{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:ACTIHA2FCR45DNOSVD3COY4TKP","short_pith_number":"pith:ACTIHA2F","schema_version":"1.0","canonical_sha256":"00a68383451479d1b5d2a8f627639353ca619aeea22c7909fa307998fb411868","source":{"kind":"arxiv","id":"2004.09984","version":3},"attestation_state":"computed","paper":{"title":"BERT-ATTACK: Adversarial Attack Against BERT Using BERT","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Linyang Li, Qipeng Guo, Ruotian Ma, Xiangyang Xue, Xipeng Qiu","submitted_at":"2020-04-21T13:30:02Z","abstract_excerpt":"Adversarial attacks for discrete data (such as texts) have been proved significantly more challenging than continuous data (such as images) since it is difficult to generate adversarial samples with gradient-based methods. Current successful attack methods for texts usually adopt heuristic replacement strategies on the character or word level, which remains challenging to find the optimal solution in the massive space of possible combinations of replacements while preserving semantic consistency and language fluency. In this paper, we propose \\textbf{BERT-Attack}, a high-quality and effective "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2004.09984","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2020-04-21T13:30:02Z","cross_cats_sorted":[],"title_canon_sha256":"3272ba78737d747fd77bdeb3f092e7f2bd89d1256590a9a0e5de4b5e7a762e90","abstract_canon_sha256":"ac225bd20c1c63fb14cc0d3d6e0f703007d828c4586fb0cc7f2020f2882627de"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:39:43.268959Z","signature_b64":"pgjwZ2GBHFYHYFyxFQtYXDuyMmqcuabzJeRSRh3b2SLGnnhRkGeUre1ZQsqIL5uOhKB/mc6vTVv8ETo9Ea9mBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"00a68383451479d1b5d2a8f627639353ca619aeea22c7909fa307998fb411868","last_reissued_at":"2026-07-05T01:39:43.268546Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:39:43.268546Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"BERT-ATTACK: Adversarial Attack Against BERT Using BERT","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Linyang Li, Qipeng Guo, Ruotian Ma, Xiangyang Xue, Xipeng Qiu","submitted_at":"2020-04-21T13:30:02Z","abstract_excerpt":"Adversarial attacks for discrete data (such as texts) have been proved significantly more challenging than continuous data (such as images) since it is difficult to generate adversarial samples with gradient-based methods. Current successful attack methods for texts usually adopt heuristic replacement strategies on the character or word level, which remains challenging to find the optimal solution in the massive space of possible combinations of replacements while preserving semantic consistency and language fluency. In this paper, we propose \\textbf{BERT-Attack}, a high-quality and effective "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2004.09984","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2004.09984/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2004.09984","created_at":"2026-07-05T01:39:43.268607+00:00"},{"alias_kind":"arxiv_version","alias_value":"2004.09984v3","created_at":"2026-07-05T01:39:43.268607+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2004.09984","created_at":"2026-07-05T01:39:43.268607+00:00"},{"alias_kind":"pith_short_12","alias_value":"ACTIHA2FCR45","created_at":"2026-07-05T01:39:43.268607+00:00"},{"alias_kind":"pith_short_16","alias_value":"ACTIHA2FCR45DNOS","created_at":"2026-07-05T01:39:43.268607+00:00"},{"alias_kind":"pith_short_8","alias_value":"ACTIHA2F","created_at":"2026-07-05T01:39:43.268607+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.17288","citing_title":"When Efficiency Backfires: Cascading LLMs Trigger Cascade Failure under Adversarial Attack","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2512.07222","citing_title":"Pay Less Attention to Function Words for Free Robustness of Vision-Language Models","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07403","citing_title":"RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement","ref_index":18,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP","json":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP.json","graph_json":"https://pith.science/api/pith-number/ACTIHA2FCR45DNOSVD3COY4TKP/graph.json","events_json":"https://pith.science/api/pith-number/ACTIHA2FCR45DNOSVD3COY4TKP/events.json","paper":"https://pith.science/paper/ACTIHA2F"},"agent_actions":{"view_html":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP","download_json":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP.json","view_paper":"https://pith.science/paper/ACTIHA2F","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2004.09984&json=true","fetch_graph":"https://pith.science/api/pith-number/ACTIHA2FCR45DNOSVD3COY4TKP/graph.json","fetch_events":"https://pith.science/api/pith-number/ACTIHA2FCR45DNOSVD3COY4TKP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP/action/storage_attestation","attest_author":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP/action/author_attestation","sign_citation":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP/action/citation_signature","submit_replication":"https://pith.science/pith/ACTIHA2FCR45DNOSVD3COY4TKP/action/replication_record"}},"created_at":"2026-07-05T01:39:43.268607+00:00","updated_at":"2026-07-05T01:39:43.268607+00:00"}