Open xyf-lsy opened 4 years ago
Hello, lousylove,
It's been a long time. I remember I tested with three methods, see some results here: https://gongzhitaao.org/adversarial-text/ I remember DeepFool was the best. On that page, the numbers are accuracies before and after knn rounding.
Hello, I recently read your article carefully, but I am curious why the direct attack success rate in embedding is so low, and I also tried the round operation, but found that basically all the words are rounded back to the original Words,I wonder what techniques did you use?