{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:DPDQ7CZ373ZBOYHEYUIF2LYQHS","short_pith_number":"pith:DPDQ7CZ3","schema_version":"1.0","canonical_sha256":"1bc70f8b3bfef21760e4c5105d2f103cac4a44f95c24b3af646b7d07c3b92e72","source":{"kind":"arxiv","id":"2005.00174","version":2},"attestation_state":"computed","paper":{"title":"Universal Adversarial Attacks with Natural Triggers for Text Classification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CL","authors_text":"Hsuan-Tung Peng, Karthik Narasimhan, Liwei Song, Xinwei Yu","submitted_at":"2020-05-01T01:58:24Z","abstract_excerpt":"Recent work has demonstrated the vulnerability of modern text classifiers to universal adversarial attacks, which are input-agnostic sequences of words added to text processed by classifiers. Despite being successful, the word sequences produced in such attacks are often ungrammatical and can be easily distinguished from natural text. We develop adversarial attacks that appear closer to natural English phrases and yet confuse classification systems when added to benign inputs. We leverage an adversarially regularized autoencoder (ARAE) to generate triggers and propose a gradient-based search t"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2005.00174","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2020-05-01T01:58:24Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"63acf331aaaa4128c9f27d49470becee8991cdf221ca7dcd38144905c084d09f","abstract_canon_sha256":"66ef8a7b78db4817038a6c2804fa54ba86f9d7f859ffec38bf396c353db1675a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:30:11.915773Z","signature_b64":"yMNMStsq61/movR2mgMtPtrcUe+0KojxMOnpuiWS7xfA3YkjVpPzHHvAnyWY44ZcrtGkKgcxKx0KWMm2lcTEAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1bc70f8b3bfef21760e4c5105d2f103cac4a44f95c24b3af646b7d07c3b92e72","last_reissued_at":"2026-07-05T02:30:11.915259Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:30:11.915259Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Universal Adversarial Attacks with Natural Triggers for Text Classification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.CL","authors_text":"Hsuan-Tung Peng, Karthik Narasimhan, Liwei Song, Xinwei Yu","submitted_at":"2020-05-01T01:58:24Z","abstract_excerpt":"Recent work has demonstrated the vulnerability of modern text classifiers to universal adversarial attacks, which are input-agnostic sequences of words added to text processed by classifiers. Despite being successful, the word sequences produced in such attacks are often ungrammatical and can be easily distinguished from natural text. We develop adversarial attacks that appear closer to natural English phrases and yet confuse classification systems when added to benign inputs. We leverage an adversarially regularized autoencoder (ARAE) to generate triggers and propose a gradient-based search t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2005.00174","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2005.00174/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2005.00174","created_at":"2026-07-05T02:30:11.915320+00:00"},{"alias_kind":"arxiv_version","alias_value":"2005.00174v2","created_at":"2026-07-05T02:30:11.915320+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2005.00174","created_at":"2026-07-05T02:30:11.915320+00:00"},{"alias_kind":"pith_short_12","alias_value":"DPDQ7CZ373ZB","created_at":"2026-07-05T02:30:11.915320+00:00"},{"alias_kind":"pith_short_16","alias_value":"DPDQ7CZ373ZBOYHE","created_at":"2026-07-05T02:30:11.915320+00:00"},{"alias_kind":"pith_short_8","alias_value":"DPDQ7CZ3","created_at":"2026-07-05T02:30:11.915320+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2406.10162","citing_title":"Sycophancy to Subterfuge: Investigating Reward-Tampering in Large Language Models","ref_index":229,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS","json":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS.json","graph_json":"https://pith.science/api/pith-number/DPDQ7CZ373ZBOYHEYUIF2LYQHS/graph.json","events_json":"https://pith.science/api/pith-number/DPDQ7CZ373ZBOYHEYUIF2LYQHS/events.json","paper":"https://pith.science/paper/DPDQ7CZ3"},"agent_actions":{"view_html":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS","download_json":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS.json","view_paper":"https://pith.science/paper/DPDQ7CZ3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2005.00174&json=true","fetch_graph":"https://pith.science/api/pith-number/DPDQ7CZ373ZBOYHEYUIF2LYQHS/graph.json","fetch_events":"https://pith.science/api/pith-number/DPDQ7CZ373ZBOYHEYUIF2LYQHS/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS/action/timestamp_anchor","attest_storage":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS/action/storage_attestation","attest_author":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS/action/author_attestation","sign_citation":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS/action/citation_signature","submit_replication":"https://pith.science/pith/DPDQ7CZ373ZBOYHEYUIF2LYQHS/action/replication_record"}},"created_at":"2026-07-05T02:30:11.915320+00:00","updated_at":"2026-07-05T02:30:11.915320+00:00"}