REVIEW 4 major objections 6 minor 1 cited by
EMPRA: Embedding Perturbation Rank Attack against Neural Ranking Models
T0 review · 4 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read A black-box attack rewrites documents to promote 96% of targets into the top 10.
desk verdict EMPRA is a genuinely new attack combination with strong evaluations, but the headline 96% number depends on an in-distribution surrogate and the core decoder is left underspecified. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The machinery is the pair (transporter, transformer) acting on sentence embeddings. The transporter computes a normalized gradient of the dot product between the sentence embedding and an anchor embedding, steps along it with size $\eta$, and clips the result to an $\ell_\infty$ ball of radius $\epsilon$ around the original embedding; the transformer $\Pi$ converts that perturbed embedding back into text (Eq. 4). Iterating $N$ times produces candidate adversarial sentences. A second stage inserts each candidate at every position of the document and scores the resulting document with an interpolated measure $\alpha C_{\mathrm{coh}} + (1-\alpha) C_{\mathrm{rel}}$, where coherence comes from a next-sentence-prediction function and relevance from a generic neural ranker; the highest-scoring candidate becomes the adversarial document. The use of a generic ranker rather than a surrogate imitation is what the paper calls 'surrogate-agnostic'.
What would settle it
Measure the reconstruction fidelity of the transformer function on embeddings perturbed exactly as in Eq. (4): for a held-out set of sentences, push the embeddings toward anchor embeddings at the reported $\epsilon=0.01$ and step size $\eta=0.1$, decode with $\Pi$, and compute the distance between the decoded text's embedding and the perturbed target embedding. If that distance is often larger than $\epsilon$, the perturbation loop is not actually moving the decoded text toward the anchor, and the attack should fail; conversely, replacing $\Pi$ with a deliberately weak decoder should measurably reduce the 95.6% top-10 rate reported for the surrogate setting.
Extended reading notes
Core claim
The core discovery is that an effective ranking attack can be generated without imitating the victim model: instead, the attacker perturbs sentence embeddings in a direction that points toward query-relevant anchors, and then converts those perturbed embeddings back into text. EMPRA's transporter function moves each sentence embedding iteratively toward the embeddings of anchor texts—the query, the current top-ranked document, and the sentence in the top document most similar to the target sentence—under an $\ell_\infty$ constraint. Its transformer function maps each intermediate embedding back to lexical form, and re-embedding the decoded text closes the loop. The rewritten sentence is inserted into the target document at the position that best satisfies a combined score of next-sentence coherence and relevance as judged by a generic neural ranker. The paper reports that this pipeline outperforms existing word-, trigger-, and prompt-based attacks on MS MARCO, with the largest gains on documents that start far from the top.
Load-bearing premise
The attack only works if the transformer function can reliably write out fluent sentences whose embeddings match the perturbed target embeddings; if decoding perturbed embeddings is lossy, the iterative refinement loses its guiding signal and the reported rank boosts would not occur.
Editorial extensions
If this is right
- Neural ranking models that rely on cross-encoders appear vulnerable to an attacker who only rewrites documents fluently, without any imitation of the target model.
- Documents ranked in the long tail can be promoted into the top 10 with a single rewritten sentence insertion, implying current rankers place too much weight on the locally added context.
- The attack's imperceptibility metrics suggest that fluency-based defenses (perplexity filters, linguistic-acceptability classifiers) will not catch this family of manipulations.
- If EMPRA's results hold across victim models, then any public generic ranker suffices to launch the attack, so search operators cannot protect themselves by withholding their own ranking model.
- Defense would need to target the embedding-space perturbation itself, for instance by training rankers that are robust to sentence-level embedding shifts, rather than detecting trigger tokens.
Reading between the lines
- The paper leaves the transformer function $\Pi$ unspecified; a replication study should measure how reconstruction error of $\Pi$ grows with perturbation radius and iteration count, since that error bounds whether the gradient signal actually reaches the final text.
- The same embedding-perturbation pipeline could be inverted to demote documents by moving their sentence embeddings away from the query anchors, turning EMPRA into a two-directional content manipulation tool.
- Because the attack's success is measured on one dataset (MS MARCO) and one family of cross-encoder rankers, a direct test on a different corpus or on generative/retrieval-augmented rankers would reveal whether the reported 96% top-10 rate is a property of the method or of the benchmark.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces EMPRA, a black-box attack against neural ranking models. It operates in two stages: sentence embeddings of a target document are iteratively perturbed toward anchor embeddings (the query, the top-ranked document, or a similar sentence from that document) by a transporter function and decoded back to text by a transformer function; the generated texts are then inserted at all positions of the target document, and the final adversarial document is selected by an interpolated score combining BERT NSP coherence and relevance from a generic NRM. Experiments on MS MARCO V1 with the MiniLM victim ranker compare EMPRA with Query+, GPT-4, PRADA, PAT, Brittle-BERT, and IDEM, reporting the best attack metrics overall and low perplexity. The abstract claims that almost 96% of target documents originally ranked 51-100 are moved into the top 10 and that the method does not depend on surrogate models for adversarial text generation.
Significance. If the results are reproducible, EMPRA is a useful contribution to adversarial IR: it demonstrates a practical black-box attack that outperforms several recent baselines while maintaining readability, and the authors release code and experimental data. The significance is currently limited by two unresolved issues: the key decoding component Pi is not specified, and the headline 96% figure is produced by the in-distribution surrogate M_S1 rather than by the generic/surrogate-agnostic configuration emphasized in the abstract. These issues must be addressed before the central claims can be accepted.
major comments (4)
- [Abstract, Section 6.1, Tables 2 and 3] The abstract and Section 1 state that EMPRA 'successfully achieves a re-ranking of almost 96% of target documents originally ranked between 51-100 to rank within the top 10' and that it 'does not depend on surrogate models.' In the paper's own results, the 95.6% Easy-5 value is obtained with M_S1, an in-distribution surrogate trained on 6,837 queries from the victim model's distribution (Section 5.3.2), not with a generic model. The best generic configuration in Table 2 is M_G4, which gives 74.3% Easy-5 and 35.1% Hard-5. The reported 96% therefore belongs to the surrogate-aware setting, not to the surrogate-agnostic setting the abstract emphasizes; the abstract should be reworded and the surrogate-agnostic results should be reported as the headline or explicitly separated.
- [Section 4.1, Eqs. (4)-(5), Algorithm 1] The transformer function Pi is the load-bearing component of the method, but the paper never identifies the model, its training data, its loss, or its decoding accuracy. Eq. (4) and Algorithm 1 line 9 rely on Pi to map every perturbed embedding E(S)^(t+1) back to fluent lexical text whose own embedding matches the target. Without specifying Pi, the core generative claim cannot be checked or reproduced; the authors should provide the implementation details and a quantitative evaluation of reconstruction fidelity.
- [Eq. (4)] The gradient notation in Eq. (4) is ambiguous: the derivative is written as partial derivative with respect to S while S denotes a discrete sentence, yet the quantity inside the norm is E(S)^(t) dot E(A) over the product of norms. If the gradient is taken with respect to the continuous embedding coordinates, this should be stated explicitly; if it is taken with respect to text, the expression is not well-defined. The iterative refinement of a textual hypothesis H(i) described in Section 4.1 also does not appear in the loop of Algorithm 1, so the actual decoding procedure is unclear.
- [Section 4.2, Eq. (8), Algorithm 1] The claim that EMPRA 'does not depend on surrogate models for adversarial text generation' is too broad. In Stage 2, Eq. (8) and Algorithm 1 lines 22-24 use a generic NRM M_G to score every candidate by query relevance and to select the final adversarial document. This is a dependence on an external ranking model even if M_G is not trained on the victim's pseudo-labels. The authors should either relax the wording or provide an analysis showing that the candidate selection does not drive the reported attack success.
minor comments (6)
- [Table 3] In the Hard-5 block the column header 'Readibility' is misspelled and should be 'Readability'.
- [Section 6.2 (ii)] The text states that Brittle-BERT's boosted top-10 decreases 'from 81.3% to 33.2% and 43.4%'; Table 3 reports 43.4% for M_Gbest on Easy-5, so the 33.2 value appears to be a typo.
- [Section 5.3.5 and Section 6.4] The perturbation bound epsilon and step size eta are fixed at 0.01 and 0.1 respectively without a sensitivity analysis; Section 6.4 ablates only the number of iterations and the interpolation coefficient alpha, not epsilon or eta.
- [Figures 2 and 3] The captions of Figures 2 and 3 do not identify the plotted metric or the curve labels, and the text does not describe the axes; please expand the captions or explain the figures in the body.
- [Section 6.5 and Table 6] The human evaluation uses only two annotators on the 32 Mixture documents, and the reported kappa values are very low (for example 0.01 for fluency), so the imperceptibility and fluency conclusions should be presented with appropriate caution.
- [Manuscript header] The ACM reference format line in the header lists the year 2018 while the submission is from 2024/2025; this should be corrected.
Circularity Check
The abstract's 'almost 96%' headline is produced by the in-distribution surrogate M_S1, not by the surrogate-agnostic M_G configuration, whose best number is 74.3%; the method's final selection also optimizes an external ranker's relevance score.
-
fitted input called prediction
[Abstract; Section 5.3.2; Section 6.1 (Table 2); Section 7]
"Specifically, EMPRA successfully achieves a re-ranking of almost 96% of target documents originally ranked between 51-100 to rank within the top 10. Furthermore, EMPRA does not depend on surrogate models for adversarial text generation... M_S1: Trained on the full set of 6,837 eval small queries from MS MARCO, serving as an ID surrogate model... M_S1 achieves the highest %r≤10 (95.6%)"
The abstract and conclusion attribute the 'almost 96%' result to EMPRA without qualification, immediately after claiming surrogate independence. Inside the paper, that 96% is the M_S1 row: M_S1 is an in-distribution surrogate fitted to the victim model using 6,837 pseudo-relevance queries generated by querying the victim. The surrogate-agnostic configuration is M_Gbest, which Table 3 reports at 74.3% for Easy-5 %r≤10, and the best generic model in Table 2 (M_G1) reaches only 85.2%. Thus the flagship number is not a surrogate-free result; it is a surrogate-fitted result presented as the method's headline, and the claimed independence from surrogate models is not supported by the number that carries the claim.
-
self definitional
[Section 4.2, Eq. (8), Eq. (9); Algorithm 1 Stage 2 (lines 12-27)]
"To calculate the relevance score between each adversarial candidate and the query in the black-box setting, our proposed surrogate-agnostic attacking model utilizes the relevance scoring function of a generic neural ranking model M_G, as follows: C_rel(q,d_adv_i,p)=f_rel(q,d_adv_i,p). ... The adversarial document d_adv for the target document d would be the candidate with the highest Score_interp"
The final adversarial document is, by construction, selected as the candidate maximizing an interpolation that includes f_rel(., M_G) (Eq. 8, Eq. 9). When M_G is replaced by the surrogate M_S1, the 96% result is literally the output of a candidate-selection procedure driven by a surrogate trained on the victim's own re-ranked lists. Calling this 'surrogate-agnostic' works only under the paper's narrow definition, which excludes Models trained on pseudo-relevance labels but still allows a ranking model to make the decisive choice.
full rationale
EMPRA is evaluated against strong external baselines and reports extensive empirical comparisons, so the attack itself has independent content and is not a pure re-derivation of its inputs. However, the central framing is partially circular. The headline 96% figure in the abstract and conclusion is the M_S1 row, where M_S1 is an in-distribution surrogate trained by querying the victim model with 6,837 eval queries, while the paper's own surrogate-agnostic (M_Gbest) result is 74.3%. The selection stage in Algorithm 1 and Eq. (8)-(9) also optimizes an external ranker's relevance score, so the 'no surrogate model' claim applies only to the candidate-generation stage. The unspecified transformer function Pi is a real correctness risk but not a circularity, since it is an implementation gap rather than a conclusion that equals its premise. There are no load-bearing self-citations or imported uniqueness theorems. The circularity is thus concentrated in the claim architecture: the flagship result is generated by the very surrogate dependence the abstract disclaims, and the surrogate-agnostic terminology is defined so that using a generic ranker still counts as agnostic. This warrants a 6 rather than a higher score because the underlying experiments, tables, and baselines still carry independent empirical information.
Assumptions & free parameters
free parameters (4)
- Perturbation bound epsilon =
0.01
- Step size eta =
0.1
- Max iterations N =
25
- Interpolation coefficient alpha =
0.5
assumptions (4)
- domain assumption Sentence embeddings are differentiable with respect to the input text, so the gradient in Eq. (4) can be computed and used to move E(S) toward E(A).
- ad hoc to paper The transformer function Π can decode any perturbed embedding into fluent lexical text while preserving the embedding's semantic content.
- domain assumption NSP score and generic NRM relevance score are valid proxies for coherence and query relevance in the black-box setting.
- domain assumption MS MARCO dev queries and BM25 top-1000 candidates are representative of realistic attack scenarios.
Cite this review
Pith. "Pith review of EMPRA: Embedding Perturbation Rank Attack against Neural Ranking Models." pith.science (2026). https://pith.science/paper/7RTGDRMP
@misc{pith2026241216382,
author = {Pith},
title = {Pith review of: EMPRA: Embedding Perturbation Rank Attack against Neural Ranking Models},
year = {2026},
howpublished = {\url{https://pith.science/paper/7RTGDRMP}},
note = {Machine review of arXiv:2412.16382}
}
read the original abstract
Recent research has shown that neural information retrieval techniques may be susceptible to adversarial attacks. Adversarial attacks seek to manipulate the ranking of documents, with the intention of exposing users to targeted content. In this paper, we introduce the Embedding Perturbation Rank Attack (EMPRA) method, a novel approach designed to perform adversarial attacks on black-box Neural Ranking Models (NRMs). EMPRA manipulates sentence-level embeddings, guiding them towards pertinent context related to the query while preserving semantic integrity. This process generates adversarial texts that seamlessly integrate with the original content and remain imperceptible to humans. Our extensive evaluation conducted on the widely-used MS MARCO V1 passage collection demonstrate the effectiveness of EMPRA against a wide range of state-of-the-art baselines in promoting a specific set of target documents within a given ranked results. Specifically, EMPRA successfully achieves a re-ranking of almost 96% of target documents originally ranked between 51-100 to rank within the top 10. Furthermore, EMPRA does not depend on surrogate models for adversarial text generation, enhancing its robustness against different NRMs in realistic settings.
Figures
Forward citations
Cited by 1 Pith paper
-
Evaluating the Robustness of Retrieval-Augmented Generation to Adversarial Evidence in the Health Domain
Misleading health documents in RAG context sharply lower LLM accuracy, and heavily helpful-biased retrieval pools restore it.
Reference graph
Works this paper leans on
-
[1]
Naveed Akhtar and Ajmal Mian. 2018. Threat of adversarial attacks on deep learning in computer vision: A survey.Ieee Access 6 (2018), 14410–14430
work page 2018
-
[2]
Naveed Akhtar, Ajmal Mian, Navid Kardan, and Mubarak Shah. 2021. Advances in adversarial attacks and defenses in computer vision: A survey. IEEE Access 9 (2021), 155161–155196
work page 2021
-
[3]
Bowman, Gabor Angeli, Christopher Potts, and Christopher D
Samuel R. Bowman, Gabor Angeli, Christopher Potts, and Christopher D. Manning. 2015. A large annotated corpus for learning natural language inference. In Proceedings of the 2015 Conference on Empirical Methods in Natural Language Processing , Lluís Màrquez, Chris Callison-Burch, and Jian Su (Eds.). Association for Computational Linguistics, Lisbon, Portug...
-
[4]
Tom B Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer. 2017. Adversarial patch. arXiv preprint arXiv:1712.09665 (2017)
arXiv 2017
-
[5]
Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). Ieee, 39–57
2017
-
[6]
Carlos Castillo, Brian D Davison, et al. 2011. Adversarial web search. Foundations and trends® in information retrieval 4, 5 (2011), 377–486
2011
-
[7]
Jingfan Chen, Wenqi Fan, Guanghui Zhu, Xiangyu Zhao, Chunfeng Yuan, Qing Li, and Yihua Huang. 2022. Knowledge-enhanced black-box attacks for recommendations. In Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining . 108–117
work page 2022
-
[8]
Xuanang Chen, Ben He, Zheng Ye, Le Sun, and Yingfei Sun. 2023. Towards Imperceptible Document Manipulations against Neural Ranking Models. In Findings of the Association for Computational Linguistics: ACL 2023 , Anna Rogers, Jordan Boyd-Graber, and Naoaki Okazaki (Eds.). Association for Computational Linguistics, Toronto, Canada, 6648–6664. https://doi.or...
Show all 68 references
-
[9]
Gordon V Cormack, Mark D Smucker, and Charles LA Clarke. 2011. Efficient and effective spam filtering and re-ranking for large web datasets. Information retrieval 14 (2011), 441–465
2011
-
[10]
Edgar Dale and Jeanne S Chall. 1948. A formula for predicting readability: Instructions. Educational research bulletin (1948), 37–54
1948
-
[11]
Yashar Deldjoo, Tommaso Di Noia, and Felice Antonio Merra. 2021. A survey on adversarial recommender systems: from attack/defense strategies to generative adversarial networks. ACM Computing Surveys (CSUR) 54, 2 (2021), 1–38
2021
-
[12]
Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human...
2019
-
[13]
Javid Ebrahimi, Anyi Rao, Daniel Lowd, and Dejing Dou. 2018. HotFlip: White-Box Adversarial Examples for Text Classification. InProceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 2: Short Papers) , Iryna Gurevych and Yusuke Miyao (E...
2018 doi
-
[14]
Wenqi Fan, Xiangyu Zhao, Xiao Chen, Jingran Su, Jingtong Gao, Lin Wang, Qidong Liu, Yiqi Wang, Han Xu, Lei Chen, et al. 2022. A comprehensive survey on trustworthy recommender systems. arXiv preprint arXiv:2209.10117 (2022)
2022 arXiv
-
[15]
Wenqi Fan, Xiangyu Zhao, Qing Li, Tyler Derr, Yao Ma, Hui Liu, Jianping Wang, and Jiliang Tang. 2023. Adversarial Attacks for Black-Box Recommender Systems Via Copying Transferable Cross-Domain User Profiles. IEEE Transactions on Knowledge and Data Engineering (2023)
2023
-
[16]
Minghong Fang, Neil Zhenqiang Gong, and Jia Liu. 2020. Influence function based data poisoning attacks to top-n recommender systems. In Proceedings of The Web Conference 2020 . 3019–3025
2020
-
[17]
Minghong Fang, Guolei Yang, Neil Zhenqiang Gong, and Jia Liu. 2018. Poisoning attacks to graph-based recommender systems. In Proceedings of the 34th annual computer security applications conference . 381–392
2018
-
[18]
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)
2014 arXiv
-
[19]
Shreya Goyal, Sumanth Doddapaneni, Mitesh M Khapra, and Balaraman Ravindran. 2023. A survey of adversarial defenses and robustness in nlp. Comput. Surveys 55, 14s (2023), 1–39
2023
-
[20]
Grammarly. 2023. Grammarly. https://app.grammarly.com/ Accessed: 2023-05-28
2023
-
[21]
Zoltán Gyöngyi, Hector Garcia-Molina, et al. 2005. Web Spam Taxonomy.. In AIRWeb, Vol. 5. Citeseer, 39–47
2005
-
[22]
Niddal H Imam and Vassilios G Vassilakis. 2019. A survey of attacks against twitter spam detectors in an adversarial environment. Robotics 8, 3 (2019), 50
2019
-
[23]
Di Jin, Zhijing Jin, Joey Tianyi Zhou, and Peter Szolovits. 2020. Is BERT really robust? a strong baseline for natural language attack on text classification and entailment. In Proceedings of the AAAI conference on artificial intelligence , Vol. 34. 8018–8025
2020
-
[24]
Vladimir Karpukhin, Barlas Oguz, Sewon Min, Patrick Lewis, Ledell Wu, Sergey Edunov, Danqi Chen, and Wen-tau Yih. 2020. Dense Passage Retrieval for Open-Domain Question Answering. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP)...
2020 doi
-
[25]
Tom Kwiatkowski, Jennimaria Palomaki, Olivia Redfield, Michael Collins, Ankur Parikh, Chris Alberti, Danielle Epstein, Illia Polosukhin, Jacob Devlin, Kenton Lee, et al. 2019. Natural questions: a benchmark for question answering research. Transactions of the Association for C...
2019
-
[26]
Mike Lewis, Yinhan Liu, Naman Goyal, Marjan Ghazvininejad, Abdelrahman Mohamed, Omer Levy, Veselin Stoyanov, and Luke Zettlemoyer. 2020. BART: Denoising Sequence-to-Sequence Pre-training for Natural Language Generation, Translation, and Comprehension. In Proceedings of the 58t...
2020
-
[27]
Linyang Li, Ruotian Ma, Qipeng Guo, Xiangyang Xue, and Xipeng Qiu. 2020. BERT-ATTACK: Adversarial Attack Against BERT Using BERT. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP) , Bonnie Webber, Trevor Cohn, Yulan He, and Yang ...
2020 doi
-
[28]
Chen Lin, Si Chen, Hui Li, Yanghua Xiao, Lianyun Li, and Qian Yang. 2020. Attacking recommender systems with augmented user profiles. In Proceedings of the 29th ACM international conference on information & knowledge management . 855–864
2020
-
[29]
Jimmy Lin, Rodrigo Nogueira, and Andrew Yates. 2022. Pretrained transformers for text ranking: Bert and beyond . Springer Nature
2022
-
[30]
Jiawei Liu, Yangyang Kang, Di Tang, Kaisong Song, Changlong Sun, Xiaofeng Wang, Wei Lu, and Xiaozhong Liu. 2022. Order-Disorder: Imitation Adversarial Attacks for Black-box Neural Ranking Models. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications S...
2022
-
[31]
Yu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke, Wei Chen, Yixing Fan, and Xueqi Cheng. 2023. Black-box Adversarial Attacks against Dense Retrieval Models: A Multi-view Contrastive Learning Method. In Proceedings of the 32nd ACM International Conference on Information a...
2023
-
[32]
Yu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke, Wei Chen, Yixing Fan, and Xueqi Cheng. 2023. Topic-oriented Adversarial Attacks against Black-box Neural Ranking Models. In Proceedings of the 46th International ACM SIGIR Conference on Research and Development in Informa...
2023
-
[33]
Yu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke, Yixing Fan, and Xueqi Cheng. 2024. Multi-granular Adversarial Attacks against Black-box Neural Ranking Models. In Proceedings of the 47th International ACM SIGIR Conference on Research and Development in Information Retri...
2024
-
[34]
Teng Long, Qi Gao, Lili Xu, and Zhangbing Zhou. 2022. A survey on adversarial attacks in computer vision: Taxonomy, visualization and future directions. Computers & Security 121 (2022), 102847
2022
-
[35]
Gallil Maimon and Lior Rokach. 2022. A universal adversarial policy for text classifiers. Neural Networks 153 (2022), 282–291. Manuscript submitted to ACM EMPRA: Embedding Perturbation Rank Attack against Neural Ranking Models 27
2022
-
[36]
Tri Nguyen, Mir Rosenberg, Xia Song, Jianfeng Gao, Saurabh Tiwary, Rangan Majumder, and Li Deng. 2016. Ms marco: A human-generated machine reading comprehension dataset. (2016)
2016
-
[37]
Jianmo Ni, Gustavo Hernandez Abrego, Noah Constant, Ji Ma, Keith Hall, Daniel Cer, and Yinfei Yang. 2022. Sentence-T5: Scalable Sentence Encoders from Pre-trained Text-to-Text Models. InFindings of the Association for Computational Linguistics: ACL 2022 , Smaranda Muresan, Pre...
2022 doi
-
[38]
Rodrigo Nogueira and Kyunghyun Cho. 2019. Passage Re-ranking with BERT. arXiv preprint arXiv:1901.04085 (2019)
2019 arXiv
-
[39]
Rodrigo Nogueira, Zhiying Jiang, Ronak Pradeep, and Jimmy Lin. 2020. Document Ranking with a Pretrained Sequence-to-Sequence Model. In Findings of the Association for Computational Linguistics: EMNLP 2020 , Trevor Cohn, Yulan He, and Yang Liu (Eds.). Association for Computatio...
2020 doi
-
[40]
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016. Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE symposium on security and privacy (SP) . IEEE, 582–597
2016
-
[41]
P Patil Swati, BV Pawar, and S Patil Ajay. 2013. Search engine optimization: A study. Research Journal of Computer and Information Technology Sciences 1, 1 (2013), 10–13
2013
-
[42]
Gustavo Penha, Arthur Câmara, and Claudia Hauff. 2022. Evaluating the robustness of retrieval pipelines with query variation generators. In European conference on information retrieval . Springer, 397–412
2022
-
[43]
Ronak Pradeep, Rodrigo Nogueira, and Jimmy Lin. 2021. The expando-mono-duo design pattern for text ranking with pretrained sequence-to- sequence models. arXiv preprint arXiv:2101.05667 (2021)
2021 arXiv
-
[44]
Shilin Qiu, Qihe Liu, Shijie Zhou, and Wen Huang. 2022. Adversarial attack and defense technologies in natural language processing: A survey. Neurocomputing 492 (2022), 278–307
2022
-
[45]
Alec Radford, Jeffrey Wu, Rewon Child, David Luan, Dario Amodei, Ilya Sutskever, et al. 2019. Language models are unsupervised multitask learners. OpenAI blog 1, 8 (2019), 9
2019
-
[46]
Pranav Rajpurkar, Robin Jia, and Percy Liang. 2018. Know What You Don‘t Know: Unanswerable Questions for SQuAD. In Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 2: Short Papers) , Iryna Gurevych and Yusuke Miyao (Eds.). Associa...
2018 doi
-
[47]
Nisarg Raval and Manisha Verma. 2020. One word at a time: adversarial attacks on retrieval models. arXiv preprint arXiv:2008.02197 (2020)
2020 arXiv
-
[48]
Nils Reimers and Iryna Gurevych. 2019. Sentence-BERT: Sentence Embeddings using Siamese BERT-Networks. In Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP- IJ...
2019 doi
-
[49]
Stephen E Robertson and Steve Walker. 1994. Some simple effective approximations to the 2-poisson model for probabilistic weighted retrieval. In SIGIR’94: Proceedings of the Seventeenth Annual International ACM-SIGIR Conference on Research and Development in Information Retrie...
1994
-
[50]
Victor Sanh, Lysandre Debut, Julien Chaumond, and Thomas Wolf. 2019. DistilBERT, a distilled version of BERT: smaller, faster, cheaper and lighter. arXiv preprint arXiv:1910.01108 (2019)
2019 arXiv
-
[51]
Minoru Sasaki and Hiroyuki Shinnou. 2005. Spam detection using text clustering. In 2005 International Conference on Cyberworlds (CW’05) . IEEE, 4–pp
2005
-
[52]
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter. 2016. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 acm sigsac conference on computer and communications security . 1528–1540
2016
-
[53]
Bhambri Siddhant, Muku Sumanyu, Tulasi Avinash, and Buduru Arun Balaji. 2019. A survey of black-box adversarial attacks on computer vision models. arXiv preprint arXiv:1912.01667 (2019)
2019 arXiv
-
[54]
Congzheng Song, Alexander Rush, and Vitaly Shmatikov. 2020. Adversarial Semantic Collisions. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP) , Bonnie Webber, Trevor Cohn, Yulan He, and Yang Liu (Eds.). Association for Computati...
2020 doi
-
[55]
Junshuai Song, Zhao Li, Zehong Hu, Yucheng Wu, Zhenpeng Li, Jian Li, and Jun Gao. 2020. Poisonrec: an adaptive data poisoning framework for attacking black-box recommender systems. In 2020 IEEE 36th International Conference on Data Engineering (ICDE) . IEEE, 157–168
2020
-
[56]
Junshuai Song, Jiangshan Zhang, Jifeng Zhu, Mengyun Tang, and Yong Yang. 2022. TRAttack: Text rewriting attack against text retrieval. In Proceedings of the 7th Workshop on Representation Learning for NLP . 191–203
2022
-
[57]
Kaitao Song, Xu Tan, Tao Qin, Jianfeng Lu, and Tie-Yan Liu. 2020. Mpnet: Masked and permuted pre-training for language understanding. Advances in neural information processing systems 33 (2020), 16857–16867
2020
-
[58]
Wenhui Wang, Furu Wei, Li Dong, Hangbo Bao, Nan Yang, and Ming Zhou. 2020. Minilm: Deep self-attention distillation for task-agnostic compression of pre-trained transformers. Advances in Neural Information Processing Systems 33 (2020), 5776–5788
2020
-
[59]
Yumeng Wang, Lijun Lyu, and Avishek Anand. 2022. BERT rankers are brittle: a study using adversarial document perturbations. In Proceedings of the 2022 ACM SIGIR International Conference on Theory of Information Retrieval . 115–120
2022
-
[60]
Zongwei Wang, Min Gao, Jundong Li, Junwei Zhang, and Jiang Zhong. 2022. Gray-box shilling attack: an adversarial learning approach. ACM Transactions on Intelligent Systems and Technology (TIST) 13, 5 (2022), 1–21. Manuscript submitted to ACM 28 Bigdeli et al
2022
-
[61]
Zongwei Wang, Junliang Yu, Min Gao, Wei Yuan, Guanhua Ye, Shazia Sadiq, and Hongzhi Yin. 2024. Poisoning Attacks and Defenses in Recommender Systems: A Survey. arXiv preprint arXiv:2406.01022 (2024)
2024 arXiv
-
[62]
Alex Warstadt, Amanpreet Singh, and Samuel R Bowman. 2019. Neural network acceptability judgments. Transactions of the Association for Computational Linguistics 7 (2019), 625–641
2019
-
[63]
Chenwang Wu, Defu Lian, Yong Ge, Zhihao Zhu, and Enhong Chen. 2021. Triple adversarial learning for influence based poisoning attack in recommender systems. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining . 1830–1840
2021
-
[64]
Chen Wu, Ruqing Zhang, Jiafeng Guo, Wei Chen, Yixing Fan, Maarten de Rijke, and Xueqi Cheng. 2022. Certified Robustness to Word Substitution Ranking Attack for Neural Ranking Models. In Proceedings of the 31st ACM International Conference on Information & Knowledge Management ...
2022
-
[65]
Chen Wu, Ruqing Zhang, Jiafeng Guo, Maarten De Rijke, Yixing Fan, and Xueqi Cheng. 2023. Prada: practical black-box adversarial attacks against neural ranking models. ACM Transactions on Information Systems 41, 4 (2023), 1–27
2023
-
[66]
Zexuan Zhong, Ziqing Huang, Alexander Wettig, and Danqi Chen. 2023. Poisoning Retrieval Corpora by Injecting Adversarial Passages. InProceedings of the 2023 Conference on Empirical Methods in Natural Language Processing , Houda Bouamor, Juan Pino, and Kalika Bali (Eds.). Assoc...
2023 doi
-
[67]
Bin Zhou and Jian Pei. 2009. OSD: An online web spam detection system. In In Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD , Vol. 9
2009
-
[68]
Wei Zou, Shujian Huang, Jun Xie, Xinyu Dai, and Jiajun Chen. 2020. A Reinforced Generation of Adversarial Examples for Neural Machine Translation. In Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics , Dan Jurafsky, Joyce Chai, Natalie Sch...
2020 doi
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.