Multi-granular Adversarial Attacks against Black-box Neural Ranking Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Yu-An, Zhang, Ruqing, Guo, Jiafeng, de Rijke, Maarten, Fan, Yixing, Cheng, Xueqi
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914748667265024
author Liu, Yu-An
Zhang, Ruqing
Guo, Jiafeng
de Rijke, Maarten
Fan, Yixing
Cheng, Xueqi
author_facet Liu, Yu-An
Zhang, Ruqing
Guo, Jiafeng
de Rijke, Maarten
Fan, Yixing
Cheng, Xueqi
contents Adversarial ranking attacks have gained increasing attention due to their success in probing vulnerabilities, and, hence, enhancing the robustness, of neural ranking models. Conventional attack methods employ perturbations at a single granularity, e.g., word or sentence level, to target documents. However, limiting perturbations to a single level of granularity may reduce the flexibility of adversarial examples, thereby diminishing the potential threat of the attack. Therefore, we focus on generating high-quality adversarial examples by incorporating multi-granular perturbations. Achieving this objective involves tackling a combinatorial explosion problem, which requires identifying an optimal combination of perturbations across all possible levels of granularity, positions, and textual pieces. To address this challenge, we transform the multi-granular adversarial attack into a sequential decision-making process, where perturbations in the next attack step build on the perturbed document in the current attack step. Since the attack process can only access the final state without direct intermediate signals, we use reinforcement learning to perform multi-granular attacks. During the reinforcement learning process, two agents work cooperatively to identify multi-granular vulnerabilities as attack targets and organize perturbation candidates into a final perturbation sequence. Experimental results show that our attack method surpasses prevailing baselines in both attack effectiveness and imperceptibility.
format Preprint
id arxiv_https___arxiv_org_abs_2404_01574
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Multi-granular Adversarial Attacks against Black-box Neural Ranking Models
Liu, Yu-An
Zhang, Ruqing
Guo, Jiafeng
de Rijke, Maarten
Fan, Yixing
Cheng, Xueqi
Information Retrieval
Cryptography and Security
Machine Learning
Adversarial ranking attacks have gained increasing attention due to their success in probing vulnerabilities, and, hence, enhancing the robustness, of neural ranking models. Conventional attack methods employ perturbations at a single granularity, e.g., word or sentence level, to target documents. However, limiting perturbations to a single level of granularity may reduce the flexibility of adversarial examples, thereby diminishing the potential threat of the attack. Therefore, we focus on generating high-quality adversarial examples by incorporating multi-granular perturbations. Achieving this objective involves tackling a combinatorial explosion problem, which requires identifying an optimal combination of perturbations across all possible levels of granularity, positions, and textual pieces. To address this challenge, we transform the multi-granular adversarial attack into a sequential decision-making process, where perturbations in the next attack step build on the perturbed document in the current attack step. Since the attack process can only access the final state without direct intermediate signals, we use reinforcement learning to perform multi-granular attacks. During the reinforcement learning process, two agents work cooperatively to identify multi-granular vulnerabilities as attack targets and organize perturbation candidates into a final perturbation sequence. Experimental results show that our attack method surpasses prevailing baselines in both attack effectiveness and imperceptibility.
title Multi-granular Adversarial Attacks against Black-box Neural Ranking Models
topic Information Retrieval
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2404.01574