Pith. sign in

REVIEW 1 cited by

Analyzing Adversarial Attacks on Sequence-to-Sequence Relevance Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2403.07654 v1 pith:BMMEEQB6 submitted 2024-03-12 cs.IR

classification cs.IR
keywords relevancemodelsdocumentspromptsequence-to-sequenceadversarialattacksinjection
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Modern sequence-to-sequence relevance models like monoT5 can effectively capture complex textual interactions between queries and documents through cross-encoding. However, the use of natural language tokens in prompts, such as Query, Document, and Relevant for monoT5, opens an attack vector for malicious documents to manipulate their relevance score through prompt injection, e.g., by adding target words such as true. Since such possibilities have not yet been considered in retrieval evaluation, we analyze the impact of query-independent prompt injection via manually constructed templates and LLM-based rewriting of documents on several existing relevance models. Our experiments on the TREC Deep Learning track show that adversarial documents can easily manipulate different sequence-to-sequence relevance models, while BM25 (as a typical lexical model) is not affected. Remarkably, the attacks also affect encoder-only relevance models (which do not rely on natural language prompt tokens), albeit to a lesser extent.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Adversarial Text Generation with Dynamic Contextual Perturbation

    cs.CR 2025-06 reject novelty 4.0 of 10

    An NLP attack that swaps gradient-important words with synonyms while minimizing BERT embedding distance is reported to beat PWWS and BERT-Attack on accuracy drop, perturbation rate, and queries, but the paper gives n...

Pith tools