Review Article

Text Adversarial Attacks and Defenses: Issues, Taxonomy, and Perspectives

Table 3

Categories of adversarial attacks (from perturbation level to methods).

Perturbation levelAttack phaseAccess knowledgeRelative work

CharLocationBlind[79]
PerturbationGradient[28, 80]
Blind[27, 29, 79, 8183]

WordLocationGradient[29, 61, 81, 84, 8489]
Score[7, 27, 8994]
PerturbationGradient[6, 42, 90, 9598]
Score[92, 99106]
Decision[107, 108]
Blind[29, 60, 85, 93, 101, 109111]

SentencePerturbationScore[45, 93, 112]
Decision[7, 113]
Blind[86, 114]
GenerationGradient[115]
Score[59, 116]
Decision[19, 44, 58, 59, 64, 117]
Blind[43, 60, 118]

HybridGenerationScore[119]