The second round of adversarial writing attacks the ir and rnn models. The questions targeted against the ir system degrade the performance of all models. However, the reverse does not hold: The ir model is robust to the questions written to fool the rnn.
This site uses cookies. By continuing to use our website, you are agreeing to our privacy policy. No content on this site may be used to train artificial intelligence systems without permission in writing from the MIT Press.