arXiv cs.CL
7/17/2026

LBA: Textual Hard-Label Adversarial Attack under Low Query Budgets
Short summary
LBA is a sampling-based method for generating adversarial texts under low query budgets in hard-label scenarios, where only the final classification is known. Unlike greedy approaches that modify one position at a time, LBA constructs an approximate distribution of high-quality adversarial examples by integrating prior and posterior knowledge, iteratively refining the distribution to guide sampling. Experiments across six language models and four datasets show LBA outperforms state-of-the-art baselines on all metrics, with LLM-based assessment confirming better semantic preservation and comprehensibility.
- •LBA uses sampling-based approach to generate adversarial texts under low query budgets
- •Integrates prior and posterior knowledge to iteratively refine adversarial example distribution
- •Outperforms baselines across six LMs and four datasets with better semantic preservation
Generated with AI, which can make mistakes.
Is this a good recommendation for you?
