# Gradient-based word deletion - RoBERTa + Word Dropout

I trained a much better model using RoBERTa, Word Dropout, and a max sequence length of 256 ([link](https://wandb.ai/jack-morris/deid-wikibio/runs/1ge2izf0?workspace=user-jxmorris12)). I'm going to re-run my experiments using this model and see if it is smart enough to condition on birthdays.

In [1]:
import sys
sys.path.append('/home/jxm3/research/deidentification/unsupervised-deidentification')

In [2]:
from model import DocumentProfileMatchingTransformer

# model that was trained at the link given above, gets >99% validation accuracy,
# and is trained with word dropout!
checkpoint_path = "/home/jxm3/research/deidentification/unsupervised-deidentification/saves/roberta-base_2022-03-30-1320__dropout_0.5/deid-wikibio_default/1ge2izf0_38/checkpoints/epoch=67-step=61947.ckpt"
model = DocumentProfileMatchingTransformer.load_from_checkpoint(
    checkpoint_path,
    profile_encoder_name="st-paraphrase",
    dataset_name='wiki_bio',
    model_name_or_path="roberta-base",
    num_workers=1,
    loss_fn='exact',
    base_folder="/home/jxm3/research/deidentification/unsupervised-deidentification",
)

Some weights of the model checkpoint at roberta-base were not used when initializing RobertaModel: ['lm_head.dense.bias', 'lm_head.layer_norm.weight', 'lm_head.dense.weight', 'lm_head.layer_norm.bias', 'lm_head.bias', 'lm_head.decoder.weight']
- This IS expected if you are initializing RobertaModel from the checkpoint of a model trained on another task or with another architecture (e.g. initializing a BertForSequenceClassification model from a BertForPreTraining model).
- This IS NOT expected if you are initializing RobertaModel from the checkpoint of a model that you expect to be exactly identical (initializing a BertForSequenceClassification model from a BertForSequenceClassification model).


could not find nearest neighbors file for training data, trying to continue without them: /home/jxm3/research/deidentification/unsupervised-deidentification/precomputed_similarities/st-paraphrase/wiki_bio__train[:10%]__2048/neighbors.p
Initialized DocumentProfileMatchingTransformer with learning_rate = 0.0001
[*] Word dropout hyperparameters: ratio: 0.5 / percentage: 0.5 / token: <mask>


In [17]:
from datamodule import WikipediaDataModule
import os

num_cpus = os.cpu_count()

dm = WikipediaDataModule(
    model_name_or_path='roberta-base',
    profile_encoder_name="st-paraphrase",
    dataset_name='wiki_bio',
    num_workers=min(8, num_cpus),
    train_batch_size=64,
    eval_batch_size=64,
    max_seq_length=256,
    redaction_strategy="",
    base_folder="/home/jxm3/research/deidentification/unsupervised-deidentification",
)
dm.setup("fit")

Initializing WikipediaDataModule with num_workers = 8


Using custom data configuration default
Reusing dataset wiki_bio (/home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da)
Using custom data configuration default
Reusing dataset wiki_bio (/home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da)
Loading cached processed dataset at /home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da/cache-777e395491fb4772.arrow
Loading cached processed dataset at /home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da/cache-2a642fa33a5f98ac.arrow
Loading cached processed dataset at /home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da/cache-c1547e273c5c0253.arrow
Loading cached processed dataset at 

### Testing tokenizer and mask token

In [18]:
dm.tokenizer.encode("Hi there")

[0, 30086, 89, 2]

In [19]:
dm.tokenizer.encode("Hi there [MASK]")

[0, 30086, 89, 646, 32804, 530, 742, 2]

In [20]:
dm.tokenizer.encode("Hi there <mask>")

[0, 30086, 89, 50264, 2]

In [21]:
[dm.tokenizer.decode(t) for t in dm.tokenizer.encode("Hi there <mask> / intersectionality")]

['<s>', 'Hi', ' there', '<mask>', ' /', ' intersection', 'ality', '</s>']

In [22]:
[dm.tokenizer.decode(t) for t in dm.tokenizer.encode("intersectionality")]

['<s>', 'inter', 'section', 'ality', '</s>']

## 2. Define attack in TextAttack 

In [23]:
import textattack

### (a) Beam search + replace with `[MASK]`

In [24]:
class WordSwapSingleWord(textattack.transformations.word_swap.WordSwap):
    """Takes a sentence and transforms it by replacing with a single fixed word.
    """
    single_word: str
    def __init__(self, single_word: str = "?", **kwargs):
        super().__init__(**kwargs)
        self.single_word = single_word

    def _get_replacement_words(self, _word: str):
        return [self.single_word]

transformation = WordSwapSingleWord(single_word=dm.tokenizer.mask_token)
transformation(textattack.shared.AttackedText("Hello my name is Jack"))

[<AttackedText "<mask> my name is Jack">,
 <AttackedText "Hello <mask> name is Jack">,
 <AttackedText "Hello my <mask> is Jack">,
 <AttackedText "Hello my name <mask> Jack">,
 <AttackedText "Hello my name is <mask>">]

### (b) "Attack success" as fullfilment of the metric

In [25]:
from typing import List
import torch

class ChangeClassificationToBelowTopKClasses(textattack.goal_functions.ClassificationGoalFunction):
    k: int
    def __init__(self, *args, k: int = 1, **kwargs):
        self.k = k
        super().__init__(*args, **kwargs)

    def _is_goal_complete(self, model_output, _):
        original_class_score = model_output[self.ground_truth_output]
        num_better_classes = (model_output > original_class_score).sum()
        return num_better_classes >= self.k

    def _get_score(self, model_output, _):
        return 1 - model_output[self.ground_truth_output]
    
    
    """have to reimplement the following method to change the precision on the sum-to-one condition."""
    def _process_model_outputs(self, inputs, scores):
        """Processes and validates a list of model outputs.
        This is a task-dependent operation. For example, classification
        outputs need to have a softmax applied.
        """
        # Automatically cast a list or ndarray of predictions to a tensor.
        if isinstance(scores, list):
            scores = torch.tensor(scores)

        # Ensure the returned value is now a tensor.
        if not isinstance(scores, torch.Tensor):
            raise TypeError(
                "Must have list, np.ndarray, or torch.Tensor of "
                f"scores. Got type {type(scores)}"
            )

        # Validation check on model score dimensions
        if scores.ndim == 1:
            # Unsqueeze prediction, if it's been squeezed by the model.
            if len(inputs) == 1:
                scores = scores.unsqueeze(dim=0)
            else:
                raise ValueError(
                    f"Model return score of shape {scores.shape} for {len(inputs)} inputs."
                )
        elif scores.ndim != 2:
            # If model somehow returns too may dimensions, throw an error.
            raise ValueError(
                f"Model return score of shape {scores.shape} for {len(inputs)} inputs."
            )
        elif scores.shape[0] != len(inputs):
            # If model returns an incorrect number of scores, throw an error.
            raise ValueError(
                f"Model return score of shape {scores.shape} for {len(inputs)} inputs."
            )
        elif not ((scores.sum(dim=1) - 1).abs() < 1e-4).all():
            # Values in each row should sum up to 1. The model should return a
            # set of numbers corresponding to probabilities, which should add
            # up to 1. Since they are `torch.float` values, allow a small
            # error in the summation.
            scores = torch.nn.functional.softmax(scores, dim=1)
            if not ((scores.sum(dim=1) - 1).abs() < 1e-4).all():
                raise ValueError("Model scores do not add up to 1.")
        return scores.cpu()


## (c) Model wrapper that computes similarities of input documents with validation profiles

In [26]:
import transformers

class MyModelWrapper(textattack.models.wrappers.ModelWrapper):
    model: DocumentProfileMatchingTransformer
    tokenizer: transformers.PreTrainedTokenizer
    profile_embeddings: torch.Tensor
    max_seq_length: int
    
    def __init__(self, model: DocumentProfileMatchingTransformer, tokenizer: transformers.PreTrainedTokenizer, max_seq_length: int = 64):
        self.model = model
        self.model.eval()
        self.tokenizer = tokenizer
        self.profile_embeddings = torch.tensor(model.val_embeddings)
        self.max_seq_length = max_seq_length
                 
    def to(self, device):
        self.model.to(device)
        self.profile_embeddings.to(device)
        return self # so semantics `model = MyModelWrapper().to('cuda')` works properly

    def __call__(self, text_input_list, batch_size=32):
        model_device = next(self.model.parameters()).device
        tokenized_ids = self.tokenizer.batch_encode_plus(
            text_input_list,
            max_length=self.max_seq_length,
            padding=True,
            truncation=True
        )
        tokenized_ids = {k: torch.tensor(v).to(model_device) for k,v in tokenized_ids.items()}
        
        # TODO: implement batch size if we start running out of memory here.
        with torch.no_grad():
            document_embeddings = self.model.document_model(**tokenized_ids)
            document_embeddings = document_embeddings['last_hidden_state'][:, 0, :] # (batch, document_emb_dim)
            document_embeddings = self.model.lower_dim_embed(document_embeddings) # (batch, emb_dim)

        document_to_profile_probs = torch.nn.functional.softmax(
            document_embeddings @ self.profile_embeddings.T.to(model_device), dim=-1)
        assert document_to_profile_probs.shape == (len(text_input_list), len(self.profile_embeddings))
        return document_to_profile_probs
            

## (d) Dataset that loads Wikipedia documents with names as labels

Oh, and it filters out examples that are too long.

In [27]:
from typing import Tuple

from collections import OrderedDict

import datasets

class WikiDataset(textattack.datasets.Dataset):
    dataset: datasets.Dataset
    
    def __init__(self, dm: WikipediaDataModule):
        self.shuffled = True
        # filter out super long examples
        self.dataset = [ex for ex in dm.val_dataset if ex['document'].count(' ') < 100]
        self.label_names = list(dm.val_dataset['name'])
    
    def __len__(self) -> int:
        return len(self.dataset)
    
    def __getitem__(self, i: int) -> Tuple[OrderedDict, int]:
        input_dict = OrderedDict([
            ('document', self.dataset[i]['document'])
        ])
        return input_dict, self.dataset[i]['text_key_id']
        

## 3. Run attack once

In [28]:
from textattack.loggers import CSVLogger
from textattack.shared import AttackedText

import pandas as pd
class CustomCSVLogger(CSVLogger):
    """Logs attack results to a CSV."""

    def log_attack_result(self, result: textattack.goal_function_results.ClassificationGoalFunctionResult):
        original_text, perturbed_text = result.diff_color(self.color_method)
        original_text = original_text.replace("\n", AttackedText.SPLIT_TOKEN)
        perturbed_text = perturbed_text.replace("\n", AttackedText.SPLIT_TOKEN)
        result_type = result.__class__.__name__.replace("AttackResult", "")
        row = {
            "original_person": result.original_result._processed_output[0],
            "original_text": original_text,
            "perturbed_person": result.perturbed_result._processed_output[0],
            "perturbed_text": perturbed_text,
            "original_score": result.original_result.score,
            "perturbed_score": result.perturbed_result.score,
            "original_output": result.original_result.output,
            "perturbed_output": result.perturbed_result.output,
            "ground_truth_output": result.original_result.ground_truth_output,
            "num_queries": result.num_queries,
            "result_type": result_type,
        }
        self.df = pd.concat([self.df, pd.DataFrame([row])], ignore_index=True)
        self._flushed = False

In [29]:
class MaxNumWordsModified(textattack.constraints.PreTransformationConstraint):
    def __init__(self, max_num_words: int):
        self.max_num_words = max_num_words

    def _get_modifiable_indices(self, current_text):
        """Returns the word indices in current_text which are able to be
        modified."""

        if len(current_text.attack_attrs["modified_indices"]) >= self.max_num_words:
            return set()
        else:
            return set(range(len(current_text.words)))

    def extra_repr_keys(self):
        return ["max_num_words"]

In [30]:
model_wrapper = MyModelWrapper(model, dm.tokenizer)
model_wrapper.to('cuda')

<__main__.MyModelWrapper at 0x7fdc0ae04040>

In [36]:
# 
#  Initialize attack
# 

from textattack import Attack
from textattack.constraints.pre_transformation import RepeatModification

goal_function = ChangeClassificationToBelowTopKClasses(model_wrapper, k=10)
constraints = [RepeatModification(), MaxNumWordsModified(max_num_words=25)]
transformation = WordSwapSingleWord(single_word=dm.tokenizer.mask_token)
search_method = textattack.search_methods.BeamSearch(beam_width=4)

attack = Attack(
    goal_function, constraints, transformation, search_method
)

from tqdm import tqdm # tqdm provides us a nice progress bar.
from textattack.attack_results import SuccessfulAttackResult
from textattack import Attacker
from textattack import AttackArgs

attack_args = AttackArgs(num_examples=15, disable_stdout=True)
dataset = WikiDataset(dm)

attacker = Attacker(attack, dataset, attack_args)

results_iterable = attacker.attack_dataset()

logger = CustomCSVLogger(color_method='html')

# 
# Run attack
# 
from tqdm import tqdm
for result in results_iterable:
    tqdm._instances.clear() # Doesn't fix the progress bar :-(
    logger.log_attack_result(result)

from IPython.display import display, HTML

display(HTML(logger.df.to_html(escape=False)))

textattack: No entry found for goal function <class '__main__.ChangeClassificationToBelowTopKClasses'>.
textattack: Unknown if model of class <class 'model.DocumentProfileMatchingTransformer'> compatible with goal function <class '__main__.ChangeClassificationToBelowTopKClasses'>.


Attack(
  (search_method): BeamSearch(
    (beam_width):  4
  )
  (goal_function):  ChangeClassificationToBelowTopKClasses
  (transformation):  WordSwapSingleWord
  (constraints): 
    (0): RepeatModification
    (1): MaxNumWordsModified(
        (max_num_words):  25
      )
  (is_black_box):  True
) 






  0%|          | 0/15 [00:00<?, ?it/s][A[A[A


  7%|▋         | 1/15 [00:03<00:46,  3.33s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 1 / 0 / 0 / 1:   7%|▋         | 1/15 [00:03<00:46,  3.33s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 1 / 0 / 0 / 1:  13%|█▎        | 2/15 [00:03<00:23,  1.82s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 2 / 0 / 0 / 2:  13%|█▎        | 2/15 [00:03<00:23,  1.83s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 2 / 0 / 0 / 2:  20%|██        | 3/15 [00:03<00:15,  1.33s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 3 / 0 / 0 / 3:  20%|██        | 3/15 [00:03<00:15,  1.33s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 3 / 0 / 0 / 3:  27%|██▋       | 4/15 [00:05<00:14,  1.29s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 4 / 0 / 0 / 4:  27%|██▋       | 4/15 [00:05<00:14,  1.29s/it][A[A[A


[Succeeded / Failed / Skipped / Total] 4 / 0 / 0 / 4:  33%|███▎      | 5/15 [00:06<00:12,  1.23s/it][A[


+-------------------------------+--------+
| Attack Results                |        |
+-------------------------------+--------+
| Number of successful attacks: | 15     |
| Number of failed attacks:     | 0      |
| Number of skipped attacks:    | 0      |
| Original accuracy:            | 100.0% |
| Accuracy under attack:        | 0.0%   |
| Attack success rate:          | 100.0% |
| Average perturbed word %:     | 25.15% |
| Average num. words per input: | 32.47  |
| Avg num queries:              | 662.8  |
+-------------------------------+--------+


textattack: Logging to CSV at path results.csv
textattack: CSVLogger exiting without calling flush().





Unnamed: 0,original_person,original_text,perturbed_person,perturbed_text,original_score,perturbed_score,original_output,perturbed_output,ground_truth_output,num_queries,result_type
0,Michael iii of alexandria,"pope michael iii of alexandria (also known as khail iii) was the coptic pope of alexandria and patriarch of the see of st. mark (880 -- 907) .in 882 , the governor of egypt , ahmad ibn tulun , forced khail to pay heavy contributions , forcing him to sell a church and some attached properties to the local jewish community .this building was at one time believed to have later become the site of the cairo geniza .",Saint john chrysostom,"pope michael <mask> of alexandria (also known as <mask> <mask>) was the coptic pope of alexandria and patriarch of the see of st. mark (880 -- 907) .in 882 , the governor of <mask> , ahmad ibn tulun , forced <mask> to pay heavy contributions , forcing him to sell a church and some attached properties to the local jewish community .this building was at one time believed to have later become the site of the cairo geniza .",0.669087,0.986233,0,6140,0,1202,Successful
1,Hui jun,hui jun is a male former table tennis player from china .,Mien suhadi,<mask> <mask> is a <mask> former <mask> <mask> <mask> <mask> <mask> .,0.0,0.994984,1,9738,1,208,Successful
2,Okan öztürk,okan Öztürk (born 30 november 1977) is a turkish professional footballer .he currently plays as a striker for yeni malatyaspor .,Mustafa sarp,<mask> <mask> (born 30 november 1977) is a turkish professional footballer .he currently plays as a <mask> for yeni malatyaspor .,0.734742,0.990822,2,8305,2,169,Successful
3,Marie stephan,"marie stephan , (born march 14 , 1996) is a professional squash player who represents france .she reached a career-high world ranking of world no. 101 in july 2015 .",Amanda fink,"<mask> <mask> , (born <mask> 14 , 1996) is a professional <mask> player who represents <mask> .<mask> reached a career-high world ranking of world no. 101 in july 2015 .",0.072457,0.983457,3,1166,3,508,Successful
4,Leonard l. martino,leonard l. martino is a former democratic member of the pennsylvania house of representatives .he was born in butler to michael and angela pitullio martino .,Peter durant,<mask> l. <mask> is a <mask> democratic member of the <mask> house of representatives .he was born in butler to <mask> and angela pitullio <mask> .,0.608596,0.991162,4,1076,4,466,Successful
5,Salome jens,"salome jens (born may 8 , 1935) is an american stage , film and television actress .she is perhaps best known for portraying the female changeling on '' '' .",Deirdre lovejoy,"<mask> <mask> (born <mask> 8 , 1935) is an american stage , film and television actress .she is perhaps best known for portraying the female changeling on '' '' .",0.195223,0.990346,5,10660,5,214,Successful
6,Carl crawford,"carl demonte crawford (born august 5 , 1981) , nicknamed `` the perfect storm '' , is an american professional baseball left fielder with the los angeles dodgers of major league baseball (mlb) .he bats and throws left-handed .crawford was drafted by the tampa bay devil rays in the second round (52nd overall) of the 1999 major league baseball draft .he made his major league debut in 2002 .crawford has more triples (121) than any other active baseball player .",James russell,"<mask> demonte <mask> (born august 5 , 1981) , nicknamed `` the <mask> <mask> '' , is an american professional baseball left fielder with the los angeles dodgers of major league baseball (mlb) .he bats and throws left-handed .<mask> was drafted by the tampa bay devil rays in the second round (52nd overall) of the 1999 major league baseball draft .he made his major league debut in 2002 .crawford has more triples (121) than any other active baseball player .",0.312607,0.988668,6,179,6,1236,Successful
7,Jim bob,"jim bob (born james neil morrison on 22 november 1960) is a british musician and author , best known as the singer of indie punk band carter usm .",Robt ptak,"<mask> <mask> (born <mask> neil <mask> on 22 november 1960) is a british musician and author , <mask> known as the singer of indie punk band <mask> <mask> .",0.16694,0.994719,7,5162,7,592,Successful
8,Riddick parker,"riddick parker (born november 20 , 1972 in emporia , virginia) is a former professional american football defensive lineman for the seattle seahawks , san diego chargers , new england patriots , baltimore ravens , and san francisco 49ers of the national football league .",Dan mcgwire,"riddick <mask> (born november 20 , 1972 in <mask> , <mask>) is a former professional american football <mask> lineman for the seattle seahawks , san diego chargers , new england patriots , baltimore ravens , and san francisco 49ers of the national football league .",0.748561,0.984179,8,5042,8,471,Successful
9,Blessed osanna of cattaro -lrb- ozana kotorska -rrb-,blessed osanna of cattaro t.o.s.d. (-rrb- was a catholic visionary and anchoress from cattaro (kotor) .she was a teenage convert from orthodoxy of serbian descent from montenegro (zeta) .she became a dominican tertiary and was posthumously venerated as a saint in kotor .she was later beatified in 1934 .,Lea jagodič,<mask> <mask> of <mask> <mask>.o.s.d. (-rrb- <mask> a <mask> visionary and anchoress from <mask> (kotor) .she <mask> a teenage <mask> from <mask> of serbian descent from montenegro (zeta) .she <mask> a dominican tertiary and <mask> posthumously venerated as a saint in kotor .she was later beatified in 1934 .,0.119172,0.990009,9,145,9,2032,Successful


## Same attack but with k=100

In [37]:
from textattack import Attack
from textattack.constraints.pre_transformation import RepeatModification

goal_function = ChangeClassificationToBelowTopKClasses(model_wrapper, k=100)
constraints = [RepeatModification(), MaxNumWordsModified(max_num_words=25)]
transformation = WordSwapSingleWord(single_word=dm.tokenizer.mask_token)
search_method = textattack.search_methods.BeamSearch(beam_width=4)

attack = Attack(
    goal_function, constraints, transformation, search_method
)
# 
#  Initialize attack
# 
from tqdm import tqdm # tqdm provides us a nice progress bar.
from textattack.attack_results import SuccessfulAttackResult
from textattack import Attacker
from textattack import AttackArgs

attack_args = AttackArgs(num_examples=15, disable_stdout=True)
dataset = WikiDataset(dm)

attacker = Attacker(attack, dataset, attack_args)

results_iterable = attacker.attack_dataset()

logger = CustomCSVLogger(color_method='html')

# 
# Run attack
# 
from tqdm import tqdm
for result in results_iterable:
    tqdm._instances.clear() # Doesn't fix the progress bar :-(
    logger.log_attack_result(result)

from IPython.display import display, HTML

display(HTML(logger.df.to_html(escape=False)))

textattack: No entry found for goal function <class '__main__.ChangeClassificationToBelowTopKClasses'>.
textattack: Unknown if model of class <class 'model.DocumentProfileMatchingTransformer'> compatible with goal function <class '__main__.ChangeClassificationToBelowTopKClasses'>.


Attack(
  (search_method): BeamSearch(
    (beam_width):  4
  )
  (goal_function):  ChangeClassificationToBelowTopKClasses
  (transformation):  WordSwapSingleWord
  (constraints): 
    (0): RepeatModification
    (1): MaxNumWordsModified(
        (max_num_words):  25
      )
  (is_black_box):  True
) 



[Succeeded / Failed / Skipped / Total] 13 / 2 / 0 / 15:  43%|████▎     | 15/35 [01:34<02:05,  6.27s/it]
[Succeeded / Failed / Skipped / Total] 4 / 0 / 0 / 4:  40%|████      | 4/10 [00:58<01:28, 14.68s/it]
[Succeeded / Failed / Skipped / Total] 11 / 4 / 0 / 15: 100%|██████████| 15/15 [01:13<00:00,  4.92s/it]


+-------------------------------+--------+
| Attack Results                |        |
+-------------------------------+--------+
| Number of successful attacks: | 11     |
| Number of failed attacks:     | 4      |
| Number of skipped attacks:    | 0      |
| Original accuracy:            | 100.0% |
| Accuracy under attack:        | 26.67% |
| Attack success rate:          | 73.33% |
| Average perturbed word %:     | 37.71% |
| Average num. words per input: | 32.47  |
| Avg num queries:              | 1452.4 |
+-------------------------------+--------+


textattack: Logging to CSV at path results.csv
textattack: CSVLogger exiting without calling flush().





Unnamed: 0,original_person,original_text,perturbed_person,perturbed_text,original_score,perturbed_score,original_output,perturbed_output,ground_truth_output,num_queries,result_type
0,Michael iii of alexandria,"pope michael iii of alexandria (also known as khail iii) was the coptic pope of alexandria and patriarch of the see of st. mark (880 -- 907) .in 882 , the governor of egypt , ahmad ibn tulun , forced khail to pay heavy contributions , forcing him to sell a church and some attached properties to the local jewish community .this building was at one time believed to have later become the site of the cairo geniza .",Fouad twal البطريرك فؤاد طوال,"pope michael <mask> <mask> alexandria (<mask> known as <mask> <mask>) was <mask> coptic pope <mask> alexandria and <mask> of <mask> <mask> of st. <mask> (<mask> -- 907) .in 882 , <mask> governor <mask> <mask> , ahmad ibn tulun , <mask> <mask> <mask> <mask> heavy contributions , forcing him to sell a church and some attached properties to the local <mask> community .this building was at one time believed to <mask> <mask> become <mask> <mask> of <mask> cairo geniza .",0.669087,0.997515,0,396,0,5882,Failed
1,Hui jun,hui jun is a male former table tennis player from china .,Aran zalewski,<mask> <mask> <mask> <mask> <mask> <mask> <mask> <mask> <mask> <mask> <mask> .,0.0,0.998887,1,8565,1,232,Failed
2,Okan öztürk,okan Öztürk (born 30 november 1977) is a turkish professional footballer .he currently plays as a striker for yeni malatyaspor .,Artyom serdyuk,<mask> <mask> (born 30 <mask> <mask>) is a <mask> professional footballer .he currently plays as a <mask> for <mask> <mask> .,0.734742,0.998846,2,8196,2,469,Successful
3,Marie stephan,"marie stephan , (born march 14 , 1996) is a professional squash player who represents france .she reached a career-high world ranking of world no. 101 in july 2015 .",Amanda fink,"<mask> <mask> , (<mask> <mask> <mask> , <mask>) <mask> <mask> <mask> <mask> <mask> <mask> <mask> <mask> .<mask> <mask> <mask> <mask> <mask> ranking <mask> <mask> <mask>. 101 <mask> <mask> <mask> .",0.072457,0.985506,3,1166,3,1420,Failed
4,Leonard l. martino,leonard l. martino is a former democratic member of the pennsylvania house of representatives .he was born in butler to michael and angela pitullio martino .,Peter durant,<mask> l. <mask> is <mask> <mask> <mask> <mask> of the <mask> <mask> of <mask> .he was born in <mask> to <mask> and angela pitullio <mask> .,0.608596,0.999083,4,1076,4,862,Successful
5,Salome jens,"salome jens (born may 8 , 1935) is an american stage , film and television actress .she is perhaps best known for portraying the female changeling on '' '' .",Charulatha,"<mask> <mask> (born <mask> 8 , <mask>) is an american stage , film and television actress .she is <mask> best known for portraying the <mask> changeling on '' '' .",0.195223,0.998895,5,11608,5,466,Successful
6,Carl crawford,"carl demonte crawford (born august 5 , 1981) , nicknamed `` the perfect storm '' , is an american professional baseball left fielder with the los angeles dodgers of major league baseball (mlb) .he bats and throws left-handed .crawford was drafted by the tampa bay devil rays in the second round (52nd overall) of the 1999 major league baseball draft .he made his major league debut in 2002 .crawford has more triples (121) than any other active baseball player .",Cole figueroa,"<mask> <mask> <mask> (born <mask> 5 , 1981) , nicknamed <mask> the <mask> <mask> '' , is an american professional baseball left fielder with the los angeles dodgers of major league baseball (mlb) .he bats and throws left-handed .<mask> was drafted by the tampa bay <mask> rays in the second round (52nd overall) of the 1999 major league baseball draft .he made his major league debut in 2002 .crawford has more triples (121) than any other active baseball player .",0.312607,0.998572,6,11514,6,2332,Successful
7,Jim bob,"jim bob (born james neil morrison on 22 november 1960) is a british musician and author , best known as the singer of indie punk band carter usm .",Jai paul,"<mask> <mask> (born <mask> <mask> <mask> on 22 november 1960) is a <mask> musician and author , <mask> known as the singer of indie <mask> band <mask> <mask> .",0.16694,0.998714,7,10601,7,820,Successful
8,Riddick parker,"riddick parker (born november 20 , 1972 in emporia , virginia) is a former professional american football defensive lineman for the seattle seahawks , san diego chargers , new england patriots , baltimore ravens , and san francisco 49ers of the national football league .",Garnell wilds,"riddick <mask> (<mask> november 20 , <mask> in <mask> , <mask>) is a former <mask> american <mask> <mask> <mask> for the seattle seahawks , san diego <mask> , new england <mask> , <mask> ravens , and <mask> <mask> <mask> <mask> <mask> <mask> <mask> <mask> .",0.748561,0.998562,8,2962,8,2167,Successful
9,Blessed osanna of cattaro -lrb- ozana kotorska -rrb-,blessed osanna of cattaro t.o.s.d. (-rrb- was a catholic visionary and anchoress from cattaro (kotor) .she was a teenage convert from orthodoxy of serbian descent from montenegro (zeta) .she became a dominican tertiary and was posthumously venerated as a saint in kotor .she was later beatified in 1934 .,Lea jagodič,<mask> <mask> of <mask> <mask>.<mask>.s.d. (-rrb- <mask> <mask> <mask> <mask> and anchoress <mask> <mask> (kotor) .she <mask> a teenage <mask> <mask> <mask> of serbian descent <mask> montenegro (zeta) .she <mask> <mask> <mask> tertiary and <mask> <mask> venerated as a saint in kotor .she was later beatified in 1934 .,0.119172,0.998311,9,145,9,3292,Successful
