模式识别与人工智能
Friday, Apr. 4, 2025 Home      About Journal      Editorial Board      Instructions      Ethics Statement      Contact Us                   中文
Pattern Recognition and Artificial Intelligence  2022, Vol. 35 Issue (3): 254-261    DOI: 10.16451/j.cnki.issn1003-6059.202203005
Researches and Applications Current Issue| Next Issue| Archive| Adv Search |
Gradient-Based Adversarial Ranking Attack
WU Chen1,2, ZHANG Ruqing1,2, GUO Jiafeng1,2, FAN Yixing1,2
1. Key Laboratory of Network Data Science and Technology, In-stitute of Computing Technology, Chinese Academy of Sciences, Beijing 100190;
2. School of Computer and Control Engineering, University of Chinese Academy of Sciences, Beijing 100190

Download: PDF (706 KB)   HTML (1 KB) 
Export: BibTeX | EndNote (RIS)      
Abstract  Ranking competition is prevalent in Web retrieval, and undesirable effects are caused by this adversarial attack behavior. Thus, the study on attack methods is conducive to designing a more robust ranking model.The existing attack methods are recognized by people easily and cannot attack neural ranking models effectively.In this paper, a gradient-based adversarial attack method(GARA) is proposed, including gradient-based word importance ranking, gradient-based adversarial ranking attack and embedding-based word replacement. Given a target ranking model, the backpropagation is firstly conducted based on the constructed ranking-based adversarial attack objective. Then the most important words of a specific document is recognized based on the gradient information. These important words are perturbed in the word embedding space based on the projected gradient descent. Finally, by adopting the counter-fitting technology, the document perturbation is completed by substituting the important word with its synonym which is semantically similar to the original word and nearest to the perturbed word vector.Experiments on MQ2007 and MS MARCO datasets demonstrate the effectiveness of the proposed method.
Key wordsRanking Competition      Adversarial Attack      Gradient-Based Attack      Neural Ranking Model      Web Retrieval     
Received: 16 August 2021     
ZTFLH: TP 391  
Fund:National Natural Science Foundation of China(No.62006218,61902381,61773362,61872338), Project of Beijing Academy of Artificial Intelligence(BAAI)(No.BAAI2019ZD0306), Project of Youth Innovation Promotion Association of CAS(No.20144310,2016102,2021100), the Lenovo-CAS Joint Lab Youth Scientist Project(No.cstc2017jcjyBX0059)
Corresponding Authors: ZHANG Ruqing, Ph.D., assistant professor. Her research interests include natural language processing.   
About author:: WU Chen, Ph.D. candidate. His research interests include information retrieval and na-tural language processing.
GUO Jiafeng, Ph.D., professor. His research interests include data mining and information retrieval.
FAN Yixing, Ph.D., assistant professor. His research interests include data mining and information retrieval.
Service
E-mail this article
Add to my bookshelf
Add to citation manager
E-mail Alert
RSS
Articles by authors
WU Chen
ZHANG Ruqing
GUO Jiafeng
FAN Yixing
Cite this article:   
WU Chen,ZHANG Ruqing,GUO Jiafeng等. Gradient-Based Adversarial Ranking Attack[J]. Pattern Recognition and Artificial Intelligence, 2022, 35(3): 254-261.
URL:  
http://manu46.magtech.com.cn/Jweb_prai/EN/10.16451/j.cnki.issn1003-6059.202203005      OR     http://manu46.magtech.com.cn/Jweb_prai/EN/Y2022/V35/I3/254
Copyright © 2010 Editorial Office of Pattern Recognition and Artificial Intelligence
Address: No.350 Shushanhu Road, Hefei, Anhui Province, P.R. China Tel: 0551-65591176 Fax:0551-65591176 Email: bjb@iim.ac.cn
Supported by Beijing Magtech  Email:support@magtech.com.cn