Skip to main content
ICFEM'23VerificationLanguage ModelsRobustnessFormal Methods

PdD: Formalizing Robustness Against Character-Level Perturbations

Zhongkui Ma, Xinguo Feng, Zihan Wang, Shuofeng Liu, Mengyao Ma, Hao Guan, Mark Huasong Meng

Character-level perturbation specifications and controlled text augmentation for studying language-model robustness.

The problem

Text perturbations need an explicit specification before robustness results can be interpreted. PdD focuses on character-level changes to language-model inputs.

The method

Probability distribution, density and diversity describe how perturbations are generated. The specification also supports controlled dataset augmentation for robustness training.

Evidence and scope

The work evaluates robustness improvements from training with the generated examples. It is complementary to activation-hull approximation: defining and testing perturbations is not itself a sound bound-propagation verifier. Character-level and word-level threat models cover different input changes and can complement one another.

Authorship note

The publisher records equal contribution by Zhongkui Ma and Xinguo Feng. The complete author order remains in the byline above.

Use the Paper and GitHub links above for the specification and perturbation-generation implementation.

Citation

@inproceedings{ma2023formalizing,
  title={Formalizing Robustness Against Character-Level Perturbations for Neural Network Language Models},
  author={Ma, Zhongkui and Feng, Xinguo and Wang, Zihan and Liu, Shuofeng and Ma, Mengyao and Guan, Hao and Meng, Mark Huasong},
  booktitle={International Conference on Formal Engineering Methods},
  pages={100--117},
  year={2023},
  organization={Springer}
}