Cross-Entropy Attacks to Language Models via Rare Event Simulation