Fall of Giants: How popular text-based MLaaS fall against a simple evasion attack

The increased demand for machine learning applications made companies offer\nMachine-Learning-as-a-Service (MLaaS). In MLaaS (a market estimated 8000M USD\nby 2025), users pay for well-performing ML models without dealing with the\ncomplicated training procedure. Among MLaaS, text-based applications are the\nmost popular ones (e.g., language translators). Given this popularity, MLaaS\nmust provide resiliency to adversarial manipulations. For example, a wrong\ntranslation might lead to a misunderstanding between two parties. In the text\ndomain, state-of-the-art attacks mainly focus on strategies that leverage ML\nmodels' weaknesses. Unfortunately, not much attention has been given to the\nother pipeline' stages, such as the indexing stage (i.e., when a sentence is\nconverted from a textual to a numerical representation) that, if manipulated,\ncan significantly affect the final performance of the application.\n In this paper, we propose a novel text evasion technique called\n"\\textit{Zero-Width} attack" (ZeW) that leverages the injection of human\nnon-readable characters, affecting indexing stage mechanisms. We demonstrate\nthat our simple yet effective attack deceives MLaaS of "giants" such as Amazon,\nGoogle, IBM, and Microsoft. Our case study, based on the manipulation of\nhateful tweets, shows that out of 12 analyzed services, only one is resistant\nto our injection strategy. We finally introduce and test a simple \\textit{input\nvalidation} defense that can prevent our proposed attack.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC