{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:10:35Z","timestamp":1772039435985,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":48,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,15]],"date-time":"2021-11-15T00:00:00Z","timestamp":1636934400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Horizon 2020 research and innovation programme","award":["830929"],"award-info":[{"award-number":["830929"]}]},{"name":"Marie Sk?odowska-Curie grant","award":["101007673"],"award-info":[{"award-number":["101007673"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,15]]},"DOI":"10.1145\/3474369.3486871","type":"proceedings-article","created":{"date-parts":[[2021,10,28]],"date-time":"2021-10-28T11:13:28Z","timestamp":1635419608000},"page":"1-12","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Unicode Evil"],"prefix":"10.1145","author":[{"given":"Antreas","family":"Dionysiou","sequence":"first","affiliation":[{"name":"University of Cyprus, Nicosia, Cyprus"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elias","family":"Athanasopoulos","sequence":"additional","affiliation":[{"name":"University of Cyprus, Nicosia, Cyprus"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,11,15]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998","author":"Alzantot Moustafa","year":"2018","unstructured":"Moustafa Alzantot , Yash Sharma , Ahmed Elgohary , Bo-Jhang Ho , Mani Srivastava , and Kai-Wei Chang . 2018. Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998 ( 2018 ). Moustafa Alzantot, Yash Sharma, Ahmed Elgohary, Bo-Jhang Ho, Mani Srivastava, and Kai-Wei Chang. 2018. Generating natural language adversarial examples. arXiv preprint arXiv:1804.07998 (2018)."},{"key":"e_1_3_2_2_2_1","volume-title":"Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397","author":"Athalye Anish","year":"2017","unstructured":"Anish Athalye , Logan Engstrom , Andrew Ilyas , and Kevin Kwok . 2017. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397 ( 2017 ). Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2017. Synthesizing robust adversarial examples. arXiv preprint arXiv:1707.07397 (2017)."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"crossref","unstructured":"Marco Barreno Blaine Nelson Russell Sears Anthony D Joseph and J Doug Tygar. 2006. Can machine learning be secure?. In ASIACCS. ACM 16--25. Marco Barreno Blaine Nelson Russell Sears Anthony D Joseph and J Doug Tygar. 2006. Can machine learning be secure?. In ASIACCS. ACM 16--25.","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_2_2_4_1","volume-title":"Synthetic and natural noise both break neural machine translation. arXiv preprint arXiv:1711.02173","author":"Belinkov Yonatan","year":"2017","unstructured":"Yonatan Belinkov and Yonatan Bisk . 2017. Synthetic and natural noise both break neural machine translation. arXiv preprint arXiv:1711.02173 ( 2017 ). Yonatan Belinkov and Yonatan Bisk. 2017. Synthetic and natural noise both break neural machine translation. arXiv preprint arXiv:1711.02173 (2017)."},{"key":"e_1_3_2_2_5_1","volume-title":"Design of robust classifiers for adversarial environments","author":"Biggio Battista","unstructured":"Battista Biggio , Giorgio Fumera , and Fabio Roli . 2011. Design of robust classifiers for adversarial environments . In SMC. IEEE , 977--982. Battista Biggio, Giorgio Fumera, and Fabio Roli. 2011. Design of robust classifiers for adversarial environments. In SMC. IEEE, 977--982."},{"key":"e_1_3_2_2_6_1","volume-title":"mbox","author":"John Brooke","year":"1996","unstructured":"John Brooke et al mbox . 1996 . SUS-A quick and dirty usability scale. Usability evaluation in industry, Vol. 189 , 194 (1996), 4--7. John Brooke et almbox. 1996. SUS-A quick and dirty usability scale. Usability evaluation in industry, Vol. 189, 194 (1996), 4--7."},{"key":"e_1_3_2_2_7_1","volume-title":"EuroS&P","author":"Carlini Nicholas","unstructured":"Nicholas Carlini and David Wagner . 2017. Towards evaluating the robustness of neural networks . In EuroS&P . IEEE , 39--57. Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In EuroS&P. IEEE, 39--57."},{"key":"e_1_3_2_2_8_1","unstructured":"Minhao Cheng Jinfeng Yi Pin-Yu Chen Huan Zhang and Cho-Jui Hsieh. 2018. Seq2Sick: Evaluating the Robustness of Sequence-to-Sequence Models with Adversarial Examples. (2018). arxiv: cs.LG\/1803.01128 Minhao Cheng Jinfeng Yi Pin-Yu Chen Huan Zhang and Cho-Jui Hsieh. 2018. Seq2Sick: Evaluating the Robustness of Sequence-to-Sequence Models with Adversarial Examples. (2018). arxiv: cs.LG\/1803.01128"},{"key":"e_1_3_2_2_9_1","volume-title":"EMNIST: an extension of MNIST to handwritten letters. arXiv preprint arXiv:1702.05373","author":"Cohen Gregory","year":"2017","unstructured":"Gregory Cohen , Saeed Afshar , Jonathan Tapson , and Andr\u00e9 van Schaik . 2017. EMNIST: an extension of MNIST to handwritten letters. arXiv preprint arXiv:1702.05373 ( 2017 ). Gregory Cohen, Saeed Afshar, Jonathan Tapson, and Andr\u00e9 van Schaik. 2017. EMNIST: an extension of MNIST to handwritten letters. arXiv preprint arXiv:1702.05373 (2017)."},{"key":"e_1_3_2_2_10_1","volume-title":"Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin , Ming-Wei Chang , Kenton Lee , and Kristina Toutanova . 2018 . Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018). Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)."},{"key":"e_1_3_2_2_11_1","volume-title":"Convolutional Neural Networks in Combination with Support Vector Machines for Complex Sequential Data Classification","author":"Dionysiou Antreas","unstructured":"Antreas Dionysiou , Michalis Agathocleous , Chris Christodoulou , and Vasilis Promponas . 2018. Convolutional Neural Networks in Combination with Support Vector Machines for Complex Sequential Data Classification . In ICANN. Springer , 444--455. Antreas Dionysiou, Michalis Agathocleous, Chris Christodoulou, and Vasilis Promponas. 2018. Convolutional Neural Networks in Combination with Support Vector Machines for Complex Sequential Data Classification. In ICANN. Springer, 444--455."},{"key":"e_1_3_2_2_12_1","volume-title":"SoK: Machine vs. Machine--A Systematic Classification of Automated Machine Learning-Based CAPTCHA Solvers. Computers & Security","author":"Dionysiou Antreas","year":"2020","unstructured":"Antreas Dionysiou and Elias Athanasopoulos . 2020. SoK: Machine vs. Machine--A Systematic Classification of Automated Machine Learning-Based CAPTCHA Solvers. Computers & Security ( 2020 ), 101947. Antreas Dionysiou and Elias Athanasopoulos. 2020. SoK: Machine vs. Machine--A Systematic Classification of Automated Machine Learning-Based CAPTCHA Solvers. Computers & Security (2020), 101947."},{"key":"e_1_3_2_2_13_1","volume-title":"HoneyGen: Generating Honeywords Using Representation Learning","author":"Dionysiou Antreas","unstructured":"Antreas Dionysiou , Vassilis Vassiliades , and Elias Athanasopoulos . 2021. HoneyGen: Generating Honeywords Using Representation Learning . Association for Computing Machinery , New York, NY, USA , 265--279. https:\/\/doi.org\/10.1145\/3433210.3453092 10.1145\/3433210.3453092 Antreas Dionysiou, Vassilis Vassiliades, and Elias Athanasopoulos. 2021. HoneyGen: Generating Honeywords Using Representation Learning. Association for Computing Machinery, New York, NY, USA, 265--279. https:\/\/doi.org\/10.1145\/3433210.3453092"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Anthony Y Fu Xiaotie Deng Liu Wenyin and Greg Little. 2006. The methodology and an application to fight against unicode attacks. In SOUPS. 91--101. Anthony Y Fu Xiaotie Deng Liu Wenyin and Greg Little. 2006. The methodology and an application to fight against unicode attacks. In SOUPS. 91--101.","DOI":"10.1145\/1143120.1143132"},{"key":"e_1_3_2_2_16_1","volume-title":"Mary Lou Soffa, and Yanjun Qi","author":"Gao Ji","year":"2018","unstructured":"Ji Gao , Jack Lanchantin , Mary Lou Soffa, and Yanjun Qi . 2018 . Black-box generation of adversarial text sequences to evade deep learning classifiers. In SPW. IEEE , 50--56. Ji Gao, Jack Lanchantin, Mary Lou Soffa, and Yanjun Qi. 2018. Black-box generation of adversarial text sequences to evade deep learning classifiers. In SPW. IEEE, 50--56."},{"key":"e_1_3_2_2_17_1","volume-title":"Adversarial texts with gradient methods. arXiv preprint arXiv:1801.07175","author":"Gong Zhitao","year":"2018","unstructured":"Zhitao Gong , Wenlu Wang , Bo Li , Dawn Song , and Wei-Shinn Ku. 2018. Adversarial texts with gradient methods. arXiv preprint arXiv:1801.07175 ( 2018 ). Zhitao Gong, Wenlu Wang, Bo Li, Dawn Song, and Wei-Shinn Ku. 2018. Adversarial texts with gradient methods. arXiv preprint arXiv:1801.07175 (2018)."},{"key":"e_1_3_2_2_18_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"crossref","unstructured":"Daniel Holden Jun Saito Taku Komura and Thomas Joyce. 2015. Learning motion manifolds with convolutional autoencoders. In SIGGRAPH. ACM 18. Daniel Holden Jun Saito Taku Komura and Thomas Joyce. 2015. Learning motion manifolds with convolutional autoencoders. In SIGGRAPH. ACM 18.","DOI":"10.1145\/2820903.2820918"},{"key":"e_1_3_2_2_20_1","volume-title":"Deceiving google's perspective api built for detecting toxic comments. arXiv preprint arXiv:1702.08138","author":"Hosseini Hossein","year":"2017","unstructured":"Hossein Hosseini , Sreeram Kannan , Baosen Zhang , and Radha Poovendran . 2017. Deceiving google's perspective api built for detecting toxic comments. arXiv preprint arXiv:1702.08138 ( 2017 ). Hossein Hosseini, Sreeram Kannan, Baosen Zhang, and Radha Poovendran. 2017. Deceiving google's perspective api built for detecting toxic comments. arXiv preprint arXiv:1702.08138 (2017)."},{"key":"e_1_3_2_2_21_1","unstructured":"Minqing Hu and Bing Liu. 2004. Mining and summarizing customer reviews. In SIGKDD. ACM 168--177. Minqing Hu and Bing Liu. 2004. Mining and summarizing customer reviews. In SIGKDD. ACM 168--177."},{"key":"e_1_3_2_2_22_1","volume-title":"Benjamin IP Rubinstein, and JD Tygar","author":"Huang Ling","year":"2011","unstructured":"Ling Huang , Anthony D Joseph , Blaine Nelson , Benjamin IP Rubinstein, and JD Tygar . 2011 . Adversarial machine learning. In AISec. ACM , 43--58. Ling Huang, Anthony D Joseph, Blaine Nelson, Benjamin IP Rubinstein, and JD Tygar. 2011. Adversarial machine learning. In AISec. ACM, 43--58."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1215"},{"key":"e_1_3_2_2_24_1","volume-title":"Compressing text classification models. arXiv preprint arXiv:1612.03651","author":"Joulin Armand","year":"2016","unstructured":"Armand Joulin , Edouard Grave , Piotr Bojanowski , Matthijs Douze , H\u00e9rve J\u00e9gou , and Tomas Mikolov . 2016. FastText.zip : Compressing text classification models. arXiv preprint arXiv:1612.03651 ( 2016 ). Armand Joulin, Edouard Grave, Piotr Bojanowski, Matthijs Douze, H\u00e9rve J\u00e9gou, and Tomas Mikolov. 2016. FastText.zip: Compressing text classification models. arXiv preprint arXiv:1612.03651 (2016)."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1181"},{"key":"e_1_3_2_2_26_1","unstructured":"Alex Krizhevsky Ilya Sutskever and Geoffrey E Hinton. 2012. Imagenet classification with deep convolutional neural networks. In NeurIPS. 1097--1105. Alex Krizhevsky Ilya Sutskever and Geoffrey E Hinton. 2012. Imagenet classification with deep convolutional neural networks. In NeurIPS. 1097--1105."},{"key":"e_1_3_2_2_27_1","volume-title":"A Visual Analytics Framework for Adversarial Text Generation. arXiv preprint arXiv:1909.11202","author":"Laughlin Brandon","year":"2019","unstructured":"Brandon Laughlin , Christopher Collins , Karthik Sankaranarayanan , and Khalil El-Khatib . 2019. A Visual Analytics Framework for Adversarial Text Generation. arXiv preprint arXiv:1909.11202 ( 2019 ). Brandon Laughlin, Christopher Collins, Karthik Sankaranarayanan, and Khalil El-Khatib. 2019. A Visual Analytics Framework for Adversarial Text Generation. arXiv preprint arXiv:1909.11202 (2019)."},{"key":"e_1_3_2_2_28_1","volume-title":"et almbox. 1995 a. Convolutional networks for images, speech, and time series. The handbook of brain theory and neural networks","author":"LeCun Yann","year":"1995","unstructured":"Yann LeCun , Yoshua Bengio , et almbox. 1995 a. Convolutional networks for images, speech, and time series. The handbook of brain theory and neural networks , Vol. 3361 , 10 ( 1995 ), 1995. Yann LeCun, Yoshua Bengio, et almbox. 1995 a. Convolutional networks for images, speech, and time series. The handbook of brain theory and neural networks, Vol. 3361, 10 (1995), 1995."},{"key":"e_1_3_2_2_29_1","volume-title":"ICANN","volume":"60","author":"LeCun Yann","year":"1995","unstructured":"Yann LeCun , LD Jackel , Leon Bottou , A Brunot , Corinna Cortes , JS Denker , Harris Drucker , I Guyon , UA Muller , Eduard Sackinger , 1995 b. Comparison of learning algorithms for handwritten digit recognition . In ICANN , Vol. 60 . Perth, Australia, 53--60. Yann LeCun, LD Jackel, Leon Bottou, A Brunot, Corinna Cortes, JS Denker, Harris Drucker, I Guyon, UA Muller, Eduard Sackinger, et al. 1995 b. Comparison of learning algorithms for handwritten digit recognition. In ICANN, Vol. 60. Perth, Australia, 53--60."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23138"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/3304222.3304355"},{"key":"e_1_3_2_2_32_1","volume-title":"49th ACL: Human language technologies. ACL, 142--150.","author":"Maas Andrew L","unstructured":"Andrew L Maas , Raymond E Daly , Peter T Pham , Dan Huang , Andrew Y Ng , and Christopher Potts . 2011. Learning word vectors for sentiment analysis . In 49th ACL: Human language technologies. ACL, 142--150. Andrew L Maas, Raymond E Daly, Peter T Pham, Dan Huang, Andrew Y Ng, and Christopher Potts. 2011. Learning word vectors for sentiment analysis. In 49th ACL: Human language technologies. ACL, 142--150."},{"key":"e_1_3_2_2_33_1","volume-title":"42nd ACL. ACL, 271--es.","author":"Pang Bo","unstructured":"Bo Pang and Lillian Lee . 2004. A Sentimental Education: Sentiment Analysis Using Subjectivity Summarization Based on Minimum Cuts . In 42nd ACL. ACL, 271--es. Bo Pang and Lillian Lee. 2004. A Sentimental Education: Sentiment Analysis Using Subjectivity Summarization Based on Minimum Cuts. In 42nd ACL. ACL, 271--es."},{"key":"e_1_3_2_2_34_1","volume-title":"43rd ACL. ACL, 115--124.","author":"Pang Bo","unstructured":"Bo Pang and Lillian Lee . 2005. Seeing stars: Exploiting class relationships for sentiment categorization with respect to rating scales . In 43rd ACL. ACL, 115--124. Bo Pang and Lillian Lee. 2005. Seeing stars: Exploiting class relationships for sentiment categorization with respect to rating scales. In 43rd ACL. ACL, 115--124."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1561\/1500000011"},{"key":"e_1_3_2_2_36_1","volume-title":"ASIACCS","author":"Papernot Nicolas","unstructured":"Nicolas Papernot , Patrick McDaniel , Ian Goodfellow , Somesh Jha , Z. Berkay Celik , and Ananthram Swami . 2017. Practical Black-Box Attacks Against Machine Learning . In ASIACCS . ACM , New York, NY, USA , 506--519. Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2017. Practical Black-Box Attacks Against Machine Learning. In ASIACCS. ACM, New York, NY, USA, 506--519."},{"key":"e_1_3_2_2_37_1","volume-title":"EuroS&P","author":"Papernot Nicolas","unstructured":"Nicolas Papernot , Patrick McDaniel , Somesh Jha , Matt Fredrikson , Z Berkay Celik , and Ananthram Swami . 2016a. The limitations of deep learning in adversarial settings . In EuroS&P . IEEE , 372--387. Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016a. The limitations of deep learning in adversarial settings. In EuroS&P. IEEE, 372--387."},{"key":"e_1_3_2_2_38_1","volume-title":"Crafting adversarial input sequences for recurrent neural networks","author":"Papernot Nicolas","unstructured":"Nicolas Papernot , Patrick McDaniel , Ananthram Swami , and Richard Harang . 2016b. Crafting adversarial input sequences for recurrent neural networks . In MILCOM. IEEE , 49--54. Nicolas Papernot, Patrick McDaniel, Ananthram Swami, and Richard Harang. 2016b. Crafting adversarial input sequences for recurrent neural networks. In MILCOM. IEEE, 49--54."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.3390\/app10228079"},{"key":"e_1_3_2_2_40_1","volume-title":"Glove: Global vectors for word representation. In EMNLP. 1532--1543.","author":"Pennington Jeffrey","year":"2014","unstructured":"Jeffrey Pennington , Richard Socher , and Christopher Manning . 2014 . Glove: Global vectors for word representation. In EMNLP. 1532--1543. Jeffrey Pennington, Richard Socher, and Christopher Manning. 2014. Glove: Global vectors for word representation. In EMNLP. 1532--1543."},{"key":"e_1_3_2_2_41_1","volume-title":"Fanny Yang, John C Duchi, and Percy Liang.","author":"Raghunathan Aditi","year":"2019","unstructured":"Aditi Raghunathan , Sang Michael Xie , Fanny Yang, John C Duchi, and Percy Liang. 2019 . Adversarial training can hurt generalization. arXiv preprint arXiv:1906.06032 (2019). Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C Duchi, and Percy Liang. 2019. Adversarial training can hurt generalization. arXiv preprint arXiv:1906.06032 (2019)."},{"key":"e_1_3_2_2_43_1","volume-title":"Towards crafting text adversarial samples. arXiv preprint arXiv:1707.02812","author":"Samanta Suranjana","year":"2017","unstructured":"Suranjana Samanta and Sameep Mehta . 2017. Towards crafting text adversarial samples. arXiv preprint arXiv:1707.02812 ( 2017 ). Suranjana Samanta and Sameep Mehta. 2017. Towards crafting text adversarial samples. arXiv preprint arXiv:1707.02812 (2017)."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"crossref","unstructured":"David Sculley Gabriel Wachman and Carla E Brodley. 2006. Spam Filtering Using Inexact String Matching in Explicit Feature Space with On-Line Linear Classifiers.. In TREC. David Sculley Gabriel Wachman and Carla E Brodley. 2006. Spam Filtering Using Inexact String Matching in Explicit Feature Space with On-Line Linear Classifiers.. In TREC.","DOI":"10.6028\/NIST.SP.500-272.spam-tufts.sculley"},{"key":"e_1_3_2_2_45_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 ( 2013 ). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_2_46_1","volume-title":"Adversarial attacks and defenses in images, graphs and text: A review. arXiv preprint arXiv:1909.08072","author":"Xu Han","year":"2019","unstructured":"Han Xu , Yao Ma , Haochen Liu , Debayan Deb , Hui Liu , Jiliang Tang , and Anil Jain . 2019. Adversarial attacks and defenses in images, graphs and text: A review. arXiv preprint arXiv:1909.08072 ( 2019 ). Han Xu, Yao Ma, Haochen Liu, Debayan Deb, Hui Liu, Jiliang Tang, and Anil Jain. 2019. Adversarial attacks and defenses in images, graphs and text: A review. arXiv preprint arXiv:1909.08072 (2019)."},{"key":"e_1_3_2_2_47_1","unstructured":"Xiang Zhang Junbo Zhao and Yann LeCun. 2015. Character-level convolutional networks for text classification. In NIPS. 649--657. Xiang Zhang Junbo Zhao and Yann LeCun. 2015. Character-level convolutional networks for text classification. In NIPS. 649--657."},{"key":"e_1_3_2_2_48_1","unstructured":"Ye Zhang and Byron Wallace. 2017. A Sensitivity Analysis of (and Practitioners' Guide to) Convolutional Neural Networks for Sentence Classification. In IJCNLP. AFNLP Taipei Taiwan 253--263. Ye Zhang and Byron Wallace. 2017. A Sensitivity Analysis of (and Practitioners' Guide to) Convolutional Neural Networks for Sentence Classification. In IJCNLP. AFNLP Taipei Taiwan 253--263."},{"key":"e_1_3_2_2_49_1","volume-title":"ICLR","author":"Zhao Zhengli","year":"2018","unstructured":"Zhengli Zhao , Dheeru Dua , and Sameer Singh . 2018. Generating natural adversarial examples . in ICLR ( 2018 ). Zhengli Zhao, Dheeru Dua, and Sameer Singh. 2018. Generating natural adversarial examples. in ICLR (2018)."}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event Republic of Korea","acronym":"CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3474369.3486871","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3474369.3486871","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:30:26Z","timestamp":1750188626000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3474369.3486871"}},"subtitle":["Evading NLP Systems Using Visual Similarities of Text Characters"],"short-title":[],"issued":{"date-parts":[[2021,11,15]]},"references-count":48,"alternative-id":["10.1145\/3474369.3486871","10.1145\/3474369"],"URL":"https:\/\/doi.org\/10.1145\/3474369.3486871","relation":{},"subject":[],"published":{"date-parts":[[2021,11,15]]},"assertion":[{"value":"2021-11-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}