IP Library Granted Patent US 11,755,657
Granted Patent B2
US 11,755,657 · App. 17/933,147 · Granted Sep 12, 2023

Training a question-answer dialog system to avoid adversarial attacks

Inventors: Sara Rosenthal (Spring Valley, NY); Avirup Sil (Hopewell Junction, NY); Mihaela Ancuta Bornea (White Plains, NY); Radu Florian (Danbury, CT)
Assignee: International Business Machines Corporation
G06F16/90332G06F16/337G06F21/54G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,657
App. No.
17/933,147
Granted
Sep 12, 2023
Kind
B2
Abstract

A method, computer program product, and/or computer system generate a first adversarial statement via: (1) receiving a question and an original context for the question; (2) converting the question into a statement with a placeholder answer; (3) picking randomly an answer entity from a training text corpus; (4) replacing the placeholder answer with the randomly picked answer entity; and (5) leaving a correct question entity in the statement. The first adversarial statement is inserted into the original context to form a first adversarial context. The question and the first adversarial context as a first pair and the question and the original context as a second pair are input into a question-answer dialog system to train the question-answer dialog system.

Claims (48)

1. A method for detecting an information operations campaign, the method comprising:

A method comprising:

generating, by a computing device, a first adversarial statement via:

receiving a question and an original context for the question;

converting the question into a statement with a placeholder answer;

picking randomly an answer entity from a training text corpus;

replacing the placeholder answer with the randomly picked answer entity; and

leaving a correct question entity in the statement;

inserting, by the computing device, the first adversarial statement into the original context to form a first adversarial context;

inputting, by the computing device, the question and the first adversarial context as a first pair and the question and the original context as a second pair into a question-answer dialog system to train the question-answer dialog system; and

using the trained question-answer dialog system to automatically respond to a further question that is received.

2. The method of claim 1 , further comprising determining, by the computing device, an entity type of an answer to the question, wherein the picking of the answer entity for the adversarial statement from the training text corpus occurs from entities in the training text corpus having the determined entity type.

3. The method of claim 2 , wherein the determining of the entity type comprises the computing device predicting the entity type in a non-adversarial setting.

4. The method of claim 2 , wherein the determined entity type is a type of entity of a correct answer to the question.

5. The method of claim 1 , wherein the original context includes a correct answer to the question, the correct answer is disposed in an answer position within the original context, and the answer position is input into the question-answer dialog system to train the question-answer dialog system.

6. The method of claim 5 , wherein the answer position is input into the question-answer dialog system as a group together with the second pair.

7. The method of claim 1 , wherein the placeholder answer is disposed in a candidate answer position within the first adversarial context, and the candidate answer position is input into the question-answer dialog system to train the question-answer dialog system.

8. The method of claim 7 , wherein the candidate answer position is input into the question-answer dialog system as a group together with the first pair.

9. The method of claim 1 , wherein the first adversarial context includes a correct answer to the question.

10. The method of claim 1 , wherein in response to receiving a new question and a new context for answering the new question, the trained question-answer dialog system provides a new answer for the new question and provides a predicted position of the new answer within the new context.

11. The method of claim 1 , wherein the original context is in a first language, and the first adversarial statement is in a second language that is different from the first language.

12. A computer program product comprising a computer readable storage medium having program code embodied therewith, wherein the computer readable storage medium is not a transitory signal per se, wherein the program code is readable and executable by a processor to perform a method of training a question-answer dialog system to avoid adversarial attacks, and wherein the method comprises:

generating a first adversarial statement via:

receiving a question and an original context for the question;

converting the question into a statement with a placeholder answer;

picking randomly an answer entity from a training text corpus;

replacing the placeholder answer with the randomly picked answer entity; and

leaving a correct question entity in the statement;

inserting the first adversarial statement into the original context to form a first adversarial context;

inputting the question and the first adversarial context as a first pair and the question and the original context as a second pair into a question-answer dialog system to train the question-answer dialog system; and

using the trained question-answer dialog system to automatically respond to a further question that is received.

13. The computer program product of claim 12 , wherein the method further comprises determining an entity type of an answer to the question, wherein the picking of the answer entity for the adversarial statement from the training text corpus occurs from entities in the training text corpus having the determined entity type.

14. The computer program product of claim 12 , wherein the original context includes a correct answer to the question, the correct answer is disposed in an answer position within the original context, and the answer position is input into the question-answer dialog system to train the question-answer dialog system.

15. The computer program product of claim 12 , wherein the placeholder answer is disposed in a candidate answer position within the first adversarial context, and the candidate answer position is input into the question-answer dialog system to train the question-answer dialog system.

16. The computer program product of claim 12 , wherein in response to receiving a new question and a new context for answering the new question, the trained question-answer dialog system provides a new answer for the new question and provides a predicted position of the new answer within the new context.

17. A computer system comprising one or more processors, one or more computer readable memories, and one or more computer readable non-transitory storage mediums, and program instructions stored on at least one of the one or more computer readable non-transitory storage mediums for execution by at least one of the one or more processors via at least one of the one or more computer readable memories, the stored program instructions executed to perform a method comprising:

generating a first adversarial statement via:

receiving a question and an original context for the question;

converting the question into a statement with a placeholder answer;

picking randomly an answer entity from a training text corpus;

replacing the placeholder answer with the randomly picked answer entity; and

leaving a correct question entity in the statement;

inserting the first adversarial statement into the original context to form a first adversarial context;

inputting the question and the first adversarial context as a first pair and the question and the original context as a second pair into a question-answer dialog system to train the question-answer dialog system; and

using the trained question-answer dialog system to automatically respond to a further question that is received.

18. The computer system of claim 17 , wherein the method further comprises determining an entity type of an answer to the question, wherein the picking of the answer entity for the adversarial statement from the training text corpus occurs from entities in the training text corpus having the determined entity type.

19. The computer system of claim 17 , wherein the original context includes a correct answer to the question, the correct answer is disposed in an answer position within the original context, and the answer position is input into the question-answer dialog system to train the question-answer dialog system.

20. The computer system of claim 17 , wherein in response to receiving a new question and a new context for answering the new question, the trained question-answer dialog system provides a new answer for the new question and provides a predicted position of the new answer within the new context.

Assignments (3)
SECURITY INTEREST Recorded Jul 8, 2025
From: ANTHROPIC, PBC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071626/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2025
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: ANTHROPIC, PBC
Reel/Frame 071201/0198 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: ROSENTHAL, SARA; SIL, AVIRUP; BORNEA, MIHAELA ANCUTA; FLORIAN, RADU
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 061132/0565 →
Continuity (2)
Continuation 17076031 · Oct 21, 2020
Related Publication 20230009893A1 · Jan 12, 2023
Cited By (1)
US 12,561,522