Richard Plant, Mario Valerio Giuffrida, Nikolaos Pitropakis, Dimitra Gkatzia

IEEE Transactions on Audio, Speech and Language Processing (2024)

R. Plant, M. V. Giuffrida, N. Pitropakis and D. Gkatzia, “Evaluating Language Model Vulnerability to Poisoning Attacks in Low-Resource Settings,” inĀ IEEE Transactions on Audio, Speech and Language Processing, vol. 33, pp. 54-67, 2025, doi: 10.1109/TASLP.2024.3507565

wp-content/uploads/2020/10/tex.png
@ARTICLE{10771712,
  author={Plant, Richard and Giuffrida, Mario Valerio and Pitropakis, Nikolaos and Gkatzia, Dimitra},
  journal={IEEE Transactions on Audio, Speech and Language Processing}, 
  title={Evaluating Language Model Vulnerability to Poisoning Attacks in Low-Resource Settings}, 
  year={2025},
  volume={33},
  number={},
  pages={54-67},
  keywords={Data models;Training;Computational modeling;Accuracy;Benchmark testing;Decision making;Speech processing;Security;Online services;Linguistics;Language modelling;machine learning methods for hlt;language understanding and computational semantics},
  doi={10.1109/TASLP.2024.3507565}}

Abstract

Pre-trained language models are a highly effective source of knowledge transfer for natural language processing tasks, as their development represents an investment of resources beyond the reach of most researchers and end users. The widespread availability of such easily adaptable resources has enabled high levels of performance, which is especially valuable for low-resource language users who have typically been overlooked when it comes to NLP applications. However, these models introduce vulnerabilities in NLP toolchains, since they may prove vulnerable to attacks from malicious actors with access to the data used for downstream training. By perturbing instances from the training set, such attacks seek to undermine model capabilities and produce radically different outcomes during inference. We show that adversarial data manipulation has a severe effect on model performance, with BERT’s performance dropping by more than 30% on average across all tasks at a poisoning ratio greater than 50%. Additionally, we conduct the first evaluation of this kind in the Basque language domain, establishing the vulnerability of low-resource models to the same form of attack.