EvaLDA: Efficient Evasion Attacks Towards Latent Dirichlet Allocation
Qi Zhou, Haipeng Chen, Yitao Zheng, Zhen Wang
Abstract
As one of the most powerful topic models, Latent Dirichlet Allocation (LDA) has been used in a vast range of tasks, including document understanding, information retrieval and peer-reviewer assignment. Despite its tremendous popularity, the security of LDA has rarely been studied. This poses severe risks to security-critical tasks such as sentiment analysis and peer-reviewer assignment that are based on LDA. In this paper, we are interested in knowing whether LDA models are vulnerable to adversarial perturbations of benign document examples during inference time. We formalize the evasion attack to LDA models as an optimization problem and prove it to be NP-hard. We then propose a novel and efficient algorithm, EvaLDA to solve it. We show the effectiveness of EvaLDA via extensive empirical evaluations. For instance, in the NIPS dataset, EvaLDA can averagely promote the rank of a target topic from 10 to around 7 by only replacing 1% of the words with similar words in a victim document. Our work provides significant insights into the power and limitations of evasion attacks to LDA models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on2
Related papers
- Topic-oriented Adversarial Attacks against Black-box Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke et al.SIGIR 2023 · 20 citations
- Federated Latent Dirichlet Allocation: A Local Differential Privacy Based FrameworkYansheng Wang, Yongxin Tong, Dingyuan ShiAAAI 2020 · 128 citations
- E-LDA: Toward Interpretable LDA Topic Models with Strong Guarantees in Logarithmic Parallel TimeAdam BreuerICML 2025
- LimeAttack: Local Explainable Method for Textual Hard-Label Adversarial AttackHai Zhu, Qingyang Zhao, Weiwei Shang, Yuren Wu et al.AAAI 2024 · 19 citations
- ICL-Evader: Zero-Query Black-Box Evasion Attacks on In-Context Learning and Their DefensesNingyuan He, Ronghong Huang, Qianqian Tang, Hongyu Wang et al.WWW 2026
