{"url":"/task/adversarial-text","name":"Adversarial Text","slug":"adversarial-text","description_markdown":"Adversarial Text refers to a specialised text sequence that is designed specifically to influence the prediction of a language model. Generally, Adversarial Text attack are carried out on Large Language Models (LLMs). Research on understanding different adversarial approaches can help us build effective defense mechanisms to detect malicious text input and build robust language models.","categories":[{"name":"Adversarial","url":"/area/adversarial"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":114,"papers_with_code":51,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":2,"subtasks":0,"parent_tasks":1},"benchmarks":[],"datasets":[{"url":"/dataset/harmfultasks","name":"HarmfulTasks","full_name":"Harmful and Malicious Tasks for LLMs in Jailbreaking Prompts","num_papers_in_archive":1},{"url":"/dataset/texygen-platform","name":"Texygen Platform","full_name":"","num_papers_in_archive":1}],"subtasks":[],"parent_tasks":[{"url":"/task/adversarial-attack","name":"Adversarial Attack"}],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":51,"tagged_in_all":114,"items":[{"url":"/paper/generative-adversarial-text-to-image","title":"Generative Adversarial Text to Image Synthesis","date":"2016-05-17","arxiv_id":"1605.05396","repositories_listed":39,"syntology":{"n":19,"n_ran":9,"n_unverified":10,"n_pointer_only":6}},{"url":"/paper/is-bert-really-robust-natural-language-attack","title":"Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment","date":"2019-07-27","arxiv_id":"1907.11932","repositories_listed":7,"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":2}},{"url":"/paper/retsim-resilient-and-efficient-text","title":"RETSim: Resilient and Efficient Text Similarity","date":"2023-11-28","arxiv_id":"2311.17264","repositories_listed":3,"syntology":null},{"url":"/paper/generating-natural-language-attacks-in-a-hard","title":"Generating Natural Language Attacks in a Hard Label Black Box Setting","date":"2020-12-29","arxiv_id":"2012.14956","repositories_listed":3,"syntology":{"n":6,"n_ran":6,"n_unverified":0,"n_pointer_only":6}},{"url":"/paper/advcodec-towards-a-unified-framework-for-1","title":"T3: Tree-Autoencoder Constrained Adversarial Text Generation for Targeted Attack","date":"2019-12-22","arxiv_id":"1912.10375","repositories_listed":3,"syntology":null},{"url":"/paper/semantic-preserving-adversarial-text-attacks","title":"Semantic-Preserving Adversarial Text Attacks","date":"2021-08-23","arxiv_id":"2108.10015","repositories_listed":2,"syntology":null},{"url":"/paper/searching-for-a-search-method-benchmarking","title":"Searching for a Search Method: Benchmarking Search Algorithms for Generating NLP Adversarial Examples","date":"2020-09-09","arxiv_id":"2009.06368","repositories_listed":2,"syntology":null},{"url":"/paper/end-to-end-adversarial-text-to-speech","title":"End-to-End Adversarial Text-to-Speech","date":"2020-06-05","arxiv_id":"2006.03575","repositories_listed":2,"syntology":{"n":12,"n_ran":9,"n_unverified":3,"n_pointer_only":12}},{"url":"/paper/textattack-a-framework-for-adversarial","title":"TextAttack: A Framework for Adversarial Attacks, Data Augmentation, and Adversarial Training in NLP","date":"2020-04-29","arxiv_id":"2005.05909","repositories_listed":2,"syntology":null},{"url":"/paper/bae-bert-based-adversarial-examples-for-text","title":"BAE: BERT-based Adversarial Examples for Text Classification","date":"2020-04-04","arxiv_id":"2004.01970","repositories_listed":2,"syntology":null},{"url":"/paper/black-box-generation-of-adversarial-text","title":"Black-box Generation of Adversarial Text Sequences to Evade Deep Learning Classifiers","date":"2018-01-13","arxiv_id":"1801.04354","repositories_listed":2,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/stealthrank-llm-ranking-manipulation-via","title":"StealthRank: LLM Ranking Manipulation via Stealthy Prompt Optimization","date":"2025-04-08","arxiv_id":"2504.05804","repositories_listed":1,"syntology":null},{"url":"/paper/breaking-bert-gradient-attack-on-twitter","title":"Breaking BERT: Gradient Attack on Twitter Sentiment Analysis for Targeted Misclassification","date":"2025-04-02","arxiv_id":"2504.01345","repositories_listed":1,"syntology":null},{"url":"/paper/smab-mab-based-word-sensitivity-estimation","title":"SMAB: MAB based word Sensitivity Estimation Framework and its Applications in Adversarial Text Generation","date":"2025-02-10","arxiv_id":"2502.07101","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_unverified":1,"n_pointer_only":0}},{"url":"/paper/empra-embedding-perturbation-rank-attack","title":"EMPRA: Embedding Perturbation Rank Attack against Neural Ranking Models","date":"2024-12-20","arxiv_id":"2412.16382","repositories_listed":1,"syntology":null},{"url":"/paper/binaryselect-to-improve-accessibility-of","title":"BinarySelect to Improve Accessibility of Black-Box Attack Research","date":"2024-12-13","arxiv_id":"2412.10617","repositories_listed":1,"syntology":null},{"url":"/paper/tscheater-generating-high-quality-tibetan","title":"TSCheater: Generating High-Quality Tibetan Adversarial Texts via Visual Similarity","date":"2024-12-03","arxiv_id":"2412.02371","repositories_listed":1,"syntology":null},{"url":"/paper/nmt-obfuscator-attack-ignore-a-sentence-in","title":"NMT-Obfuscator Attack: Ignore a sentence in translation with only one word","date":"2024-11-19","arxiv_id":"2411.12473","repositories_listed":1,"syntology":null},{"url":"/paper/advi2i-adversarial-image-attack-on-image-to","title":"AdvI2I: Adversarial Image Attack on Image-to-Image Diffusion models","date":"2024-10-28","arxiv_id":"2410.21471","repositories_listed":1,"syntology":null},{"url":"/paper/controlled-generation-of-natural-adversarial","title":"Adversarial Decoding: Generating Readable Documents for Adversarial Objectives","date":"2024-10-03","arxiv_id":"2410.02163","repositories_listed":1,"syntology":null},{"url":"/paper/vision-fused-attack-advancing-aggressive-and","title":"Vision-fused Attack: Advancing Aggressive and Stealthy Adversarial Text against Neural Machine Translation","date":"2024-09-08","arxiv_id":"2409.05021","repositories_listed":1,"syntology":{"n":4,"n_ran":0,"n_unverified":4,"n_pointer_only":4}},{"url":"/paper/2408-00312","title":"Adversarial Text Rewriting for Text-aware Recommender Systems","date":"2024-08-01","arxiv_id":"2408.00312","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-attacks-on-multimodal-agents","title":"Dissecting Adversarial Robustness of Multimodal LM Agents","date":"2024-06-18","arxiv_id":"2406.12814","repositories_listed":1,"syntology":{"n":21,"n_ran":16,"n_unverified":5,"n_pointer_only":0}},{"url":"/paper/white-box-multimodal-jailbreaks-against-large","title":"White-box Multimodal Jailbreaks Against Large Vision-Language Models","date":"2024-05-28","arxiv_id":"2405.17894","repositories_listed":1,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":5}},{"url":"/paper/revisiting-the-adversarial-robustness-of","title":"Revisiting the Adversarial Robustness of Vision Language Models: a Multimodal Perspective","date":"2024-04-30","arxiv_id":"2404.19287","repositories_listed":1,"syntology":{"n":22,"n_ran":14,"n_unverified":8,"n_pointer_only":0}},{"url":"/paper/few-shot-adversarial-prompt-learning-on","title":"Few-Shot Adversarial Prompt Learning on Vision-Language Models","date":"2024-03-21","arxiv_id":"2403.14774","repositories_listed":1,"syntology":{"n":9,"n_ran":5,"n_unverified":4,"n_pointer_only":0}},{"url":"/paper/boosting-transferability-in-vision-language","title":"Boosting Transferability in Vision-Language Attacks via Diversification along the Intersection Region of Adversarial Trajectory","date":"2024-03-19","arxiv_id":"2403.12445","repositories_listed":1,"syntology":null},{"url":"/paper/a-curious-case-of-searching-for-the","title":"A Curious Case of Searching for the Correlation between Training Data and Adversarial Robustness of Transformer Textual Models","date":"2024-02-18","arxiv_id":"2402.11469","repositories_listed":1,"syntology":null},{"url":"/paper/arabic-synonym-bert-based-adversarial","title":"Arabic Synonym BERT-based Adversarial Examples for Text Classification","date":"2024-02-05","arxiv_id":"2402.03477","repositories_listed":1,"syntology":null},{"url":"/paper/bert-lost-patience-won-t-be-robust-to-1","title":"BERT Lost Patience Won't Be Robust to Adversarial Slowdown","date":"2023-10-29","arxiv_id":"2310.19152","repositories_listed":1,"syntology":{"n":5,"n_ran":3,"n_unverified":2,"n_pointer_only":0}}],"syntology_records":12,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}