Gradient-based analysis of NLP models is manipulable

N/ACitations
Citations of this article
95Readers
Mendeley users who have this article in their library.

Abstract

Gradient-based analysis methods, such as saliency map visualizations and adversarial input perturbations, have found widespread use in interpreting neural NLP models due to their simplicity, flexibility, and most importantly, their faithfulness. In this paper, however, we demonstrate that the gradients of a model are easily manipulable, and thus bring into question the reliability of gradient-based analyses. In particular, we merge the layers of a target model with a FACADE model that overwhelms the gradients without affecting the predictions. This FACADE model can be trained to have gradients that are misleading and irrelevant to the task, such as focusing only on the stop words in the input. On a variety of NLP tasks (text classification, NLI, and QA), we show that our method can manipulate numerous gradient-based analysis techniques: saliency maps, input reduction, and adversarial perturbations all identify unimportant or targeted tokens as being highly important. The code and a tutorial of this paper is available at http://ucinlp.github.io/facade.

Cite

CITATION STYLE

APA

Wang, J., Tuyls, J., Wallace, E., & Singh, S. (2020). Gradient-based analysis of NLP models is manipulable. In Findings of the Association for Computational Linguistics Findings of ACL: EMNLP 2020 (pp. 247–258). Association for Computational Linguistics (ACL). https://doi.org/10.18653/v1/2020.findings-emnlp.24

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free