arXiv:2502.05225cs.CRcs.AI2025-02NAACL被引 4

构建首个真实钓鱼文本视觉扰动数据集,提升对抗攻击防御能力

BitAbuse: A Dataset of Visually Perturbed Texts for Defending Phishing Attacks

  • 基于真实钓鱼案例构建32万+条视觉扰动文本数据集
  • 模型在该数据集上实现96%识别准确率,显著优于旧方法
  • 揭示真实与合成数据差距,助力防御模型可靠性提升

钓鱼攻击常通过视觉扰动文本绕过安全系统,此类噪声构成对语言模型的对抗性干扰,影响内容理解。由于真实钓鱼案例稀缺,以往研究多依赖合成数据。本文提出BitAbuse数据集,包含325,580条真实世界中的视觉扰动文本,源自原始语料及人工扰动生成。每条输入均标注对应的真实还原版本。基于该数据集训练的语言模型表现显著优于先前方法,识别准确率达约96%。分析显示真实与合成样本间存在显著差异,凸显本数据集对构建可靠还原模型的价值。我们公开发布BitAbuse数据集,涵盖真实钓鱼案例及其视觉扰动标注,以支持未来对抗攻击防御研究。

原文摘要 · Abstract (English)

Phishing often targets victims through visually perturbed texts to bypass security systems. The noise contained in these texts functions as an adversarial attack, designed to deceive language models and hinder their ability to accurately interpret the content. However, since it is difficult to obtain sufficient phishing cases, previous studies have used synthetic datasets that do not contain real-world cases. In this study, we propose the BitAbuse dataset, which includes real-world phishing cases, to address the limitations of previous research. Our dataset comprises a total of 325,580 visually perturbed texts. The dataset inputs are drawn from the raw corpus, consisting of visually perturbed sentences and sentences generated through an artificial perturbation process. Each input sentence is labeled with its corresponding ground truth, representing the restored, non-perturbed version. Language models trained on our proposed dataset demonstrated significantly better performance compared to previous methods, achieving an accuracy of approximately 96%. Our analysis revealed a significant gap between real-world and synthetic examples, underscoring the value of our dataset for building reliable pre-trained models for restoration tasks. We release the BitAbuse dataset, which includes real-world phishing cases annotated with visual perturbations, to support future research in adversarial attack defense.

钓鱼防御视觉扰动对抗样本数据集

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。