{"id":{"repo_id":"aalto","oai_identifier":"oai:aaltodoc.aalto.fi:123456789/108772"},"canonical_url":"https://search.dev.ndltd.org/etd/aalto/oai:aaltodoc.aalto.fi:123456789/108772","repository":{"repo_id":"aalto","name":"Aalto University","base_url":"https://aaltodoc.aalto.fi/server/oai/request"},"display":{"title":"Natural Language Processing in Adversarial Settings and Beyond: Benefits and Risks of Text Classification, Transformation, and Representation","abstract":"Natural language processing (NLP) has developed significantly during recent years, with important consequences that extend beyond its immediate domain. The increased availability of NLP technologies has repercussions for information security and privacy in particular, both positive and negative. For example, classifying text based on semantic content or writing style has many benign uses, but also allows adversarial application for censorship or violations of privacy. Conversely, automatic text transformation can be used to perform model evasion attacks as well as defend against illegitimate profiling of text. This dissertation investigates the performance and security implications of NLP techniques across multiple tasks, with a focus on adversarial settings. We first explored how well state-of-the-art text classification techniques can detect various types of adversarial text, such as deception or hate speech. Here, we observed that classifiers tend to get caught on simple features regardless of model architecture, which can make them unreliable and vulnerable to evasion. Instead of complicating the model alone, increasing the training dataset is needed for improving performance. We further demonstrated that text transformation can successfully be used to expand training data artificially. However, some adversarial text classes – such as deception – are likely too context-dependent to be reliably detected by available techniques. We also applied text transformation to counteract classification, from both an attacker's and a defender's perspective. A major finding was that deep neural networks (DNNs) were unreliable at maintaining semantic content across transformations, in contrast to rule-based techniques that allow restrictive control of the output. On the other hand, DNNs are more flexible and can generate more variable texts than symbolic rules alone. This illustrates the complementary relationship between DNN-based and rule-based NLP, which speaks against discarding either. For mitigating model evasion, we show adversarial training to be beneficial against both kinds of techniques. Across both text classification and transformation tasks, the importance of input data representation becomes apparent. This has broad relevance in a variety of NLP settings. Motivated by recent developments in linguistic theory, we show that effective semantic representations can be attained with far fewer semantic roles than in prior formalisms. Based on this, we present a novel format that permits easy but highly detailed information retrieval, as well as straight-forward integration with DNNs as vectorized input. In addition to demonstrating the format's ability to retain information despite its structural simplicity, we applied it to parallel corpus extraction and text transformation tasks that resulted in multiple novel datasets we provide as open-access.","abstract_html":"Natural language processing (NLP) has developed significantly during recent years, with important consequences that extend beyond its immediate domain. The increased availability of NLP technologies has repercussions for information security and privacy in particular, both positive and negative. For example, classifying text based on semantic content or writing style has many benign uses, but also allows adversarial application for censorship or violations of privacy. Conversely, automatic text transformation can be used to perform model evasion attacks as well as defend against illegitimate profiling of text. This dissertation investigates the performance and security implications of NLP techniques across multiple tasks, with a focus on adversarial settings. We first explored how well state-of-the-art text classification techniques can detect various types of adversarial text, such as deception or hate speech. Here, we observed that classifiers tend to get caught on simple features regardless of model architecture, which can make them unreliable and vulnerable to evasion. Instead of complicating the model alone, increasing the training dataset is needed for improving performance. We further demonstrated that text transformation can successfully be used to expand training data artificially. However, some adversarial text classes – such as deception – are likely too context-dependent to be reliably detected by available techniques. We also applied text transformation to counteract classification, from both an attacker&#x27;s and a defender&#x27;s perspective. A major finding was that deep neural networks (DNNs) were unreliable at maintaining semantic content across transformations, in contrast to rule-based techniques that allow restrictive control of the output. On the other hand, DNNs are more flexible and can generate more variable texts than symbolic rules alone. This illustrates the complementary relationship between DNN-based and rule-based NLP, which speaks against discarding either. For mitigating model evasion, we show adversarial training to be beneficial against both kinds of techniques. Across both text classification and transformation tasks, the importance of input data representation becomes apparent. This has broad relevance in a variety of NLP settings. Motivated by recent developments in linguistic theory, we show that effective semantic representations can be attained with far fewer semantic roles than in prior formalisms. Based on this, we present a novel format that permits easy but highly detailed information retrieval, as well as straight-forward integration with DNNs as vectorized input. In addition to demonstrating the format&#x27;s ability to retain information despite its structural simplicity, we applied it to parallel corpus extraction and text transformation tasks that resulted in multiple novel datasets we provide as open-access.","abstract_has_math":false,"creators":["Gröndahl, Tommi"],"institution":"Aalto University","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Tietotekniikan laitos","school":null,"contributors":["Aalto-yliopisto","Aalto University"],"advisors":["Asokan, N., Prof., University of Waterloo, Canada / Adj. Prof., Aalto University, Department of Computer Science, Finland"],"committee_chairs":[],"committee_members":[],"year":2021,"date_issued":"2021","date_published":"2021","updated_at":"2026-08-21T22:21:56Z","subjects":[],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://aaltodoc.aalto.fi/handle/123456789/108772","outbound_label":"Repository record","outbound_source":"dc:identifier.uri"},"source_record":{"url":"https://aaltodoc.aalto.fi/server/oai/request?verb=GetRecord&metadataPrefix=dim&identifier=oai%3Aaaltodoc.aalto.fi%3A123456789%2F108772","prefix":"dim"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Aalto-yliopisto","Aalto University"]},{"key":"dc:contributor.advisor","label":"Advisor","values":["Asokan, N., Prof., University of Waterloo, Canada / Adj. Prof., Aalto University, Department of Computer Science, Finland"]},{"key":"dc:contributor.department","label":"Department","values":["Tietotekniikan laitos","Department of Computer Science"]},{"key":"dc:contributor.supervisor","label":"Supervisor","values":["Asokan, N., Prof., University of Waterloo, Canada / Adj. Prof., Aalto University, Department of Computer Science, Finland"]},{"key":"dc:creator","label":"Author","values":["Gröndahl, Tommi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2021-07-30T09:00:08Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2021-07-30T09:00:08Z"]},{"key":"dc:date.issued","label":"Date","values":["2021"]},{"key":"dc:publisher","label":"Institution","values":["Aalto University","Aalto-yliopisto"]},{"key":"dc:type","label":"Dc Type","values":["G5 Artikkeliväitöskirja"]},{"key":"dc:type.dcmitype","label":"Dc Type Dcmitype","values":["text"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://aaltodoc.aalto.fi/handle/123456789/108772"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Defence is held on 23.8.2021 12:00 – 16:00 via remote technology (Zoom), https://aalto.zoom.us/j/68871341754"]},{"key":"dc:description.abstract","label":"Abstract","values":["Natural language processing (NLP) has developed significantly during recent years, with important consequences that extend beyond its immediate domain. The increased availability of NLP technologies has repercussions for information security and privacy in particular, both positive and negative. For example, classifying text based on semantic content or writing style has many benign uses, but also allows adversarial application for censorship or violations of privacy. Conversely, automatic text transformation can be used to perform model evasion attacks as well as defend against illegitimate profiling of text. This dissertation investigates the performance and security implications of NLP techniques across multiple tasks, with a focus on adversarial settings. We first explored how well state-of-the-art text classification techniques can detect various types of adversarial text, such as deception or hate speech. Here, we observed that classifiers tend to get caught on simple features regardless of model architecture, which can make them unreliable and vulnerable to evasion. Instead of complicating the model alone, increasing the training dataset is needed for improving performance. We further demonstrated that text transformation can successfully be used to expand training data artificially. However, some adversarial text classes – such as deception – are likely too context-dependent to be reliably detected by available techniques. We also applied text transformation to counteract classification, from both an attacker's and a defender's perspective. A major finding was that deep neural networks (DNNs) were unreliable at maintaining semantic content across transformations, in contrast to rule-based techniques that allow restrictive control of the output. On the other hand, DNNs are more flexible and can generate more variable texts than symbolic rules alone. This illustrates the complementary relationship between DNN-based and rule-based NLP, which speaks against discarding either. For mitigating model evasion, we show adversarial training to be beneficial against both kinds of techniques. Across both text classification and transformation tasks, the importance of input data representation becomes apparent. This has broad relevance in a variety of NLP settings. Motivated by recent developments in linguistic theory, we show that effective semantic representations can be attained with far fewer semantic roles than in prior formalisms. Based on this, we present a novel format that permits easy but highly detailed information retrieval, as well as straight-forward integration with DNNs as vectorized input. In addition to demonstrating the format's ability to retain information despite its structural simplicity, we applied it to parallel corpus extraction and text transformation tasks that resulted in multiple novel datasets we provide as open-access.","Kieliteknologia (NLP) on kehittynyt merkittävästi viime vuosina, millä on seurauksia myös sen välittömien sovellusten ulkopuolella. NLP:n saatavuus on erityisen merkittävää tietoturvan ja yksityisyyden näkökulmasta, sekä positiivisessa että negatiivisessa mielessä. Esimerkiksi tekstien luokittelua merkityksen tai kirjoitustyylin perusteella voidaan hyödyntää monin tavoin, mutta se sallii myös vahingollisen käytön, kuten sensuurin tai yksityisyydenloukkaukset. Vastaavasti tekstin automaattista muokkausta voidaan käyttää sekä kiertohyökkäyksiin että puolustautumiseen tekstin asiatonta profilointia vastaan. Tämä väitöskirja tutkii NLP-menetelmien suoriutumista useissa tehtävissä ja tämän seurauksia koskien tietoturvaa, erityisesti hyökkäys-puolustusasetelmissa. Tarkastelimme aluksi, kykenevätkö johtavat NLP-menetelmät tunnistamaan haitallista tekstiä, kuten valheita tai vihapuhetta. Havaitsimme, että luokittelijat jäävät usein kiinni yksinkertaisiin piirteisiin riippumatta koneoppimismallista, mikä voi tehdä niistä epäluotettavia ja altistaa ne kiertohyökkäyksille. Mallin monimutkaistamisen sijaan tarvitaan harjoitusdatan lisäämistä. Osoitimme myös, että tekstin muokkaamista voi onnistuneesti käyttää harjoitusdatan synteettiseen laajentamiseen. Jotkin haitalliset tekstityypit – kuten valhe – ovat kuitenkin todennäköisesti liian kontekstiriippuvaisia, jotta niiden luotettava tunnistus olisi mahdollista nykymenetelmillä. Käytimme tekstin muokkausta myös luokittelun kiertämiseen sekä hyökkääjän että puolustautujan näkökulmasta. Oleellinen tulos oli, että syväoppivat neuroverkot (Deep Neural Network: DNN) eivät säilyttäneet semanttista sisältöä luotettavasti toisin kuin sääntöpohjaiset menetelmät, jotka sallivat tiukan kontrollin muokkauksista. Toisaalta DNN:t ovat joustavampia ja pystyvät tuottamaan vaihtelevampaa tekstiä kuin pelkät symboliset säännöt. Tämä osoittaa DNN:ien ja sääntöpohjaisen NLP:n vastavuoroisuudesta, mikä puoltaa sitä, ettei kumpaakaan tulisi hylätä. Kiertohyökkäyksen välttämiskeinona näytämme, että esimerkkihyökkäysten lisääminen harjoitusdataan on hyödyllistä kummankinlaisia tekniikoita vastaan. Datan esittämisen tärkeys nousee esiin sekä tekstin luokittelu- että muokkaustehtävissä. Tämä on oleellista monenlaisissa NLP-sovelluksissa. Viimeaikaisten kielitieteellisten kehitysten motivoimina näytämme, että ilmaisuvoimaisia semanttisia representaatioita on mahdollista tuottaa käyttämällä huomattavasti vähemmän semanttisia rooleja kuin aiemmissa formalismeissa. Tämän pohjalta esitämme uuden formaatin, joka sallii helpon mutta tehokkaan tiedonhaun sekä suoraviivaisen integraation DNN:ien kanssa vektorisoidussa muodossa. Osoitamme kyseisen formaatin kyvyn säilyttää informaatiota yksinkertaisesta rakenteestaan huolimatta. Lisäksi sovelsimme sitä lauseparikorpuksien tuottamiseen ja tekstin muokkaukseen, mistä syntyneet useat uudet aineistot luovutamme saataville avoimesti."]},{"key":"dc:format.mimetype","label":"Dc Format Mimetype","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Natural Language Processing in Adversarial Settings and Beyond: Benefits and Risks of Text Classification, Transformation, and Representation"]}]}],"canonical_facts":{"dc:contributor":["Aalto-yliopisto","Aalto University"],"dc:contributor.advisor":["Asokan, N., Prof., University of Waterloo, Canada / Adj. Prof., Aalto University, Department of Computer Science, Finland"],"dc:contributor.department":["Tietotekniikan laitos","Department of Computer Science"],"dc:contributor.supervisor":["Asokan, N., Prof., University of Waterloo, Canada / Adj. Prof., Aalto University, Department of Computer Science, Finland"],"dc:creator":["Gröndahl, Tommi"],"dc:date.accessioned":["2021-07-30T09:00:08Z"],"dc:date.available":["2021-07-30T09:00:08Z"],"dc:date.issued":["2021"],"dc:description":["Defence is held on 23.8.2021 12:00 – 16:00 via remote technology (Zoom), https://aalto.zoom.us/j/68871341754"],"dc:description.abstract":["Natural language processing (NLP) has developed significantly during recent years, with important consequences that extend beyond its immediate domain. The increased availability of NLP technologies has repercussions for information security and privacy in particular, both positive and negative. For example, classifying text based on semantic content or writing style has many benign uses, but also allows adversarial application for censorship or violations of privacy. Conversely, automatic text transformation can be used to perform model evasion attacks as well as defend against illegitimate profiling of text. This dissertation investigates the performance and security implications of NLP techniques across multiple tasks, with a focus on adversarial settings. We first explored how well state-of-the-art text classification techniques can detect various types of adversarial text, such as deception or hate speech. Here, we observed that classifiers tend to get caught on simple features regardless of model architecture, which can make them unreliable and vulnerable to evasion. Instead of complicating the model alone, increasing the training dataset is needed for improving performance. We further demonstrated that text transformation can successfully be used to expand training data artificially. However, some adversarial text classes – such as deception – are likely too context-dependent to be reliably detected by available techniques. We also applied text transformation to counteract classification, from both an attacker's and a defender's perspective. A major finding was that deep neural networks (DNNs) were unreliable at maintaining semantic content across transformations, in contrast to rule-based techniques that allow restrictive control of the output. On the other hand, DNNs are more flexible and can generate more variable texts than symbolic rules alone. This illustrates the complementary relationship between DNN-based and rule-based NLP, which speaks against discarding either. For mitigating model evasion, we show adversarial training to be beneficial against both kinds of techniques. Across both text classification and transformation tasks, the importance of input data representation becomes apparent. This has broad relevance in a variety of NLP settings. Motivated by recent developments in linguistic theory, we show that effective semantic representations can be attained with far fewer semantic roles than in prior formalisms. Based on this, we present a novel format that permits easy but highly detailed information retrieval, as well as straight-forward integration with DNNs as vectorized input. In addition to demonstrating the format's ability to retain information despite its structural simplicity, we applied it to parallel corpus extraction and text transformation tasks that resulted in multiple novel datasets we provide as open-access.","Kieliteknologia (NLP) on kehittynyt merkittävästi viime vuosina, millä on seurauksia myös sen välittömien sovellusten ulkopuolella. NLP:n saatavuus on erityisen merkittävää tietoturvan ja yksityisyyden näkökulmasta, sekä positiivisessa että negatiivisessa mielessä. Esimerkiksi tekstien luokittelua merkityksen tai kirjoitustyylin perusteella voidaan hyödyntää monin tavoin, mutta se sallii myös vahingollisen käytön, kuten sensuurin tai yksityisyydenloukkaukset. Vastaavasti tekstin automaattista muokkausta voidaan käyttää sekä kiertohyökkäyksiin että puolustautumiseen tekstin asiatonta profilointia vastaan. Tämä väitöskirja tutkii NLP-menetelmien suoriutumista useissa tehtävissä ja tämän seurauksia koskien tietoturvaa, erityisesti hyökkäys-puolustusasetelmissa. Tarkastelimme aluksi, kykenevätkö johtavat NLP-menetelmät tunnistamaan haitallista tekstiä, kuten valheita tai vihapuhetta. Havaitsimme, että luokittelijat jäävät usein kiinni yksinkertaisiin piirteisiin riippumatta koneoppimismallista, mikä voi tehdä niistä epäluotettavia ja altistaa ne kiertohyökkäyksille. Mallin monimutkaistamisen sijaan tarvitaan harjoitusdatan lisäämistä. Osoitimme myös, että tekstin muokkaamista voi onnistuneesti käyttää harjoitusdatan synteettiseen laajentamiseen. Jotkin haitalliset tekstityypit – kuten valhe – ovat kuitenkin todennäköisesti liian kontekstiriippuvaisia, jotta niiden luotettava tunnistus olisi mahdollista nykymenetelmillä. Käytimme tekstin muokkausta myös luokittelun kiertämiseen sekä hyökkääjän että puolustautujan näkökulmasta. Oleellinen tulos oli, että syväoppivat neuroverkot (Deep Neural Network: DNN) eivät säilyttäneet semanttista sisältöä luotettavasti toisin kuin sääntöpohjaiset menetelmät, jotka sallivat tiukan kontrollin muokkauksista. Toisaalta DNN:t ovat joustavampia ja pystyvät tuottamaan vaihtelevampaa tekstiä kuin pelkät symboliset säännöt. Tämä osoittaa DNN:ien ja sääntöpohjaisen NLP:n vastavuoroisuudesta, mikä puoltaa sitä, ettei kumpaakaan tulisi hylätä. Kiertohyökkäyksen välttämiskeinona näytämme, että esimerkkihyökkäysten lisääminen harjoitusdataan on hyödyllistä kummankinlaisia tekniikoita vastaan. Datan esittämisen tärkeys nousee esiin sekä tekstin luokittelu- että muokkaustehtävissä. Tämä on oleellista monenlaisissa NLP-sovelluksissa. Viimeaikaisten kielitieteellisten kehitysten motivoimina näytämme, että ilmaisuvoimaisia semanttisia representaatioita on mahdollista tuottaa käyttämällä huomattavasti vähemmän semanttisia rooleja kuin aiemmissa formalismeissa. Tämän pohjalta esitämme uuden formaatin, joka sallii helpon mutta tehokkaan tiedonhaun sekä suoraviivaisen integraation DNN:ien kanssa vektorisoidussa muodossa. Osoitamme kyseisen formaatin kyvyn säilyttää informaatiota yksinkertaisesta rakenteestaan huolimatta. Lisäksi sovelsimme sitä lauseparikorpuksien tuottamiseen ja tekstin muokkaukseen, mistä syntyneet useat uudet aineistot luovutamme saataville avoimesti."],"dc:format.mimetype":["application/pdf"],"dc:identifier.uri":["https://aaltodoc.aalto.fi/handle/123456789/108772"],"dc:language.iso":["en"],"dc:publisher":["Aalto University","Aalto-yliopisto"],"dc:title":["Natural Language Processing in Adversarial Settings and Beyond: Benefits and Risks of Text Classification, Transformation, and Representation"],"dc:type":["G5 Artikkeliväitöskirja"],"dc:type.dcmitype":["text"]},"updated_at":"2026-08-21T22:21:56Z"}