2433fec2144ccf5fea1c9c5ebdbc3924-Supplemental-Conference.pdf
–Neural Information Processing Systems
For each word, we use WordNet [7] to find its synonyms and build a list of word sets. Inaddition, toavoidreplacement clash, wedonotallowanyword to appear in more than word set. Eventually, top 50 semantically matching pairs are retained for CATER. Since the training data of the victim model is unknown to the malicious users, we randomly select 5M sentences from common crawl data as thebenigncorpus. Numbers in parentheses are resultsofcleandata.
Neural Information Processing Systems
Feb-7-2026, 22:05:14 GMT
- Technology: