Papers › Adversarial GLUE: A Multi-Task Benchmark for Robustness Evaluation of Language Models

Adversarial GLUE: A Multi-Task Benchmark for Robustness Evaluation of Language Models

4 Nov 2021arXiv:2111.02840archive 2025-07-28

Boxin Wang, Chejian Xu, Shuohang Wang, Zhe Gan, Yu Cheng, Jianfeng Gao, Ahmed Hassan Awadallah, Bo Li

Large-scale pre-trained language models have achieved tremendous success across a wide range of natural language understanding (NLU) tasks, even surpassing human performance. However, recent studies reveal that the robustness of these models can be challenged by carefully crafted textual adversarial examples. While several individual datasets have been proposed to evaluate model robustness, a principled and comprehensive benchmark is still missing. In this paper, we present Adversarial GLUE (AdvGLUE), a new multi-task benchmark to quantitatively and thoroughly explore and evaluate the vulnerabilities of modern large-scale language models under various types of adversarial attacks. In particular, we systematically apply 14 textual adversarial attack methods to GLUE tasks to construct AdvGLUE, which is further validated by humans for reliable annotations. Our findings are summarized as follows. (i) Most existing adversarial attack algorithms are prone to generating invalid or ambiguous adversarial examples, with around 90% of them either changing the original semantic meanings or misleading human annotators as well. Therefore, we perform a careful filtering process to curate a high-quality benchmark. (ii) All the language models and robust training methods we tested perform poorly on AdvGLUE, with scores lagging far behind the benign accuracy. We hope our work will motivate the development of new adversarial attacks that are more stealthy and semantic-preserving, as well as new robust language models against sophisticated adversarial attacks. AdvGLUE is available at https://adversarialglue.github.io.

PaperPDFCode

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

Code

ai-secure/adversarial-glue mentioned on GitHubpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

Adversarial AttackAdversarial RobustnessNatural Language Understanding

Datasets

Introduced by this paper, per the archive.

AdvGLUE

Results from the paper archive 2025-07-28

TaskDatasetModelMetricValueRank at snapshotLeaderboardReport
Adversarial Robustness AdvGLUE DeBERTa (single model) Accuracy 0.6086 #1 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE ALBERT (single model) Accuracy 0.5922 #2 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE T5 (single model) Accuracy 0.5682 #3 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE SMART_RoBERTa (single model) Accuracy 0.5371 #4 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE FreeLB (single model) Accuracy 0.5048 #5 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE RoBERTa (single model) Accuracy 0.5021 #6 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE InfoBERT (single model) Accuracy 0.4603 #7 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE ELECTRA (single model) Accuracy 0.4169 #8 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE BERT (single model) Accuracy 0.3369 #9 of 10 Archive leaderboard report
Adversarial Robustness AdvGLUE SMART_BERT (single model) Accuracy 0.3029 #10 of 10 Archive leaderboard report

Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections