{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/adversarial-text/papers/ran/1","list_of":"/task/adversarial-text","task":"Adversarial Text","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"ran","order_definition":"only papers where Syntology ran at least one harvested sample; date (newest first), ties by arXiv id","caption":"We ran code from the paper's repository; we did not run it on this task or check it against the task's benchmarks.","absence":"A paper missing from this list is not a recorded non-run: it may have no arXiv id, no harvested code, or only samples that have not run yet.","page":1,"pages_in_order":1,"rows_per_page":100,"rows":[1,16],"of":16,"counts":{"archive_papers_tagged":114,"with_a_code_link":51,"where_syntology_ran_a_sample":16,"not_listed_spam_title":0,"listed":114,"listed_where_code_ran":16,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":13,"every_run_a_failure_of_syntologys_instrument":3,"listed_with_a_run_with_no_instrument_failure":13,"listed_every_run_a_failure_of_syntologys_instrument":3,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/adversarial-text/papers/ran/1","prev":null,"next":null,"papers":[{"url":"/paper/adversarial-attacks-on-multimodal-agents","slug":"adversarial-attacks-on-multimodal-agents","title":"Dissecting Adversarial Robustness of Multimodal LM Agents","date":"2024-06-18","arxiv_id":"2406.12814","repositories_listed":1,"syntology":{"n":21,"n_ran":16,"n_constructed":0,"n_ran_checked":11,"n_instrument":5,"n_unverified":5,"n_honours":0,"n_violates":0,"n_no_contract":11,"n_pointer_only":1,"phrase":"16 ran (of which 0 constructed an object rather than computing a result; 11 with no instrument failure: 0 honoured, 0 violated, 11 with no contract checked; 5 where Syntology's instrument failed) · 5 unverified","sample_list":"/paper/adversarial-attacks-on-multimodal-agents#ran","syntology_url":"https://syntology.ai/paper/2406.12814","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2406.12814"}},"official":{"repos":["chenwu98/agent-attack"],"state":"official (archive's flag): 16 ran","n_ran":16,"n_constructed":0,"n_ran_no_instrument_failure":11,"n_unverified":5,"ran_from_kinds":["official"]}}},{"url":"/paper/white-box-multimodal-jailbreaks-against-large","slug":"white-box-multimodal-jailbreaks-against-large","title":"White-box Multimodal Jailbreaks Against Large Vision-Language Models","date":"2024-05-28","arxiv_id":"2405.17894","repositories_listed":1,"syntology":{"n":5,"n_ran":4,"n_constructed":0,"n_ran_checked":1,"n_instrument":3,"n_unverified":1,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":5,"phrase":"4 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 3 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/white-box-multimodal-jailbreaks-against-large#ran","syntology_url":"https://syntology.ai/paper/2405.17894","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2405.17894"}},"official":{"repos":["roywang021/UMK"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/revisiting-the-adversarial-robustness-of","slug":"revisiting-the-adversarial-robustness-of","title":"Revisiting the Adversarial Robustness of Vision Language Models: a Multimodal Perspective","date":"2024-04-30","arxiv_id":"2404.19287","repositories_listed":1,"syntology":{"n":22,"n_ran":18,"n_constructed":0,"n_ran_checked":12,"n_instrument":6,"n_unverified":4,"n_honours":1,"n_violates":0,"n_no_contract":11,"n_pointer_only":5,"phrase":"18 ran (of which 0 constructed an object rather than computing a result; 12 with no instrument failure: 1 honoured, 0 violated, 11 with no contract checked; 6 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/revisiting-the-adversarial-robustness-of#ran","syntology_url":"https://syntology.ai/paper/2404.19287","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2404.19287"}},"official":{"repos":["ellezwq/mmcoa"],"state":"official (archive's flag): 18 ran","n_ran":18,"n_constructed":0,"n_ran_no_instrument_failure":12,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/few-shot-adversarial-prompt-learning-on","slug":"few-shot-adversarial-prompt-learning-on","title":"Few-Shot Adversarial Prompt Learning on Vision-Language Models","date":"2024-03-21","arxiv_id":"2403.14774","repositories_listed":1,"syntology":{"n":9,"n_ran":5,"n_constructed":0,"n_ran_checked":0,"n_instrument":5,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 5 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/few-shot-adversarial-prompt-learning-on#ran","syntology_url":"https://syntology.ai/paper/2403.14774","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2403.14774"}},"official":{"repos":["lionel-w2/fap"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/bert-lost-patience-won-t-be-robust-to-1","slug":"bert-lost-patience-won-t-be-robust-to-1","title":"BERT Lost Patience Won't Be Robust to Adversarial Slowdown","date":"2023-10-29","arxiv_id":"2310.19152","repositories_listed":1,"syntology":{"n":5,"n_ran":3,"n_constructed":0,"n_ran_checked":2,"n_instrument":1,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":1,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/bert-lost-patience-won-t-be-robust-to-1#ran","syntology_url":"https://syntology.ai/paper/2310.19152","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2310.19152"}},"official":{"repos":["ztcoalson/waffle"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/a-pilot-study-of-query-free-adversarial","slug":"a-pilot-study-of-query-free-adversarial","title":"A Pilot Study of Query-Free Adversarial Attack against Stable Diffusion","date":"2023-03-29","arxiv_id":"2303.16378","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":1,"n_instrument":2,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/a-pilot-study-of-query-free-adversarial#ran","syntology_url":"https://syntology.ai/paper/2303.16378","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.16378"}},"official":{"repos":["optml-group/qf-attack"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/retvec-resilient-and-efficient-text","slug":"retvec-resilient-and-efficient-text","title":"RETVec: Resilient and Efficient Text Vectorizer","date":"2023-02-18","arxiv_id":"2302.09207","repositories_listed":1,"syntology":{"n":7,"n_ran":3,"n_constructed":2,"n_ran_checked":2,"n_instrument":1,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":0,"phrase":"3 ran (of which 2 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 1 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/retvec-resilient-and-efficient-text#ran","syntology_url":"https://syntology.ai/paper/2302.09207","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.09207"}},"official":{"repos":["google-research/retvec"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":2,"n_ran_no_instrument_failure":2,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/ignore-previous-prompt-attack-techniques-for","slug":"ignore-previous-prompt-attack-techniques-for","title":"Ignore Previous Prompt: Attack Techniques For Language Models","date":"2022-11-17","arxiv_id":"2211.09527","repositories_listed":1,"syntology":{"n":6,"n_ran":2,"n_constructed":0,"n_ran_checked":2,"n_instrument":0,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":0,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 0 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/ignore-previous-prompt-attack-techniques-for#ran","syntology_url":"https://syntology.ai/paper/2211.09527","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2211.09527"}},"official":{"repos":["agencyenterprise/promptinject"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/semattack-natural-textual-attacks-via-1","slug":"semattack-natural-textual-attacks-via-1","title":"SemAttack: Natural Textual Attacks via Different Semantic Spaces","date":"2022-05-03","arxiv_id":"2205.01287","repositories_listed":1,"syntology":{"n":3,"n_ran":2,"n_constructed":0,"n_ran_checked":1,"n_instrument":1,"n_unverified":1,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/semattack-natural-textual-attacks-via-1#ran","syntology_url":"https://syntology.ai/paper/2205.01287","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2205.01287"}},"official":{"repos":["ai-secure/semattack"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/generating-natural-language-attacks-in-a-hard","slug":"generating-natural-language-attacks-in-a-hard","title":"Generating Natural Language Attacks in a Hard Label Black Box Setting","date":"2020-12-29","arxiv_id":"2012.14956","repositories_listed":3,"syntology":{"n":6,"n_ran":6,"n_constructed":0,"n_ran_checked":1,"n_instrument":5,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":6,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 5 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/generating-natural-language-attacks-in-a-hard#ran","syntology_url":"https://syntology.ai/paper/2012.14956","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2012.14956"}},"official":{"repos":["RishabhMaheshwary/hard-label-attack"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["listed","official"]}}},{"url":"/paper/end-to-end-adversarial-text-to-speech","slug":"end-to-end-adversarial-text-to-speech","title":"End-to-End Adversarial Text-to-Speech","date":"2020-06-05","arxiv_id":"2006.03575","repositories_listed":2,"syntology":{"n":12,"n_ran":10,"n_constructed":7,"n_ran_checked":10,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":10,"n_pointer_only":12,"phrase":"10 ran (of which 7 constructed an object rather than computing a result; 10 with no instrument failure: 0 honoured, 0 violated, 10 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/end-to-end-adversarial-text-to-speech#ran","syntology_url":"https://syntology.ai/paper/2006.03575","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2006.03575"}},"official":null}},{"url":"/paper/is-bert-really-robust-natural-language-attack","slug":"is-bert-really-robust-natural-language-attack","title":"Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and Entailment","date":"2019-07-27","arxiv_id":"1907.11932","repositories_listed":7,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":0,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/is-bert-really-robust-natural-language-attack#ran","syntology_url":"https://syntology.ai/paper/1907.11932","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1907.11932"}},"official":{"repos":["jind11/TextFooler"],"state":"official: no sample here; runs from other or unrecorded repositories","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["unlocated"]}}},{"url":"/paper/discrete-attacks-and-submodular-optimization","slug":"discrete-attacks-and-submodular-optimization","title":"Discrete Adversarial Attacks and Submodular Optimization with Applications to Text Classification","date":"2018-12-01","arxiv_id":"1812.00151","repositories_listed":1,"syntology":{"n":3,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":2,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/discrete-attacks-and-submodular-optimization#ran","syntology_url":"https://syntology.ai/paper/1812.00151","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1812.00151"}},"official":{"repos":["cecilialeiqi/adversarial_text"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-text-generation-via-feature","slug":"adversarial-text-generation-via-feature","title":"Adversarial Text Generation via Feature-Mover's Distance","date":"2018-09-17","arxiv_id":"1809.06297","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/adversarial-text-generation-via-feature#ran","syntology_url":"https://syntology.ai/paper/1809.06297","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1809.06297"}},"official":null}},{"url":"/paper/black-box-generation-of-adversarial-text","slug":"black-box-generation-of-adversarial-text","title":"Black-box Generation of Adversarial Text Sequences to Evade Deep Learning Classifiers","date":"2018-01-13","arxiv_id":"1801.04354","repositories_listed":2,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":0,"n_honours":2,"n_violates":1,"n_no_contract":0,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 2 honoured, 1 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/black-box-generation-of-adversarial-text#ran","syntology_url":"https://syntology.ai/paper/1801.04354","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1801.04354"}},"official":{"repos":["QData/deepWordBug"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/generative-adversarial-text-to-image","slug":"generative-adversarial-text-to-image","title":"Generative Adversarial Text to Image Synthesis","date":"2016-05-17","arxiv_id":"1605.05396","repositories_listed":39,"syntology":{"n":19,"n_ran":15,"n_constructed":0,"n_ran_checked":8,"n_instrument":7,"n_unverified":4,"n_honours":1,"n_violates":0,"n_no_contract":7,"n_pointer_only":6,"phrase":"15 ran (of which 0 constructed an object rather than computing a result; 8 with no instrument failure: 1 honoured, 0 violated, 7 with no contract checked; 7 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/generative-adversarial-text-to-image#ran","syntology_url":"https://syntology.ai/paper/1605.05396","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1605.05396"}},"official":{"repos":["reedscot/icml2016"],"state":"official: no sample here; runs from other or unrecorded repositories","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["listed","unlocated"]}}}],"record_sha256":"17856c1a0794853da450c8fe97392921fb502e099122a3fa1be284878086c598","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}