Exploiting Class Probabilities for Black-box Sentence-level Attacks