DiffAttack icon indicating copy to clipboard operation
DiffAttack copied to clipboard

Question about the text perturbation.

Open caosip opened this issue 7 months ago • 3 comments

Hello, I'm really interested in your work! However, I have some questions about the adversarial attack with text perturbation. In Table 5, the adversarial attack with only perturbation on the text could also work, although not the most effective. Could you provide the reproduction codes for this part? I'm curious about how to achieve such results because it seems that text encoders (such as CLIP) don't inherently include semantics about adversarial noise. I would greatly appreciate for your reply!

caosip avatar Jul 23 '24 16:07 caosip