Method, device, equipment, storage medium and program product for generating adversarial samples
Patent Information
- Application Number
- CN202210161770.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-22
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2042-02-22
AI Technical Summary
[0003]本申请针对现有的方式的缺点,提出一种生成对抗样本的方法、装置、设备、计算机可读存储介质及计算机程序产品,用于解决如何生成可靠的对抗样本对的问题
[0051]The process involves obtaining the source text to be translated and its corresponding target text, where the target text is the translated text of the source text. It then identifies the adversarial samples to be identified for the source text and the target text. Based on the source text and its corresponding adversarial samples, a first similarity reduction rate is determined. A second similarity reduction rate is also determined based on the source text, target text, and their corresponding adversarial samples. If the first similarity reduction rate is greater than a preset first similarity reduction rate threshold, and the second similarity reduction rate is less than a preset second similarity reduction rate threshold, then the adversarial samples to be identified for the source text are determined as adversarial samples of the source text, and the adversarial samples to be identified for the target text are determined as adversarial samples of the target text. In this way, based on the source text and target text, a large number of reliable adversarial sample pairs can be generated for NMT, thereby significantly improving the robustness of NMT.
Smart Images

Figure CN116681091B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a method, apparatus, device, storage medium, and program product for generating adversarial examples. Background Technology
[0002] Most existing methods for generating adversarial examples for NMT (Neural Machine Translation) adhere to the constraint of semantic invariance. However, this severely limits the exploration space of adversarial examples and, by adding noise to discrete text, easily alters the semantics of the source text, making it difficult to meet the requirement of semantic invariance. For example, the adversarial example "Aegis is a lightweight warship" replaces "huge" with "lightweight" in the source text "Aegis is a huge warship," resulting in a semantic reversal between the adversarial example and the source text. Therefore, it is unreasonable to evaluate the attack using the original translation corresponding to the source text. Summary of the Invention
[0003] This application addresses the shortcomings of existing methods by proposing a method, apparatus, device, computer-readable storage medium, and computer program product for generating adversarial examples, thereby solving the problem of how to generate reliable adversarial example pairs.
[0004] Firstly, this application provides a method for generating adversarial examples, including:
[0005] Obtain the source text to be translated and the corresponding target text, where the target text is the translated text of the source text;
[0006] Identify the adversarial sample to be identified for the source text and the adversarial sample to be identified for the target text;
[0007] Based on the source text and the corresponding adversarial sample to be identified, a first similarity reduction rate is determined; and based on the source text, target text, and the corresponding adversarial sample to be identified, a second similarity reduction rate is determined.
[0008] If the first similarity decrease rate is greater than the preset first similarity decrease rate threshold, and the second similarity decrease rate is less than the preset second similarity decrease rate threshold, then the adversarial sample to be identified corresponding to the source text is determined to be the adversarial sample of the source text, and the adversarial sample to be identified corresponding to the target text is determined to be the adversarial sample of the target text.
[0009] In one embodiment, determining the adversarial sample to be identified corresponding to the source text and the adversarial sample to be identified corresponding to the target text includes:
[0010] Perform phrase replacement operations on both the source and target texts;
[0011] The phrase replacement operation performed on the source text and the target text respectively includes:
[0012] Input the source text into the preset monolingual masked language model, replace any phrase in the source text to obtain the first text;
[0013] The target text is input into a preset cross-language masked language model. Based on the first text, any phrase in the target text is replaced to obtain the second text. There is a phrase alignment relationship between any phrase in the target text and any phrase in the source text.
[0014] Repeat the phrase replacement operation on the source text and target text until the ratio of the replaced phrases to the source text is equal to a preset ratio threshold. Then, the phrase replacement operation on the source text and target text ends. The first text obtained after the phrase replacement operation is completed is determined as the adversarial sample to be identified corresponding to the source text, and the second text obtained after the phrase replacement operation is completed is determined as the adversarial sample to be identified corresponding to the target text.
[0015] In one embodiment, the target text is input into a preset cross-language masked language model, and based on the first text, any phrase in the target text is replaced to obtain the second text, including:
[0016] Input the target text into a preset cross-language masking language model, mask any phrase in the target text, and obtain the masked target text;
[0017] The first text and the masked target text are concatenated to obtain the third text;
[0018] The third text is input into a cross-language masked language model to obtain multiple candidate phrases, and the candidate phrase with the highest prediction probability is determined from the multiple candidate phrases;
[0019] Replace any phrase with the candidate phrase with the highest predicted probability to obtain the second text.
[0020] In one embodiment, determining a first similarity reduction rate based on the source text and the corresponding adversarial sample to be identified includes:
[0021] The source text is input into a pre-defined forward translation model to translate the source text and obtain the first sample;
[0022] The first sample is input into the preset reverse translation model to translate the first sample and obtain the first reconstructed sample.
[0023] The adversarial sample to be identified corresponding to the source text is input into the forward translation model to translate the adversarial sample to be identified corresponding to the source text, thus obtaining the second sample.
[0024] The second sample is input into the reverse translation model to translate it, resulting in the second reconstructed sample.
[0025] Based on the source text, the corresponding adversarial sample to be identified, the first reconstructed sample, and the second reconstructed sample, the first similarity reduction rate is determined.
[0026] In one embodiment, determining a first similarity reduction rate based on the source text, the corresponding adversarial sample to be identified, the first reconstructed sample, and the second reconstructed sample includes:
[0027] Based on the source text and the first reconstructed sample, determine the first similarity between the source text and the first reconstructed sample;
[0028] Based on the adversarial sample to be identified and the second reconstructed sample corresponding to the source text, determine the second similarity between the adversarial sample to be identified and the second reconstructed sample corresponding to the source text.
[0029] The rate of decrease in the first similarity is determined based on the first similarity and the second similarity.
[0030] In one embodiment, a second similarity reduction rate is determined based on the source text, the target text, and the corresponding adversarial sample to be identified, including:
[0031] The target text is input into the reverse translation model, which translates the target text to obtain a third sample;
[0032] The third sample is input into the forward translation model, and the third sample is translated to obtain the third reconstructed sample;
[0033] The second reconstructed sample is fed into the forward translation model and translated to obtain the fourth reconstructed sample.
[0034] The second similarity reduction rate is determined based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample.
[0035] In one embodiment, determining the second similarity reduction rate based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample includes:
[0036] Based on the target text and the third reconstructed sample, determine the third similarity between the target text and the third reconstructed sample;
[0037] Based on the second sample and the fourth reconstructed sample, determine the fourth similarity between the second sample and the fourth reconstructed sample;
[0038] The rate of decrease in second similarity is determined based on the third and fourth similarities.
[0039] Secondly, this application provides an apparatus for generating adversarial examples, comprising:
[0040] The first processing module is used to obtain the source text to be translated and the target text corresponding to the source text, where the target text is the translated text of the source text;
[0041] The second processing module is used to determine the adversarial sample to be identified corresponding to the source text and the adversarial sample to be identified corresponding to the target text.
[0042] The third processing module is used to determine the first similarity reduction rate based on the source text and the corresponding adversarial sample to be identified; and to determine the second similarity reduction rate based on the source text, the target text, and the corresponding adversarial sample to be identified.
[0043] The fourth processing module is used to determine, if the first similarity decrease rate is greater than a preset first similarity decrease rate threshold and the second similarity decrease rate is less than a preset second similarity decrease rate threshold, the adversarial sample to be identified corresponding to the source text is the adversarial sample of the source text, and the adversarial sample to be identified corresponding to the target text is the adversarial sample of the target text.
[0044] Thirdly, this application provides an electronic device, including: a processor, a memory, and a bus;
[0045] A bus is used to connect the processor and memory;
[0046] Memory, used to store operation instructions;
[0047] A processor is configured to execute the method for generating adversarial examples according to the first aspect of this application by invoking operation instructions.
[0048] Fourthly, this application provides a computer-readable storage medium storing a computer program that is used to execute the method for generating adversarial examples according to the first aspect of this application.
[0049] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method for generating adversarial examples in the first aspect of this application.
[0050] The technical solution provided in this application has at least the following beneficial effects:
[0051] The process involves obtaining the source text to be translated and its corresponding target text, where the target text is the translated text of the source text. It then identifies the adversarial samples to be identified for the source text and the target text. Based on the source text and its corresponding adversarial samples, a first similarity reduction rate is determined. A second similarity reduction rate is also determined based on the source text, target text, and their corresponding adversarial samples. If the first similarity reduction rate is greater than a preset first similarity reduction rate threshold, and the second similarity reduction rate is less than a preset second similarity reduction rate threshold, then the adversarial samples to be identified for the source text are determined as adversarial samples of the source text, and the adversarial samples to be identified for the target text are determined as adversarial samples of the target text. In this way, based on the source text and target text, a large number of reliable adversarial sample pairs can be generated for NMT, thereby significantly improving the robustness of NMT. Attached Figure Description
[0052] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below.
[0053] Figure 1 This is a schematic diagram of source-target-source RTT.
[0054] Figure 2 This is a schematic diagram of the system architecture for generating adversarial examples provided in an embodiment of this application;
[0055] Figure 3 A flowchart illustrating a method for generating adversarial examples provided in this application embodiment;
[0056] Figure 4 A schematic diagram illustrating the generation of adversarial examples provided in an embodiment of this application;
[0057] Figure 5 A flowchart illustrating another method for generating adversarial examples provided in this application embodiment;
[0058] Figure 6 A schematic diagram of a device for generating adversarial examples provided in an embodiment of this application;
[0059] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0060] The embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the embodiments described below with reference to the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions of the embodiments of this application.
[0061] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the terms “comprising” and “including” as used in embodiments of this application mean that the corresponding feature can be implemented as the presented feature, information, data, step, operation, element, and / or component, but do not exclude implementation as other features, information, data, step, operation, element, component, and / or combinations thereof supported by the art. It should be understood that when we say that an element is “connected” or “coupled” to another element, the one element can be directly connected or coupled to the other element, or it can mean that the one element and the other element establish a connection relationship through an intermediate element. Furthermore, “connected” or “coupled” as used herein can include wireless connection or wireless coupling. The term “and / or” as used herein indicates at least one of the items defined by the term; for example, “A and / or B” indicates implementation as “A,” or implementation as “B,” or implementation as “A and B.”
[0062] It is understood that in the specific implementation of this application, data related to the generation of adversarial examples is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0063] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0064] Related technical research has found that an effective adversarial example, by making small changes to the source code, can significantly degrade translation quality, naturally resulting in a semantically corrupting RTT (Round-Trip Translation) result. For example... Figure 1 The source-target-source RTT shown comprises two processes: a forward translation process using a forward translation model (S2T, Source to Target) and a backward translation process using a backward translation model (T2S, Target to Source). Calculate x. δ and x δ RTT results The BLEU values between x and x, and the RTT results for calculating x and x. The BLEU score between the two samples represents the degree of influence of the adversarial sample. If the difference is greater than a predefined threshold, then x is determined to be negative. δ This is an adversarial example; where x is the source sample, BLEU can measure word-level accuracy, and BLEU can also measure sentence fluency. For example... Figure 1The method shown has the following two problems:
[0065] (1) Since the source-target-source RTT includes two processes, S2T and T2S, it is impossible to determine which stage caused the decrease in BLEU value. This method will incorrectly treat samples with BLEU decrease caused by T2S as adversarial samples.
[0066] (2) This method only uses the generated adversarial samples to attack the model, without proposing how to defend against these adversarial samples, so as to improve the robustness of NMT.
[0067] Based on this, in order to solve the above problem (1), the method for generating adversarial examples provided in this application adds target-source-target RTT at the target end, calculates the BLEU decrease caused by the T2S process, and if the BLEU decrease of T2S is less than a certain threshold, while the BLEU decrease of S2T is greater than a certain threshold, then x is determined. δ To provide reliable adversarial examples, in order to solve problem (2), the method for generating adversarial examples provided in this application performs phrase replacement on the source sentence (source text) and the target sentence (target text) simultaneously to generate bilingual adversarial example pairs.
[0068] This application provides a method for generating adversarial examples using a system for generating adversarial examples. This method relates to fields such as artificial intelligence and cloud technology. For example, the forward translation model and backward translation model involved in this application are machine translation technologies in the field of artificial intelligence; furthermore, the monolingual masked language model and cross-lingual masked language model in this application are artificial neural networks in the field of artificial intelligence. The application scenarios of this method for generating adversarial examples include, but are not limited to, machine translation scenarios, such as Chinese to English translation and English to Chinese translation.
[0069] Artificial intelligence (AI) is the theory, methods, technology, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to achieve optimal results. In other words, AI is a comprehensive technology within computer science that attempts to understand the essence of intelligence and produce a new kind of intelligent machine that can react in a way similar to human intelligence. AI studies the design principles and implementation methods of various intelligent machines, enabling them to possess the functions of perception, reasoning, and decision-making.
[0070] Artificial intelligence (AI) is a comprehensive discipline encompassing a wide range of fields, including both hardware and software technologies. Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. AI software technologies primarily include computer vision, speech processing, natural language processing, as well as machine learning / deep learning, autonomous driving, and intelligent transportation.
[0071] Natural Language Processing (NLP) is an important field within computer science and artificial intelligence. It studies the theories and methods for enabling effective communication between humans and computers using natural language. NLP is a science that integrates linguistics, computer science, and mathematics. Therefore, research in this field involves natural language—the language people use in daily life—and thus it has a close relationship with linguistic research. NLP techniques typically include text processing, semantic understanding, machine translation, question answering, and knowledge graphs.
[0072] Machine translation, also known as automatic translation, is the process of using computers to convert one natural language (source language) into another natural language (target language).
[0073] Machine Learning (ML) is a multidisciplinary field involving probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers can simulate or implement human learning behavior to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is the core of artificial intelligence and the fundamental way to endow computers with intelligence; its applications span all areas of artificial intelligence. Machine learning and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and instructional learning.
[0074] To better understand and explain the solutions of the embodiments of this application, some technical terms involved in the embodiments of this application will be briefly explained below.
[0075] RTT (Round-Trip Translation), also known as recursive translation, is a process that translates words, phrases, or text into another language (forward translation), and then returns the translation result to the original language (backward translation). It is performed using machine translation software. Laypeople often use it to evaluate machine translation systems or to test whether text is suitable for machine translation when they are unfamiliar with the target language. Because the generated text is often quite different from the original text, round-trip translation can also be a source of entertainment. To compare the quality of different machine translation systems, users perform round-trip translation and compare the resulting text with the original text; the closer the round-trip translation is to the original text, the higher the quality of the machine translation system.
[0076] Adversarial examples: Adversarial examples are a type of sample designed to confuse machine learning machines. Adversarial examples look almost identical to real samples, but the addition of noise causes the machine learning model to make incorrect classification judgments.
[0077] MLM (Masked Language Modeling) is a fill-in-the-blank task that uses context words surrounding masked tokens to attempt to predict what the masked word should be. For an input containing one or more masked tokens, the model generates the most probable alternative for each token. MLM is a self-supervised learning method that does not require manual labels.
[0078] argmax: argmax is a mathematical function that represents the maximum value; argmax is a function that evaluates to the set of arguments of a function. When we have another function y = f(x), if we have the result x0 = argmax(f(x)), it means that when the function f(x) takes the value x = x0, we get the maximum value in the range of values of f(x).
[0079] The solutions provided in this application relate to artificial intelligence technology. The technical solutions of this application will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0080] To better understand the solution provided in the embodiments of this application, the solution will be described below in conjunction with a specific application scenario.
[0081] In one embodiment, Figure 2 The diagram illustrates the architecture of a generative adversarial example system applicable to embodiments of this application. It is understood that the generative adversarial example method provided in this application can be applied to, but is not limited to, applications such as... Figure 2In the application scenarios shown.
[0082] In this example, as Figure 2 As shown, the architecture of the adversarial sample generation system in this example can include, but is not limited to, terminal 10 and server 20. Terminal 10 and server 20 can interact via a network. Terminal 10 sends the source text to be translated and the corresponding target text to server 20. Server 20 obtains the source text to be translated and the corresponding target text, where the target text is the translated text of the source text. Server 20 determines the adversarial sample to be identified for the source text and the adversarial sample to be identified for the target text. Based on the source text and the corresponding adversarial sample to be identified, a first similarity reduction rate is determined. Server 20 also determines a second similarity reduction rate based on the source text, target text, and the corresponding adversarial sample to be identified for the target text. If the first similarity reduction rate is greater than a preset first similarity reduction rate threshold and the second similarity reduction rate is less than a preset second similarity reduction rate threshold, then server 20 determines the adversarial sample to be identified for the source text as the adversarial sample of the source text and the adversarial sample to be identified for the target text as the adversarial sample of the target text. In this way, a large number of reliable adversarial sample pairs can be generated for NMT, thereby significantly improving the robustness of NMT.
[0083] It is understood that the above is only one example, and this embodiment is not limited here.
[0084] The terminal can be a smartphone (such as an Android phone, iOS phone, etc.), a mobile phone emulator, a tablet computer, a laptop computer, a digital broadcast receiver, a MID (Mobile Internet Device), a PDA (Personal Digital Assistant), etc. The server can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server or server cluster that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0085] Cloud computing is a computing model that distributes computing tasks across a large pool of computers, enabling various application systems to access computing power, storage space, and information services as needed. The network providing these resources is called the "cloud." From the user's perspective, resources in the "cloud" appear infinitely scalable, readily available, on-demand, and expandable, with payment based on usage.
[0086] As a provider of fundamental cloud computing capabilities, a cloud resource pool (referred to as a cloud platform, generally called an IaaS (Infrastructure as a Service) platform) is established. Various types of virtual resources are deployed in the resource pool for external customers to choose from. The cloud resource pool mainly includes: computing devices (virtualized machines containing operating systems), storage devices, and network devices.
[0087] Based on logical function, a PaaS (Platform as a Service) layer can be deployed on top of the IaaS (Infrastructure as a Service) layer, and a SaaS (Software as a Service) layer can be deployed on top of the PaaS layer. Alternatively, SaaS can be deployed directly on top of IaaS. PaaS is a platform for running software, such as databases and web containers. SaaS refers to various types of business software, such as web portals and bulk SMS senders. Generally speaking, SaaS and PaaS are upper layers compared to IaaS.
[0088] Artificial intelligence cloud services are generally also known as AIaaS (AI as a Service). This is currently a mainstream service model for artificial intelligence platforms. Specifically, AIaaS platforms break down several common AI services and provide them as independent or packaged services in the cloud. This service model is similar to opening an AI-themed marketplace: all developers can access and use one or more AI services provided by the platform through API interfaces. Some experienced developers can also use the AI framework and AI infrastructure provided by the platform to deploy and maintain their own dedicated cloud AI services.
[0089] The aforementioned networks may include, but are not limited to, wired networks and wireless networks. Wired networks include local area networks (LANs), metropolitan area networks (MANs), and wide area networks (WANs). Wireless networks include Bluetooth, Wi-Fi, and other networks that enable wireless communication. Specific details can be determined based on actual application scenario requirements and are not limited here.
[0090] See Figure 3 , Figure 3 This illustration shows a flowchart of a method for generating adversarial examples according to an embodiment of this application. This method can be executed by any electronic device, such as a server. As an optional implementation, the method can be executed by a server. For ease of description, in the following description of some optional embodiments, a server will be used as the execution subject of the method. Figure 3As shown, the method for generating adversarial examples provided in this application includes the following steps:
[0091] S301, obtain the source text to be translated and the target text corresponding to the source text, where the target text is the translated text of the source text.
[0092] Specifically, such as Figure 4 As shown, for example, the source text (source sentence) to be translated is x, which is "This approach is reasonable.", and the corresponding target text (target sentence) is y, which is "this approach is reasonable.", where x is Chinese and y is the English translation of x.
[0093] S302, determine the adversarial sample to be identified corresponding to the source text, and the adversarial sample to be identified corresponding to the target text.
[0094] Specifically, such as Figure 4 As shown, for example, the adversarial sample to be identified corresponding to the source text is x. δ x δ The target text, "This approach is more pragmatic," corresponds to the adversarial sample to be identified as y. δ y δ For "this approach is derving truth from fact."
[0095] S303, based on the source text and the corresponding adversarial sample to be identified, determine the first similarity reduction rate; and based on the source text, the target text, and the corresponding adversarial sample to be identified, determine the second similarity reduction rate.
[0096] Specifically, such as Figure 4 The example shown is DRTT (Doubly Round-Trip Translation). For instance, the source sentence (source text) is x, which means "This approach is more reasonable." x is input into M-MLM (Monophonic Masked Language Model), where phrase replacement is performed on x to obtain the adversarial sample to be identified corresponding to the source sentence. δ x δ The target sentence (target text) is y, which is "this approach is reasonable." y is input into T-MLM (Tele-Masked Language Model) to perform phrase substitution, resulting in the adversarial sample to be identified corresponding to the target sentence. δ y δ is "this approach is derving truth from fact."; change x δThe input is fed into the forward translation model, and through the forward translation process S2T of the forward translation model, x is... δ The translation was performed to obtain the second sample y′. δ y′ δ This approach is more practical. (The phrase "y′" is used to express the idea that "y′ is more practical.") δ The input is fed into the reverse translation model, and through the reverse translation process T2S of the reverse translation model, y′ is... δ The translation was performed to obtain the second reconstructed sample. This approach is more practical. The input is fed into the forward translation model, and through the forward translation process S2T of the forward translation model, the result is... The translation was performed to obtain the fourth reconstructed sample.
[0097] x and x δ Through source-target-source RTT ( Figure 4 In S2T and T2S (S2T precedes T2S), the calculated percentage decrease in similarity is considered as the degree of influence of the adversarial example d. src (x, x) δ ), d src (x, x) δ ) represents the first similarity reduction rate, d src (x, x) δ As shown in formula (1):
[0098]
[0099] in, and They are x and x δ Sentences reconstructed using source-target-source RTT. represent x and Similarity between them x represents δ and The similarity between them. The larger the value of d... src (x, x) δ This indicates that, compared to the reconstruction quality of x, x... δ The inability to be reconstructed well by RTT means x δ The RTT result caused semantic loss, therefore x δ It could be an adversarial example.
[0100] It can be achieved through target-source-target RTT ( Figure 4 In T2S and S2T (S2T follows T2S), we determine x. δAre these truly adversarial examples? y and y′ δ The percentage decrease in similarity calculated using the target-source-target RTT is denoted as d. tgt (y,y′ δ ), d tgt (y,y′ δ ) represents the second similarity reduction rate, d tgt (y,y′ δ As shown in formula (2):
[0101]
[0102] in, and They are y and y′ respectively δ Sentences reconstructed using target-source-target RTT. Represent y and Similarity between them Represents y′ δ and The similarity between them.
[0103] d can be considered simultaneously src (x, x) δ ) and d tgt (y,y′ δ If x δ If formula (3) is satisfied, then x is determined. δ For the adversarial example of x, formula (3) is shown below:
[0104]
[0105] Wherein, β is the preset first similarity decrease rate threshold, and γ is the preset second similarity decrease rate threshold.
[0106] It should be noted that if d tgt (y,y′ δ If y' < γ, then y' can be determined. δ and The reconstruction error between them is very small, meaning the semantic loss caused by the T2S process is minimal. When d src (x, x) δ When x > β, it can be determined that the BLEU decrease caused by the source-target-source RTT is due to the forward translation model. Therefore, x δ It is a true adversarial example, namely x δ Here is an adversarial example for x.
[0107] S304, if the first similarity decrease rate is greater than the preset first similarity decrease rate threshold and the second similarity decrease rate is less than the preset second similarity decrease rate threshold, then the adversarial sample to be identified corresponding to the source text is determined to be the adversarial sample of the source text, and the adversarial sample to be identified corresponding to the target text is determined to be the adversarial sample of the target text.
[0108] Specifically, as shown in formula (3), the first similarity reduction rate d src (x, x) δ The similarity decrease rate is greater than the preset first similarity decrease rate threshold β, and the second similarity decrease rate d tgt (y,y′ δ If the similarity decrease rate is less than the preset second similarity decrease rate threshold γ, then the adversarial sample x corresponding to the source text x is determined to be the one to be identified. δ Here are the adversarial samples of the source text y, and the adversarial sample y to be identified corresponding to the target text y. δ This is an adversarial example for the target text.
[0109] In this embodiment, the source text to be translated and the corresponding target text are obtained, where the target text is the translated text of the source text; adversarial samples to be identified for the source text and adversarial samples to be identified for the target text are determined; a first similarity reduction rate is determined based on the source text and the corresponding adversarial samples; and a second similarity reduction rate is determined based on the source text, the target text, and the corresponding adversarial samples; if the first similarity reduction rate is greater than a preset first similarity reduction rate threshold and the second similarity reduction rate is less than a preset second similarity reduction rate threshold, then the adversarial samples to be identified for the source text are determined to be adversarial samples of the source text, and the adversarial samples to be identified for the target text are determined to be adversarial samples of the target text; thus, based on the source text and the target text, a large number of reliable adversarial sample pairs can be generated for NMT, thereby significantly improving the robustness of NMT.
[0110] In one embodiment, determining the adversarial sample to be identified corresponding to the source text and the adversarial sample to be identified corresponding to the target text includes:
[0111] Perform phrase replacement operations on both the source and target texts;
[0112] The phrase replacement operation performed on the source text and the target text respectively includes:
[0113] Input the source text into the preset monolingual masked language model, replace any phrase in the source text to obtain the first text;
[0114] The target text is input into a preset cross-language masked language model. Based on the first text, any phrase in the target text is replaced to obtain the second text. There is a phrase alignment relationship between any phrase in the target text and any phrase in the source text.
[0115] Repeat the phrase replacement operation on the source text and target text until the ratio of the replaced phrases to the source text is equal to a preset ratio threshold. Then, the phrase replacement operation on the source text and target text ends. The first text obtained after the phrase replacement operation is completed is determined as the adversarial sample to be identified corresponding to the source text, and the second text obtained after the phrase replacement operation is completed is determined as the adversarial sample to be identified corresponding to the target text.
[0116] In one embodiment, a monolingual masked language model (M-MLM) and a cross-lingual masked language model (T-MLM) are trained separately to perform phrase substitution on the source and target sentences. M-MLM can randomly mask a token in the source sentence and predict the masked token. T-MLM can introduce a [SEP] token to concatenate the bilingual corpus, resulting in the form "source sentence [SEP] target sentence", and then predict the masked token of the target sentence, where "[SEP]" represents the separator. M-MLM and T-MLM can be trained using an encoder-decoder Transformer model, where both M-MLM and T-MLM are Transformer frameworks.
[0117] In one embodiment, phrase alignment projects each phrase in the source sentence x to an aligned phrase in the target sentence y. The positions of the aligned words in x and y are obtained using the Fast Align tool; the phrase alignment relationship p is obtained using the phrase extraction algorithm in the Natural Language Toolkit (NLTK). For example, in the phrase "I love China", "I" corresponds to p(1), "love" corresponds to p(2), and "China" corresponds to p(3), where p(1), p(2), and p(3) represent the positions of "I", "love", and "China" in the English phrase "I love China", respectively.
[0118] In one embodiment, the process of generating bilingual adversarial examples (adversarial example pairs) includes steps A1-A10:
[0119] Step A1, convert the source sentence x = {s1, s2, ..., s...} n The input is fed into a monolingual masked language model M-MLM, and the target sentence y = {t1, t2, ..., t} is set as follows: m Input into the preset cross-language masked language model T-MLM.
[0120] Specifically, source sentence x is the source text, and target sentence y is the target text.
[0121] Step A2, repeat steps A3-A9, continuously perform phrase replacement on (x, y) until c percent of the phrases in x are replaced.
[0122] Specifically, phrase replacement refers to the phrase replacement operation, and 'c' is a preset ratio threshold.
[0123] Step A3, the phrase at the i-th position in the mask x, using x \i Indicates; to represent x \i The k phrases with the highest predicted probabilities are fed into M-MLM and used as s. i candidate replacement set k is a positive integer.
[0124] Step A4, using Each candidate phrase Replace s i Candidate sentence x can be obtained \i:j .
[0125] Step A5, as shown in formula (4), select one that allows d to... src (x, x) \i:j (to reach the maximum phrase) For the final replacement phrase, formula (4) is shown below:
[0126]
[0127] Step A6, using Replace s i Get x \i:* .
[0128] Specifically, x \i:* This is the first text.
[0129] Step A7: Determine the position p(i) corresponding to the target sentence y, where p(i) is the phrase alignment relationship.
[0130] Step A8, using a T-MLM mask to mask the phrase t in the target sentence y. p(i) , get y \p(i) ; will x \i:* and y \p(i) The phrases are concatenated and input into T-MLM to obtain the phrase w with the highest predicted probability. p(i) .
[0131] Specifically, y \p(i) For the masked target text, the first text x \i:* and the target text y after masking\p(i) The text is concatenated to obtain a third text; this third text is then input into T-MLM to obtain multiple candidate phrases, and the candidate phrase with the highest prediction probability, w, is selected from these multiple candidate phrases. p(i) .
[0132] Step A9, use w p(i) Replace t p(i) Get y δ .
[0133] Specifically, y δ It can be a second text.
[0134] Step A10, if (x δ y δ ) conforms to the formula (3) d src (x, x) δ )>β and d tqt (y,y′ δ If ) < γ, then determine (x) δ y δ ) are true adversarial sample pairs.
[0135] In one embodiment, the target text is input into a preset cross-language masked language model, and based on the first text, any phrase in the target text is replaced to obtain the second text, including:
[0136] Input the target text into a preset cross-language masking language model, mask any phrase in the target text, and obtain the masked target text;
[0137] The first text and the masked target text are concatenated to obtain the third text;
[0138] The third text is input into a cross-language masked language model to obtain multiple candidate phrases, and the candidate phrase with the highest prediction probability is determined from the multiple candidate phrases;
[0139] Replace any phrase with the candidate phrase with the highest predicted probability to obtain the second text.
[0140] Specifically, the target text y is input into the cross-lingual masked language model T-MLM, and a phrase in the target text y is masked to obtain the masked target text y. \p(i) ; the first text x \i:x and the target text y after masking \p(i) The text is concatenated to obtain a third text; this third text is then input into T-MLM to obtain multiple candidate phrases, and the candidate phrase with the highest prediction probability, w, is selected from these multiple candidate phrases. p(i) Replace the phrase with the candidate phrase w that has the highest predicted probability. p(i)The second text y is obtained. δ .
[0141] In one embodiment, determining a first similarity reduction rate based on the source text and the corresponding adversarial sample to be identified includes:
[0142] The source text is input into a pre-defined forward translation model to translate the source text and obtain the first sample;
[0143] The first sample is input into the preset reverse translation model to translate the first sample and obtain the first reconstructed sample.
[0144] The adversarial sample to be identified corresponding to the source text is input into the forward translation model to translate the adversarial sample to be identified corresponding to the source text, thus obtaining the second sample.
[0145] The second sample is input into the reverse translation model to translate it, resulting in the second reconstructed sample.
[0146] Based on the source text, the corresponding adversarial sample to be identified, the first reconstructed sample, and the second reconstructed sample, the first similarity reduction rate is determined.
[0147] Specifically, the source text x is input into the forward translation model to translate the source text x, obtaining the first sample; the first sample is then input into the backward translation model to translate the first sample, obtaining the first reconstructed sample. The adversarial sample to be identified corresponding to the source text x δ The input is fed into the forward translation model to identify the adversarial sample x corresponding to the source text. δ The translation was performed to obtain the second sample y′. δ ; the second sample y′ δ Input into the reverse translation model, for the second sample y′ δ The translation was performed to obtain the second reconstructed sample. Based on the source text x and the corresponding adversarial sample x to be identified δ First reconstructed sample Second reconstructed sample Determine the first similarity reduction rate d src (x, x) δ ), first similarity reduction rate d src (x, x) δ As shown in formula (1).
[0148] In one embodiment, determining a first similarity reduction rate based on the source text, the corresponding adversarial sample to be identified, the first reconstructed sample, and the second reconstructed sample includes:
[0149] Based on the source text and the first reconstructed sample, determine the first similarity between the source text and the first reconstructed sample;
[0150] Based on the adversarial sample to be identified and the second reconstructed sample corresponding to the source text, determine the second similarity between the adversarial sample to be identified and the second reconstructed sample corresponding to the source text.
[0151] The rate of decrease in the first similarity is determined based on the first similarity and the second similarity.
[0152] Specifically, as shown in formula (1), based on the source text x and the first reconstructed sample Determine the source text x and the first reconstructed sample First similarity between Based on the adversarial sample x to be identified in the source text δ Second reconstructed sample Determine the adversarial sample x to be identified corresponding to the source text. δ Second reconstructed sample Second similarity between Based on the first similarity Second similarity Determine the first similarity reduction rate d src (x, x) δ ).
[0153] In one embodiment, a second similarity reduction rate is determined based on the source text, the target text, and the corresponding adversarial sample to be identified, including:
[0154] The target text is input into the reverse translation model, which translates the target text to obtain a third sample;
[0155] The third sample is input into the forward translation model, and the third sample is translated to obtain the third reconstructed sample;
[0156] The second reconstructed sample is fed into the forward translation model and translated to obtain the fourth reconstructed sample.
[0157] The second similarity reduction rate is determined based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample.
[0158] Specifically, the target text y is input into the reverse translation model to translate the target text, obtaining the third sample; the third sample is then input into the forward translation model to translate the third sample, obtaining the third reconstructed sample. The second reconstructed sample For the forward translation model, the second reconstructed sample The translation was performed to obtain the fourth reconstructed sample. Based on the target text y and the third reconstruction sample Second sample y′ δ and the fourth reconstructed sample Determine the second similarity reduction rate Second similarity decrease rate As shown in formula (2).
[0159] In one embodiment, determining the second similarity reduction rate based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample includes:
[0160] Based on the target text and the third reconstructed sample, determine the third similarity between the target text and the third reconstructed sample;
[0161] Based on the second sample and the fourth reconstructed sample, determine the fourth similarity between the second sample and the fourth reconstructed sample;
[0162] The rate of decrease in second similarity is determined based on the third and fourth similarities.
[0163] Specifically, as shown in formula (2), based on the target text y and the third reconstructed sample Determine the target text y and the third reconstructed sample Third similarity between Based on the second sample y′ δ and the fourth reconstructed sample Determine the second sample y′ δ and the fourth reconstructed sample The fourth similarity between Based on third similarity and fourth similarity Determine the second similarity reduction rate d tgt (y,y′ δ ).
[0164] Applying the embodiments of this application has at least the following beneficial effects:
[0165] Based on the source and target texts, a large number of reliable adversarial sample pairs can be generated for NMT, which can significantly improve the robustness of NMT.
[0166] To better understand the methods provided in the embodiments of this application, the solutions of the embodiments of this application will be further explained below with reference to specific application scenarios.
[0167] The method provided in this application embodiment can be applied to machine translation scenarios, such as Chinese to English translation and English to Chinese translation.
[0168] The method provided in this application embodiment was tested and validated on the publicly available noise dataset WMT19 (English to French). The experimental results are shown in Table 1. The adversarial example pairs generated by the method (DRTT) provided in this application embodiment can significantly improve the robustness of NMT. Transformer, TCWR, and RTT can be selected as baseline systems. The NMT robustness comparison is shown in Table 1. The method provided in this application embodiment has a BLEU value improvement of 1.25 compared to Transformer, indicating that the method provided in this application embodiment performs well in real-world noise scenarios. The method provided in this application embodiment has a BLEU value improvement of 0.63 compared to RTT, indicating that the method provided in this application embodiment can effectively filter out genuine adversarial example pairs, thereby further improving the model's robustness.
[0169] Table 1: Robustness Comparison of DRTT and Baseline Systems
[0170] Transformer 35.11 +TCWR 35.64 +0.53 +RTT 35.73 +0.62 +DRTT 36.36 +1.25
[0171] See Figure 5 , Figure 5 This illustration shows a flowchart of a method for generating adversarial examples according to an embodiment of this application. This method can be executed by any electronic device, such as a server. As an optional implementation, the method can be executed by a server. For ease of description, in the following description of some optional embodiments, a server will be used as the execution subject of the method. Figure 5 As shown, the method for generating adversarial examples provided in this application includes the following steps:
[0172] S601, obtain the source sentence and target sentence.
[0173] S602: Input the source sentence into the monolingual masked language model, replace any phrase in the source sentence, and obtain the first text.
[0174] S603: Input the target sentence into the cross-language masked language model. Based on the first text, replace any phrase in the target sentence to obtain the second text.
[0175] Specifically, there is a phrase alignment relationship between any phrase in the target sentence and any phrase in the source sentence.
[0176] S604, determine whether the ratio of the replaced phrase to the source sentence is equal to the preset ratio threshold. If the ratio of the replaced phrase to the source sentence is equal to the preset ratio threshold, proceed to step S605 for processing; if the ratio of the replaced phrase to the source sentence is less than the preset ratio threshold, proceed to step S602 for processing.
[0177] S605, the first text obtained after the phrase replacement operation is determined as the adversarial sample to be identified corresponding to the source sentence, and the second text obtained after the phrase replacement operation is determined as the adversarial sample to be identified corresponding to the target sentence.
[0178] S606, based on the source sentence and the corresponding adversarial sample to be identified, determine the first similarity reduction rate; and based on the source sentence, the target sentence and the corresponding adversarial sample to be identified, determine the second similarity reduction rate.
[0179] S607, if the first similarity decrease rate is greater than the preset first similarity decrease rate threshold and the second similarity decrease rate is less than the preset second similarity decrease rate threshold, then the adversarial sample to be identified corresponding to the source sentence is determined to be the adversarial sample of the source sentence, and the adversarial sample to be identified corresponding to the target sentence is determined to be the adversarial sample of the target sentence.
[0180] Applying the embodiments of this application has at least the following beneficial effects:
[0181] Based on the source sentence and the target sentence, a large number of reliable adversarial sample pairs can be generated for NMT, which can significantly improve the robustness of NMT.
[0182] This application also provides an apparatus for generating adversarial examples, the structural schematic diagram of which is shown below. Figure 6 As shown, the apparatus 60 for generating adversarial examples includes a first processing module 601, a second processing module 602, a third processing module 603, and a fourth processing module 604.
[0183] The first processing module 601 is used to obtain the source text to be translated and the target text corresponding to the source text, wherein the target text is the translated text of the source text;
[0184] The second processing module 602 is used to determine the adversarial sample to be identified corresponding to the source text and the adversarial sample to be identified corresponding to the target text.
[0185] The third processing module 603 is used to determine the first similarity reduction rate based on the source text and the adversarial sample to be identified corresponding to the source text; and to determine the second similarity reduction rate based on the source text, the target text and the adversarial sample to be identified corresponding to the target text.
[0186] The fourth processing module 604 is used to determine the adversarial sample to be identified corresponding to the source text as the adversarial sample of the source text and the adversarial sample to be identified corresponding to the target text as the adversarial sample of the target text if the first similarity decrease rate is greater than the preset first similarity decrease rate threshold and the second similarity decrease rate is less than the preset second similarity decrease rate threshold.
[0187] In one embodiment, the second processing module 602 is specifically used for:
[0188] Perform phrase replacement operations on both the source and target texts;
[0189] The phrase replacement operation performed on the source text and the target text respectively includes:
[0190] Input the source text into the preset monolingual masked language model, replace any phrase in the source text to obtain the first text;
[0191] The target text is input into a preset cross-language masked language model. Based on the first text, any phrase in the target text is replaced to obtain the second text. There is a phrase alignment relationship between any phrase in the target text and any phrase in the source text.
[0192] Repeat the phrase replacement operation on the source text and target text until the ratio of the replaced phrases to the source text is equal to a preset ratio threshold. Then, the phrase replacement operation on the source text and target text ends. The first text obtained after the phrase replacement operation is completed is determined as the adversarial sample to be identified corresponding to the source text, and the second text obtained after the phrase replacement operation is completed is determined as the adversarial sample to be identified corresponding to the target text.
[0193] In one embodiment, the second processing module 602 is specifically used for:
[0194] Input the target text into a preset cross-language masking language model, mask any phrase in the target text, and obtain the masked target text;
[0195] The first text and the masked target text are concatenated to obtain the third text;
[0196] The third text is input into a cross-language masked language model to obtain multiple candidate phrases, and the candidate phrase with the highest prediction probability is determined from the multiple candidate phrases;
[0197] Replace any phrase with the candidate phrase with the highest predicted probability to obtain the second text.
[0198] In one embodiment, the third processing module 603 is specifically used for:
[0199] The source text is input into a pre-defined forward translation model to translate the source text and obtain the first sample;
[0200] The first sample is input into the preset reverse translation model to translate the first sample and obtain the first reconstructed sample.
[0201] The adversarial sample to be identified corresponding to the source text is input into the forward translation model to translate the adversarial sample to be identified corresponding to the source text, thus obtaining the second sample.
[0202] The second sample is input into the reverse translation model to translate it, resulting in the second reconstructed sample.
[0203] Based on the source text, the corresponding adversarial sample to be identified, the first reconstructed sample, and the second reconstructed sample, the first similarity reduction rate is determined.
[0204] In one embodiment, the third processing module 603 is specifically used for:
[0205] Based on the source text and the first reconstructed sample, determine the first similarity between the source text and the first reconstructed sample;
[0206] Based on the adversarial sample to be identified and the second reconstructed sample corresponding to the source text, determine the second similarity between the adversarial sample to be identified and the second reconstructed sample corresponding to the source text.
[0207] The rate of decrease in the first similarity is determined based on the first similarity and the second similarity.
[0208] In one embodiment, the third processing module 603 is specifically used for:
[0209] The target text is input into the reverse translation model, which translates the target text to obtain a third sample;
[0210] The third sample is input into the forward translation model, and the third sample is translated to obtain the third reconstructed sample;
[0211] The second reconstructed sample is fed into the forward translation model and translated to obtain the fourth reconstructed sample.
[0212] The second similarity reduction rate is determined based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample.
[0213] In one embodiment, the third processing module 603 is specifically used for:
[0214] Based on the target text and the third reconstructed sample, determine the third similarity between the target text and the third reconstructed sample;
[0215] Based on the second sample and the fourth reconstructed sample, determine the fourth similarity between the second sample and the fourth reconstructed sample;
[0216] The rate of decrease in second similarity is determined based on the third and fourth similarities.
[0217] Applying the embodiments of this application has at least the following beneficial effects:
[0218] The process involves obtaining the source text to be translated and its corresponding target text, where the target text is the translated text of the source text. It then identifies the adversarial samples to be identified for the source text and the target text. Based on the source text and its corresponding adversarial samples, a first similarity reduction rate is determined. A second similarity reduction rate is also determined based on the source text, target text, and their corresponding adversarial samples. If the first similarity reduction rate is greater than a preset first similarity reduction rate threshold, and the second similarity reduction rate is less than a preset second similarity reduction rate threshold, then the adversarial samples to be identified for the source text are determined as adversarial samples of the source text, and the adversarial samples to be identified for the target text are determined as adversarial samples of the target text. In this way, based on the source text and target text, a large number of reliable adversarial sample pairs can be generated for NMT, thereby significantly improving the robustness of NMT.
[0219] This application also provides an electronic device, the structural schematic diagram of which is shown below. Figure 7 As shown, Figure 7 The illustrated electronic device 4000 includes a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, for example, via a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, which can be used for data interaction between the electronic device and other electronic devices, such as sending and / or receiving data. It should be noted that in practical applications, the transceiver 4004 is not limited to one type, and the structure of the electronic device 4000 does not constitute a limitation on the embodiments of this application.
[0220] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 4001 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0221] Bus 4002 may include a pathway for transmitting information between the aforementioned components. Bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 4002 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 7 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0222] The memory 4003 may be ROM (Read Only Memory) or other types of static storage devices capable of storing static information and instructions, RAM (Random Access Memory) or other types of dynamic storage devices capable of storing information and instructions, or EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium capable of carrying or storing computer programs and capable of being read by a computer, without limitation herein.
[0223] The memory 4003 is used to store computer programs that execute the embodiments of this application, and the execution is controlled by the processor 4001. The processor 4001 is used to execute the computer programs stored in the memory 4003 to implement the steps shown in the foregoing method embodiments.
[0224] Electronic devices include, but are not limited to, servers.
[0225] Applying the embodiments of this application has at least the following beneficial effects:
[0226] The process involves obtaining the source text to be translated and its corresponding target text, where the target text is the translated text of the source text. It then identifies the adversarial samples to be identified for the source text and the target text. Based on the source text and its corresponding adversarial samples, a first similarity reduction rate is determined. A second similarity reduction rate is also determined based on the source text, target text, and their corresponding adversarial samples. If the first similarity reduction rate is greater than a preset first similarity reduction rate threshold, and the second similarity reduction rate is less than a preset second similarity reduction rate threshold, then the adversarial samples to be identified for the source text are determined as adversarial samples of the source text, and the adversarial samples to be identified for the target text are determined as adversarial samples of the target text. In this way, based on the source text and target text, a large number of reliable adversarial sample pairs can be generated for NMT, thereby significantly improving the robustness of NMT.
[0227] This application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it can implement the steps and corresponding content of the aforementioned method embodiments.
[0228] This application also provides a computer program product, including a computer program that, when executed by a processor, can implement the steps and corresponding content of the aforementioned method embodiments.
[0229] Based on the same principles as the methods provided in the embodiments of this application, the embodiments of this application also provide a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in any of the optional embodiments of this application described above.
[0230] It should be understood that although arrows indicate various operation steps in the flowcharts of this application's embodiments, the order in which these steps are implemented is not limited to the order indicated by the arrows. Unless explicitly stated herein, in some implementation scenarios of this application's embodiments, the implementation steps in each flowchart can be executed in other orders as required. Furthermore, some or all steps in each flowchart, based on the actual implementation scenario, may include multiple sub-steps or multiple stages. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage can also be executed at different times. In scenarios where execution times differ, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and this application's embodiments do not limit this.
[0231] The above description is only an optional implementation method for some implementation scenarios of this application. It should be noted that for those skilled in the art, other similar implementation methods based on the technical concept of this application without departing from the technical concept of this application also fall within the protection scope of the embodiments of this application.
Claims
1. A method for generating adversarial examples, characterized in that, include: Obtain the source text to be translated and the target text corresponding to the source text, wherein the target text is the translated text of the source text; Determine the adversarial sample to be identified corresponding to the source text, and the adversarial sample to be identified corresponding to the target text; Based on the source text and the corresponding adversarial sample to be identified, a first similarity reduction rate is determined. The first similarity reduction rate is the percentage decrease in similarity calculated by source-target-source round-trip translation of the source text and the corresponding adversarial sample. Based on the source text, the target text, and the corresponding adversarial sample, a second similarity reduction rate is determined. The second similarity reduction rate is the percentage decrease in similarity calculated by target-source-target round-trip translation of the target text and the second sample. The second sample is obtained by translating the corresponding adversarial sample of the source text using a forward translation model. If the first similarity decrease rate is greater than a preset first similarity decrease rate threshold, and the second similarity decrease rate is less than a preset second similarity decrease rate threshold, then the adversarial sample to be identified corresponding to the source text is determined to be an adversarial sample of the source text, and the adversarial sample to be identified corresponding to the target text is determined to be an adversarial sample of the target text.
2. The method according to claim 1, characterized in that, The step of determining the adversarial sample to be identified corresponding to the source text and the adversarial sample to be identified corresponding to the target text includes: Perform phrase replacement operations on both the source text and the target text; The phrase replacement operation performed on the source text and the target text respectively includes: The source text is input into a preset monolingual masked language model, and any phrase in the source text is replaced to obtain the first text; The target text is input into a preset cross-language masked language model. Based on the first text, any phrase in the target text is replaced to obtain the second text. There is a phrase alignment relationship between any phrase in the target text and any phrase in the source text. Repeatedly perform phrase replacement operations on the source text and the target text until the ratio of replaced phrases to the source text equals a preset ratio threshold. Then, end the phrase replacement operations on the source text and the target text, and determine the first text obtained after the phrase replacement operation as the adversarial sample to be identified corresponding to the source text, and the second text obtained after the phrase replacement operation as the adversarial sample to be identified corresponding to the target text.
3. The method according to claim 2, characterized in that, The step of inputting the target text into a preset cross-language masking language model, and replacing any phrase in the target text based on the first text to obtain the second text, includes: The target text is input into a preset cross-language masking language model, and any phrase in the target text is masked to obtain the masked target text. The first text and the masked target text are concatenated to obtain the third text. The third text is input into the cross-language masked language model to obtain multiple candidate phrases, and the candidate phrase with the highest prediction probability is determined from the multiple candidate phrases; Replace any of the phrases with the candidate phrase with the highest predicted probability to obtain the second text.
4. The method according to claim 1, characterized in that, The step of determining the first similarity reduction rate based on the source text and the corresponding adversarial sample to be identified includes: The source text is input into a preset forward translation model to translate the source text and obtain the first sample; The first sample is input into a preset reverse translation model to translate the first sample and obtain the first reconstructed sample. The adversarial sample to be identified corresponding to the source text is input into the forward translation model to translate the adversarial sample to be identified corresponding to the source text, thereby obtaining the second sample. The second sample is input into the reverse translation model to translate the second sample and obtain the second reconstructed sample; Based on the source text, the adversarial sample to be identified corresponding to the source text, the first reconstructed sample, and the second reconstructed sample, a first similarity reduction rate is determined.
5. The method according to claim 4, characterized in that, The step of determining the first similarity reduction rate based on the source text, the adversarial sample to be identified corresponding to the source text, the first reconstructed sample, and the second reconstructed sample includes: Based on the source text and the first reconstructed sample, a first similarity is determined between the source text and the first reconstructed sample; Based on the adversarial sample to be identified corresponding to the source text and the second reconstructed sample, a second similarity is determined between the adversarial sample to be identified corresponding to the source text and the second reconstructed sample. Based on the first similarity and the second similarity, the first similarity reduction rate is determined.
6. The method according to claim 4, characterized in that, The step of determining the second similarity reduction rate based on the source text, the target text, and the corresponding adversarial sample to be identified includes: The target text is input into the reverse translation model to translate the target text and obtain a third sample; The third sample is input into the forward translation model to translate the third sample and obtain the third reconstructed sample. The second reconstructed sample is input into the forward translation model to translate the second reconstructed sample, resulting in a fourth reconstructed sample. Based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample, a second similarity reduction rate is determined.
7. The method according to claim 6, characterized in that, The step of determining the second similarity reduction rate based on the target text, the third reconstructed sample, the second sample, and the fourth reconstructed sample includes: Based on the target text and the third reconstructed sample, a third similarity is determined between the target text and the third reconstructed sample; Based on the second sample and the fourth reconstructed sample, a fourth similarity is determined between the second sample and the fourth reconstructed sample; Based on the third similarity and the fourth similarity, the second similarity reduction rate is determined.
8. An apparatus for generating adversarial examples, characterized in that, include: The first processing module is used to obtain the source text to be translated and the target text corresponding to the source text, wherein the target text is the translated text of the source text; The second processing module is used to determine the adversarial sample to be identified corresponding to the source text and the adversarial sample to be identified corresponding to the target text. The third processing module is used to determine a first similarity reduction rate based on the source text and the corresponding adversarial sample to be identified, wherein the first similarity reduction rate is the percentage decrease in similarity calculated by source-target-source round-trip translation of the source text and the corresponding adversarial sample to be identified; and to determine a second similarity reduction rate based on the source text, the target text, and the corresponding adversarial sample to be identified, wherein the second similarity reduction rate is the percentage decrease in similarity calculated by target-source-target round-trip translation of the target text and the second sample, wherein the second sample is obtained by translating the corresponding adversarial sample to be identified from the source text using a forward translation model; The fourth processing module is used to determine, if the first similarity decrease rate is greater than a preset first similarity decrease rate threshold and the second similarity decrease rate is less than a preset second similarity decrease rate threshold, the adversarial sample to be identified corresponding to the source text is an adversarial sample of the source text, and the adversarial sample to be identified corresponding to the target text is an adversarial sample of the target text.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-7.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-7.