Prepending single letters to key words makes BPE and WordPiece text classifiers misclassify malicious prompts as benign, while the tested Unigram-based models resist the trick.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.LG 1years
2025 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
TokenBreak: Bypassing Text Classification Models Through Token Manipulation
Prepending single letters to key words makes BPE and WordPiece text classifiers misclassify malicious prompts as benign, while the tested Unigram-based models resist the trick.