Abstract
Recent years have witnessed substantial progress in document retrieval, driven by advancements in numerous language models. However, these models remain vulnerable to adversarial attacks, such as Word Substitution Ranking Attack (WSRA), which manipulates retrieval results by subtly replacing words in the document content. Existing defense methods often rely on adversarial training or ensemble-based certification, both of which require extensive supervision and limit their practicality. Accordingly, we propose the Impact-Aware Defense (IAD) algorithm, which explicitly leverages three simple yet effective masking strategies. Specifically, IAD stabilizes retrieval results by minimizing the impact of word-level perturbations, ensuring that the removal of arbitrary words does not significantly alter the retrieval result. Furthermore, our theoretical analysis guarantees ranking stability by constraining perturbation-induced score deviations. Empirical results on three widely adopted retrieval benchmarks show that IAD achieves substantial robustness improvements against adversarial attacks, establishing a new state-of-the-art with up to 29.4% relative gain in Mean Reciprocal Rank (MRR) over prior best-performing methods.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the IEEE International Conference on Big Data (BigData 2025), Macau, China, December 8-11, 2025 |
| Editors | Cheng-Zhong Xu, Leong Hou U, Xueqi Cheng, Jing Gao, Giuseppe Polese, Hong Mei, Paul Boniol, Michiaki Tatsubori, Chen Zhao, Dawei Zhou, Xiaohua Hu |
| Place of Publication | U.S. |
| Publisher | IEEE |
| Pages | 1084-1093 |
| Number of pages | 10 |
| ISBN (Electronic) | 9798331594473 |
| ISBN (Print) | 9798331594473 |
| DOIs | |
| Publication status | Published - 2025 |
| Event | IEEE International Conference on Big Data - Macau, China Duration: 8 Dec 2025 → 11 Dec 2025 |
Conference
| Conference | IEEE International Conference on Big Data |
|---|---|
| Abbreviated title | BigData |
| Country/Territory | China |
| City | Macau |
| Period | 8/12/25 → 11/12/25 |
Keywords
- Adversarial Perturbation
- Certified Defense
- Document Retrieval
- Masked Language Modeling
- Word Substitution Ranking Attack
Fingerprint
Dive into the research topics of 'Impact-aware retrieval defense: mitigating word substitution ranking attacks for enhanced stability'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver