Pith. sign in

REVIEW 4 cited by

One word at a time: adversarial attacks on retrieval models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2008.02197 v1 pith:ZXJBRZRW submitted 2020-08-05 cs.IR

classification cs.IR
keywords adversarialexamplesmodelsrobustnessrankingapproachattackerdocuments
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial examples, generated by applying small perturbations to input features, are widely used to fool classifiers and measure their robustness to noisy inputs. However, little work has been done to evaluate the robustness of ranking models through adversarial examples. In this work, we present a systematic approach of leveraging adversarial examples to measure the robustness of popular ranking models. We explore a simple method to generate adversarial examples that forces a ranker to incorrectly rank the documents. Using this approach, we analyze the robustness of various ranking models and the quality of perturbations generated by the adversarial attacker across two datasets. Our findings suggest that with very few token changes (1-3), the attacker can yield semantically similar perturbed documents that can fool different rankers into changing a document's score, lowering its rank by several positions.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Search results diversification in competitive search

    cs.IR 2025-01 reject novelty 6.0 of 10

    The paper argues, via game theory and student ranking competitions, that diversity-based search ranking reduces 'mimicking the winner' herding, but the equilibrium proof and the empirical test are both flawed.

  2. Attack-in-the-Chain: Bootstrapping Large Language Models for Attacks Against Black-box Neural Ranking Models

    cs.IR 2024-12 conditional novelty 6.0 of 10

    Attack-in-the-Chain uses chain-of-thought prompting to iteratively select anchor documents and allocate word-level perturbations, boosting target documents in black-box neural ranking models on MS MARCO and TREC DL19.

  3. EMPRA: Embedding Perturbation Rank Attack against Neural Ranking Models

    cs.IR 2024-12 conditional novelty 6.0 of 10

    A sentence-level embedding perturbation attack can promote target documents into top-10 neural ranking results, but its headline success depends on a surrogate ranker despite claiming to be surrogate-free.

  4. Reproducing HotFlip for Corpus Poisoning Attacks in Dense Retrieval

    cs.IR 2025-01 conditional novelty 5.0 of 10

    A reproducibility study speeds up HotFlip corpus poisoning 16x with query centroids and shows attack transfer is poor across retrievers while query-agnostic poisoning still hits Contriever.

Pith tools