Breaking BERT: Understanding its Vulnerabilities for Named Entity Recognition through Adversarial Attack
Both generic and domain-specific BERT models are widely used for natural\nlanguage processing (NLP) tasks. In this paper we investigate the vulnerability\nof BERT models to variation in input data for Named Entity Recognition (NER)\nthrough adversarial attack. Experimental results show that BERT models are\nvulnerable to variation in the entity context with 20.2 to 45.0% of entities\npredicted completely wrong and another 29.3 to 53.3% of entities predicted\nwrong partially. BERT models seem most vulnerable to changes in the local\ncontext of entities and often a single change is sufficient to fool the model.\nThe domain-specific BERT model trained from scratch (SciBERT) is more\nvulnerable than the original BERT model or the domain-specific model that\nretains the BERT vocabulary (BioBERT). We also find that BERT models are\nparticularly vulnerable to emergent entities. Our results chart the\nvulnerabilities of BERT models for NER and emphasize the importance of further\nresearch into uncovering and reducing these weaknesses.\n
Paper
References (28)
Scroll for more · 16 remaining