2022
Character-level White-Box Adversarial Attacks against Transformers via Attachable Subwords Substitution
EMNLP 2022main
We propose the first character-level white-box adversarial attack method against transformer models. The intuition of our method comes from the observation that words are split into subtokens before being fed into the transformer models and the substitution between two close subtokens has a similar…