fooling rate
A Appendix
A.1 TPPE Method We present the pseudo code for TPPE in this paper, using the Insertion mode as an example. According to Alg. 1, we reduce the query time complexity from In our study, we assume the worst-case scenario of applying punctuation-level attacks. Softmax layer is adopted to predict the label of the input text. Paraphrase (TPPEP) to achieve a single-shot attack. We describe the TPPEP method as being decomposed into two parts: training and searching.
- Asia > Middle East > UAE > Abu Dhabi Emirate > Abu Dhabi (0.14)
- Oceania > Australia > Australian Capital Territory > Canberra (0.04)
- North America > Canada (0.04)
- Europe > Sweden > Östergötland County > Linköping (0.04)
- Europe > Switzerland (0.04)
- North America > Canada > Quebec > Montreal (0.04)
- North America > Canada (0.05)
- Asia > China (0.05)
- Asia > China (0.04)
- North America > Canada (0.04)
- North America > United States > California > Riverside County > Riverside (0.40)
- Asia (0.04)
- Information Technology > Security & Privacy (0.68)
- Government > Military (0.50)
A Appendix
A.1 TPPE Method We present the pseudo code for TPPE in this paper, using the Insertion mode as an example. According to Alg. 1, we reduce the query time complexity from In our study, we assume the worst-case scenario of applying punctuation-level attacks. Softmax layer is adopted to predict the label of the input text. Paraphrase (TPPEP) to achieve a single-shot attack. We describe the TPPEP method as being decomposed into two parts: training and searching.
- Asia > China (0.04)
- North America > Canada > British Columbia > Metro Vancouver Regional District > Vancouver (0.04)
- Asia > Middle East > UAE > Abu Dhabi Emirate > Abu Dhabi (0.14)
- Oceania > Australia > Australian Capital Territory > Canberra (0.04)
- North America > Canada (0.04)
- Europe > Sweden > Östergötland County > Linköping (0.04)