{"id":"https://openalex.org/W2777353073","doi":"https://doi.org/10.18653/v1/p18-2006","title":"HotFlip: White-Box Adversarial Examples for NLP","display_name":"HotFlip: White-Box Adversarial Examples for NLP","publication_year":2017,"publication_date":"2017-12-19","ids":{"openalex":"https://openalex.org/W2777353073","doi":"https://doi.org/10.18653/v1/p18-2006","mag":"2777353073"},"language":"en","primary_location":{"id":"mag:2777353073","is_oa":true,"landing_page_url":"https://arxiv.org/abs/1712.06751v1","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},"type":"article","indexed_in":[],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/1712.06751v1","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5074501098","display_name":"Javid Ebrahimi","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Javid Ebrahimi","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067715162","display_name":"Anyi Rao","orcid":"https://orcid.org/0000-0003-1004-7753"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Anyi Rao","raw_affiliation_strings":[],"raw_orcid":"https://orcid.org/0000-0003-1004-7753","affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053373401","display_name":"Daniel Lowd","orcid":"https://orcid.org/0000-0002-9501-0361"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Daniel Lowd","raw_affiliation_strings":[],"raw_orcid":"https://orcid.org/0000-0002-9501-0361","affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5021332177","display_name":"Dejing Dou","orcid":"https://orcid.org/0000-0003-2949-6874"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Dejing Dou","raw_affiliation_strings":[],"raw_orcid":"https://orcid.org/0000-0003-2949-6874","affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5074501098"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":5.82,"has_fulltext":true,"cited_by_count":39,"citation_normalized_percentile":{"value":0.9683666,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11242","display_name":"Nuclear Materials and Properties","score":0.9168999791145325,"subfield":{"id":"https://openalex.org/subfields/2505","display_name":"Materials Chemistry"},"field":{"id":"https://openalex.org/fields/25","display_name":"Materials Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9352856874465942},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.7279493808746338},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7219523191452026},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6768988370895386},{"id":"https://openalex.org/keywords/machine-translation","display_name":"Machine translation","score":0.6606984734535217},{"id":"https://openalex.org/keywords/character","display_name":"Character (mathematics)","score":0.5929564237594604},{"id":"https://openalex.org/keywords/word","display_name":"Word (group theory)","score":0.5799373984336853},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.47220784425735474},{"id":"https://openalex.org/keywords/translation","display_name":"Translation (biology)","score":0.4677852392196655},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.4250054657459259},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.39870020747184753},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.11499273777008057}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9352856874465942},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.7279493808746338},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7219523191452026},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6768988370895386},{"id":"https://openalex.org/C203005215","wikidata":"https://www.wikidata.org/wiki/Q79798","display_name":"Machine translation","level":2,"score":0.6606984734535217},{"id":"https://openalex.org/C2780861071","wikidata":"https://www.wikidata.org/wiki/Q1062934","display_name":"Character (mathematics)","level":2,"score":0.5929564237594604},{"id":"https://openalex.org/C90805587","wikidata":"https://www.wikidata.org/wiki/Q10944557","display_name":"Word (group theory)","level":2,"score":0.5799373984336853},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.47220784425735474},{"id":"https://openalex.org/C149364088","wikidata":"https://www.wikidata.org/wiki/Q185917","display_name":"Translation (biology)","level":4,"score":0.4677852392196655},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.4250054657459259},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.39870020747184753},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.11499273777008057},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C105580179","wikidata":"https://www.wikidata.org/wiki/Q188928","display_name":"Messenger RNA","level":3,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"mag:2777353073","is_oa":true,"landing_page_url":"https://arxiv.org/abs/1712.06751v1","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"pmh:oai:repository.hkust.edu.hk:1783.1-141779","is_oa":false,"landing_page_url":"http://repository.hkust.edu.hk/ir/Record/1783.1-141779","pdf_url":null,"source":{"id":"https://openalex.org/S4306401796","display_name":"Rare & Special e-Zone (The Hong Kong University of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I200769079","host_organization_name":"Hong Kong University of Science and Technology","host_organization_lineage":["https://openalex.org/I200769079"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference paper"}],"best_oa_location":{"id":"mag:2777353073","is_oa":true,"landing_page_url":"https://arxiv.org/abs/1712.06751v1","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":13,"referenced_works":["https://openalex.org/W1902237438","https://openalex.org/W2095705004","https://openalex.org/W2101105183","https://openalex.org/W2251939518","https://openalex.org/W2281420995","https://openalex.org/W2594590228","https://openalex.org/W2963207607","https://openalex.org/W2963696733","https://openalex.org/W2963834268","https://openalex.org/W2963969878","https://openalex.org/W2964153729","https://openalex.org/W2964253222","https://openalex.org/W2964308564"],"related_works":["https://openalex.org/W2964153729","https://openalex.org/W2963969878","https://openalex.org/W2963207607","https://openalex.org/W2963834268","https://openalex.org/W2963661177","https://openalex.org/W2963341956","https://openalex.org/W2962718684","https://openalex.org/W2799007037","https://openalex.org/W2964253222","https://openalex.org/W2962818281","https://openalex.org/W2963126845","https://openalex.org/W2735135478","https://openalex.org/W3018911559","https://openalex.org/W2963748441","https://openalex.org/W2962713901","https://openalex.org/W2609368435","https://openalex.org/W2250539671","https://openalex.org/W2064675550","https://openalex.org/W1832693441","https://openalex.org/W3210431426"],"abstract_inverted_index":{"We":[0,16],"propose":[1],"an":[2,34],"efficient":[3],"method":[4,31],"to":[5,10,25,54,70,90],"generate":[6],"white-box":[7],"adversarial":[8,62],"examples":[9],"trick":[11],"a":[12,20,79,92],"character-level":[13],"neural":[14],"classifier.":[15],"find":[17],"that":[18,85],"only":[19],"few":[21,80],"manipulations":[22],"are":[23],"needed":[24],"greatly":[26],"decrease":[27],"the":[28,46,49,66,76],"accuracy.":[29],"Our":[30],"relies":[32],"on":[33,45],"atomic":[35],"flip":[36],"operation,":[37],"which":[38,64],"swaps":[39],"one":[40],"token":[41],"for":[42],"another,":[43],"based":[44],"gradients":[47],"of":[48,56,78],"one-hot":[50],"input":[51],"vectors.":[52],"Due":[53],"efficiency":[55],"our":[57],"method,":[58],"we":[59,83],"can":[60,87],"perform":[61],"training":[63],"makes":[65],"model":[67],"more":[68],"robust":[69],"attacks":[71],"at":[72],"test":[73],"time.":[74],"With":[75],"use":[77],"semantics-preserving":[81],"constraints,":[82],"demonstrate":[84],"HotFlip":[86],"be":[88],"adapted":[89],"attack":[91],"word-level":[93],"classifier":[94],"as":[95],"well.":[96]},"counts_by_year":[{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":8},{"year":2020,"cited_by_count":11},{"year":2019,"cited_by_count":12},{"year":2018,"cited_by_count":5}],"updated_date":"2026-04-28T14:05:53.105641","created_date":"2025-10-10T00:00:00"}
