Saved in:
Bibliographic Details
Main Authors: Chang, Hao-Yuan, Wang, Kang L.
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2410.12759
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912074697801728
author Chang, Hao-Yuan
Wang, Kang L.
author_facet Chang, Hao-Yuan
Wang, Kang L.
contents Recent developments in adversarial attacks on deep learning leave many mission-critical natural language processing (NLP) systems at risk of exploitation. To address the lack of computationally efficient adversarial defense methods, this paper reports a novel, universal technique that drastically improves the robustness of Bidirectional Encoder Representations from Transformers (BERT) by combining the unitary weights with the multi-margin loss. We discover that the marriage of these two simple ideas amplifies the protection against malicious interference. Our model, the unitary multi-margin BERT (UniBERT), boosts post-attack classification accuracies significantly by 5.3% to 73.8% while maintaining competitive pre-attack accuracies. Furthermore, the pre-attack and post-attack accuracy tradeoff can be adjusted via a single scalar parameter to best fit the design requirements for the target applications.
format Preprint
id arxiv_https___arxiv_org_abs_2410_12759
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Unitary Multi-Margin BERT for Robust Natural Language Processing
Chang, Hao-Yuan
Wang, Kang L.
Computation and Language
Artificial Intelligence
Recent developments in adversarial attacks on deep learning leave many mission-critical natural language processing (NLP) systems at risk of exploitation. To address the lack of computationally efficient adversarial defense methods, this paper reports a novel, universal technique that drastically improves the robustness of Bidirectional Encoder Representations from Transformers (BERT) by combining the unitary weights with the multi-margin loss. We discover that the marriage of these two simple ideas amplifies the protection against malicious interference. Our model, the unitary multi-margin BERT (UniBERT), boosts post-attack classification accuracies significantly by 5.3% to 73.8% while maintaining competitive pre-attack accuracies. Furthermore, the pre-attack and post-attack accuracy tradeoff can be adjusted via a single scalar parameter to best fit the design requirements for the target applications.
title Unitary Multi-Margin BERT for Robust Natural Language Processing
topic Computation and Language
Artificial Intelligence
url https://arxiv.org/abs/2410.12759