year":"2021"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/JCDL.2014.6970166"},{"key":"ref5","first-page":"1137","article-title":"A neural probabilistic language model","volume":"3","author":"bengio","year":"2003","journal-title":"Journal of Machine Learning Research"},{"key":"ref82","article-title":"Request limits for translator","year":"0"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1404"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1026"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/ICDAR.2007.4376991"},{"key":"ref83","article-title":"Pillow","author":"clark","year":"2021"},{"key":"ref80","author":"savani","year":"2021","journal-title":"DistilBERT Base Uncased Emotion"},{"key":"ref35","first-page":"5998","article-title":"Attention is all you need","author":"vaswani","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref79","article-title":"Distilbert, a distilled version of bert: smaller, faster, cheaper and lighter","author":"sanh","year":"2020"},{"key":"ref34","first-page":"1700","article-title":"Recurrent continuous translation models","author":"kalchbrenner","year":"2013","journal-title":"Proceedings of the 2013 Conference on Empirical Methods in Natural Language Processing"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"ref37","article-title":"Learning phrase representations using RNN encoderdecoder for statistical machine translation","volume":"abs 1406 1078","author":"cho","year":"2014","journal-title":"CoRR"},{"key":"ref36","first-page":"3104","article-title":"Sequence to sequence learning with neural networks","volume":"27","author":"sutskever","year":"2014","journal-title":"Advances in neural information processing systems"},{"key":"ref31","article-title":"Towards the science of security and privacy in machine learning","author":"papernot","year":"2016","journal-title":"arXiv preprint arXiv 1611 03814"},{"key":"ref75","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","author":"devlin","year":"2018","journal-title":"arXiv preprint arXiv 1810 04805"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-1101"},{"key":"ref33","article-title":"A Survey of Current Paradigms in Machine Translation","author":"dorr","year":"1998","journal-title":"MARYLAND UNIV COLLEGE PARK INST FOR ADVANCED COMPUTER STUDIES"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.3115\/1119176.1119195"},{"key":"ref32","article-title":"Translation","author":"weaver","year":"1949","journal-title":"Translation Machine Translation of Languages Fourteen Essays"},{"key":"ref76","article-title":"M&#x00FC;nchener Digitalisierungszentrum (MDZ) - Bayerische Staatsbibliothek","year":"2020","journal-title":"BERT Large Cased Finetuned CoNLL03 English"},{"key":"ref2","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015"},{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv preprint arXiv 1312 6199"},{"key":"ref39","first-page":"387","article-title":"Evasion attacks against machine learning at test time","author":"biggio","year":"2013","journal-title":"Machine Learning and Knowledge Discovery in Databases"},{"key":"ref38","article-title":"Neural machine translation of rare words with subword units","volume":"abs 1508 7909","author":"sennrich","year":"2015","journal-title":"CoRR"},{"key":"ref71","article-title":"Wikipedia talk labels: Toxicity","author":"thain","year":"2017"},{"key":"ref70","article-title":"Toxic comment classifier","year":"2020"},{"key":"ref73","article-title":"Roberta: A robustly optimized BERT pretraining approach","volume":"abs 1907 11692","author":"liu","year":"2019","journal-title":"CoRR"},{"key":"ref72","article-title":"Perspective API","author":"jigsaw","year":"2021"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-6301"},{"key":"ref23","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2019"},{"key":"ref67","article-title":"Chromium","year":"2021"},{"key":"ref26","first-page":"1","article-title":"Exploiting machine learning to subvert your spam filter","volume":"8","author":"nelson","year":"2008","journal-title":"LEET"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-4009"},{"key":"ref20","article-title":"Facebook is failing in global disinformation fight, says former worker","author":"frenkel","year":"2020","journal-title":"New York Times"},{"key":"ref64","article-title":"Unicode security mechanisms for uts #39: Intentional","year":"2019"},{"key":"ref63","article-title":"Unicode Security Considerations","year":"2020","journal-title":"The Unicode Consortium"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.AI.100-2"},{"key":"ref66","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"International Conference on Learning Representations"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1423"},{"key":"ref65","article-title":"Unicode security mechanisms for uts #39: Confusables","year":"2020"},{"key":"ref28","first-page":"497","article-title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","author":"hong","year":"2019","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref29","article-title":"Label-only membership inference attacks","author":"choo","year":"2020"},{"key":"ref60","article-title":"Neural machine translation of rare words with subword units","volume":"abs 1508 7909","author":"sennrich","year":"2015","journal-title":"CoRR"},{"key":"ref62","article-title":"Unifont","author":"czyborra","year":"2021"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1023\/A:1008202821328"}],"event":{"name":"2022 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2022,5,22]]},"end":{"date-parts":[[2022,5,26]]}},"container-title":["2022 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9833550\/9833558\/09833641.pdf?arnumber=9833641","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,8]],"date-time":"2023-11-08T23:05:16Z","timestamp":1699484716000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9833641\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5]]},"references-count":84,"URL":"https:\/\/doi.org\/10.1109\/sp46214.2022.9833641","relation":{},"subject":[],"published":{"date-parts":[[2022,5]]}}}