“…Most existing attacks are word-level (Alzantot et al, 2018;Ren et al, 2019;Li et al, , 2020Jin et al, 2020;Zang et al, 2020b,a) or character-level (Hosseini et al, 2017;Ebrahimi et al, 2018;Belinkov and Bisk, 2018;Gao et al, 2018;Eger et al, 2019). Some studies present sentence-level attacks based on appending extra sentences (Jia and Liang, 2017;Wang et al, 2020a), perturbing sentence vectors or controlled text generation (Wang et al, 2020b). Iyyer et al (2018) propose to alter the syntax of original samples to generate adversarial examples, which is the most similar work to the style transferbased adversarial attack in this paper (although syntax and text style are distinct).…”