### Additive redaction

I've designed the system to remove words until the prediction of the model changes. What if we instead start by masking everything and *unmask* words until the model prediction changes?

In [3]:
import sys
sys.path.append('/home/jxm3/research/deidentification/unsupervised-deidentification')

In [4]:
from dataloader import WikipediaDataModule
import os

num_cpus = len(os.sched_getaffinity(0))

dm = WikipediaDataModule(
    document_model_name_or_path="roberta-base",
    profile_model_name_or_path="google/tapas-base",
    max_seq_length=128,
    dataset_name='wiki_bio',
    dataset_train_split='train[:1024]', # not used in this notebook
    dataset_val_split='val[:20%]',
    dataset_version='1.2.0',
    word_dropout_ratio=0.0,
    word_dropout_perc=0.0,
    num_workers=1,
    train_batch_size=64,
    eval_batch_size=64
)
dm.setup("fit")

Initializing WikipediaDataModule with num_workers = 1 and mask token `<mask>`
loading wiki_bio[1.2.0] split train[:1024]


Using custom data configuration default
Reusing dataset wiki_bio (/home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da)


loading wiki_bio[1.2.0] split val[:20%]


Using custom data configuration default
Reusing dataset wiki_bio (/home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da)
Loading cached processed dataset at /home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da/cache-793b771e10f80bbe.arrow
Loading cached processed dataset at /home/jxm3/.cache/huggingface/datasets/wiki_bio/default/1.2.0/c05ce066e9026831cd7535968a311fc80f074b58868cfdffccbc811dff2ab6da/cache-7d07543b6205ca87.arrow


  0%|          | 0/1024 [00:00<?, ?ex/s]

  0%|          | 0/14566 [00:00<?, ?ex/s]

  0%|          | 0/14566 [00:00<?, ?ex/s]

  0%|          | 0/15 [00:00<?, ?ba/s]

  0%|          | 0/14566 [00:00<?, ?ex/s]

  0%|          | 0/14566 [00:00<?, ?ex/s]

  0%|          | 0/14566 [00:00<?, ?ex/s]

  0%|          | 0/14566 [00:00<?, ?ex/s]

In [46]:
from model import CoordinateAscentModel
from model_cfg import model_paths_dict

print(model_paths_dict.keys())
checkpoint_path = model_paths_dict["model_8_ls0.1"]


model = CoordinateAscentModel.load_from_checkpoint(
    checkpoint_path
)

dict_keys(['model_3', 'model_4', 'model_5', 'model_6', 'model_7', 'model_8_ls0.01', 'model_8_ls0.05', 'model_8_ls0.1', 'model_9_ls0.01', 'model_9_ls0.05', 'model_9_ls0.1'])


Some weights of the model checkpoint at roberta-base were not used when initializing RobertaModel: ['lm_head.decoder.weight', 'lm_head.dense.weight', 'lm_head.layer_norm.weight', 'lm_head.bias', 'lm_head.dense.bias', 'lm_head.layer_norm.bias']
- This IS expected if you are initializing RobertaModel from the checkpoint of a model trained on another task or with another architecture (e.g. initializing a BertForSequenceClassification model from a BertForPreTraining model).
- This IS NOT expected if you are initializing RobertaModel from the checkpoint of a model that you expect to be exactly identical (initializing a BertForSequenceClassification model from a BertForSequenceClassification model).


Initialized model with learning_rate = 4e-05 and patience 6


## 2. Define attack in TextAttack 

In [6]:
import textattack

### (a) Beam search + replace with `[MASK]`

In [88]:
import copy 
class UnmaskSingleWord(textattack.transformations.word_swap.WordSwap):
    """Takes a sentence and transforms it by replacing with a single fixed word.
    """
    mask_token: str
    def __init__(self, mask_token: str = "[MASK]", **kwargs):
        super().__init__(**kwargs)
        self.mask_token = mask_token
        
    def _get_transformations(self, current_text, indices_to_modify):
        num_words = len(current_text.words)
        
        # print(current_text, current_text.attack_attrs.keys())
        
        # If this is the first time this text is transformed, mask all the words
        # and store them.
        if not len(current_text.attack_attrs["modified_indices"]):
            new_text = current_text.replace_words_at_indices(
                range(num_words), [self.mask_token] * num_words
            )
            # Overwrite attack_attrs so all indices are modifiable
            new_text.attack_attrs = copy.copy(current_text.attack_attrs)
            # And store pointer to original so we can get words
            new_text.attack_attrs["original_attacked_text"] = current_text
            
            current_text = new_text

            
        transformations = []
        # Now return all possible one-word-masked options.
        for i in indices_to_modify:
            unmasked_idxs = current_text.attack_attrs["modified_indices"].union({i})
            masked_idxs = set(range(num_words)) - unmasked_idxs
            original_text = current_text.attack_attrs["original_attacked_text"]
            
            masked_text = original_text.replace_words_at_indices(
                list(masked_idxs), [self.mask_token] * len(masked_idxs)
            )
            
            # propagate pointer to original
            masked_text.attack_attrs["original_attacked_text"] = current_text.attack_attrs["original_attacked_text"]
            
            # modified indices are *unmasked* indices, not masked ones
            masked_text.attack_attrs["modified_indices"] = unmasked_idxs
            
            transformations.append(masked_text)

        return transformations

    
transformation = UnmaskSingleWord(mask_token=dm.document_tokenizer.mask_token)

import random
at = textattack.shared.AttackedText("Hello my name is Jack")
for _ in range(4):
    transformation_choices = transformation(at)
    print(transformation_choices)
    at = transformation_choices[0]
    print('\t', at, '//', at.attack_attrs)
    print("*"*40,'\n')

[<AttackedText "Hello <mask> <mask> <mask> <mask>">, <AttackedText "<mask> my <mask> <mask> <mask>">, <AttackedText "<mask> <mask> name <mask> <mask>">, <AttackedText "<mask> <mask> <mask> is <mask>">, <AttackedText "<mask> <mask> <mask> <mask> Jack">]
	 <AttackedText "Hello <mask> <mask> <mask> <mask>"> // {'newly_modified_indices': {1, 2, 3, 4}, 'previous_attacked_text': <AttackedText "Hello my name is Jack">, 'modified_indices': {0}, 'original_index_map': array([0, 1, 2, 3, 4]), 'prev_attacked_text': <AttackedText "Hello my name is Jack">, 'original_attacked_text': <AttackedText "Hello my name is Jack">, 'last_transformation': UnmaskSingleWord}
**************************************** 

[<AttackedText "Hello <mask> <mask> <mask> <mask>">, <AttackedText "Hello my <mask> <mask> <mask>">, <AttackedText "Hello <mask> name <mask> <mask>">, <AttackedText "Hello <mask> <mask> is <mask>">, <AttackedText "Hello <mask> <mask> <mask> Jack">]
	 <AttackedText "Hello <mask> <mask> <mask> <mask>">

### (b) "Attack success" as fullfilment of the metric

In [94]:
from typing import List
import torch
    
class MaximumWordsUnmasked(textattack.goal_functions.classification.ClassificationGoalFunction):
    """Attempts to unmask as many words as possible without letting
    the ground-truth output person get into the top-K people.
    """
    k: int
    def __init__(self, *args, k: int = 1, **kwargs):
        self.k = k
        super().__init__(*args, **kwargs, maximizable=True)

    def _correct_person_is_topk(self, model_output) -> bool:
        """Returns true if self.ground_truth_output is in the top self.k of predicted people."""
        original_class_score = model_output[self.ground_truth_output]
        num_better_classes = (model_output > original_class_score).sum()
        return num_better_classes < self.k

    def _is_goal_complete(self, model_output, attacked_text):
        return not self._correct_person_is_topk(model_output)

    def _should_skip(self, model_output, attacked_text):
        return not self._correct_person_is_topk(model_output)

    def _get_score(self, model_output, attacked_text):
        # Give the lowest score possible to inputs which are correctly classified.
        if self._correct_person_is_topk(model_output):
            return 0

        cur_num_words = attacked_text.num_words
        initial_num_words = self.initial_attacked_text.num_words

        # The main goal is to reduce the number of words (num_words_score)
        # Lower model score for the ground truth label is used as a tiebreaker (model_score)
        # TODO is this right? Only if self.initial_attacked_text has no masks and the new guy has all the masks.
        num_words_unmasked = len(attacked_text.attack_attrs["modified_indices"])
        model_score = 1.0 - model_output[self.ground_truth_output]
        
        return num_words_unmasked + model_score

    def extra_repr_keys(self):
        return ["maximizable"]
        
    """have to reimplement the following method to change the precision on the sum-to-one condition."""
    def _process_model_outputs(self, inputs, scores):
        """Processes and validates a list of model outputs.
        This is a task-dependent operation. For example, classification
        outputs need to have a softmax applied.
        """
        # Automatically cast a list or ndarray of predictions to a tensor.
        if isinstance(scores, list):
            scores = torch.tensor(scores)

        # Ensure the returned value is now a tensor.
        if not isinstance(scores, torch.Tensor):
            raise TypeError(
                "Must have list, np.ndarray, or torch.Tensor of "
                f"scores. Got type {type(scores)}"
            )

        # Validation check on model score dimensions
        if scores.ndim == 1:
            # Unsqueeze prediction, if it's been squeezed by the model.
            if len(inputs) == 1:
                scores = scores.unsqueeze(dim=0)
            else:
                raise ValueError(
                    f"Model return score of shape {scores.shape} for {len(inputs)} inputs."
                )
        elif scores.ndim != 2:
            # If model somehow returns too may dimensions, throw an error.
            raise ValueError(
                f"Model return score of shape {scores.shape} for {len(inputs)} inputs."
            )
        elif scores.shape[0] != len(inputs):
            # If model returns an incorrect number of scores, throw an error.
            raise ValueError(
                f"Model return score of shape {scores.shape} for {len(inputs)} inputs."
            )
        elif not ((scores.sum(dim=1) - 1).abs() < 1e-4).all():
            # Values in each row should sum up to 1. The model should return a
            # set of numbers corresponding to probabilities, which should add
            # up to 1. Since they are `torch.float` values, allow a small
            # error in the summation.
            scores = torch.nn.functional.softmax(scores, dim=1)
            if not ((scores.sum(dim=1) - 1).abs() < 1e-4).all():
                raise ValueError("Model scores do not add up to 1.")
        return scores.cpu()

## (c) Model wrapper that computes similarities of input documents with validation profiles

In [47]:
import numpy as np
import tqdm

def precompute_profile_embeddings(model):
    model.profile_model.cuda()
    model.profile_model.eval()
    model.profile_embed.cuda()
    model.profile_embed.eval()

    model.val_profile_embeddings = np.zeros((len(dm.val_dataset), model.shared_embedding_dim))
    for val_batch in tqdm.tqdm(dm.val_dataloader()[0], desc="Precomputing val embeddings", colour="green", leave=False):
        with torch.no_grad():
            profile_embeddings = model.forward_profile(batch=val_batch)
        model.val_profile_embeddings[val_batch["text_key_id"]] = profile_embeddings.cpu()
    model.val_profile_embeddings = torch.tensor(model.val_profile_embeddings, dtype=torch.float32)

precompute_profile_embeddings(model)

                                                                              3.65it/s]

In [48]:
import transformers
from model.model import Model

class MyModelWrapper(textattack.models.wrappers.ModelWrapper):
    model: Model
    tokenizer: transformers.AutoTokenizer
    profile_embeddings: torch.Tensor
    max_seq_length: int
    
    def __init__(self, model: Model, tokenizer: transformers.AutoTokenizer, max_seq_length: int = 128):
        self.model = model
        self.model.eval()
        self.tokenizer = tokenizer
        self.profile_embeddings = torch.tensor(model.val_profile_embeddings)
        self.max_seq_length = max_seq_length
                 
    def to(self, device):
        self.model.to(device)
        self.profile_embeddings.to(device)
        return self # so semantics `model = MyModelWrapper().to('cuda')` works properly

    def __call__(self, text_input_list: List[str], batch_size=32):
        model_device = next(self.model.parameters()).device
        
        doc_tokenized = self.tokenizer.batch_encode_plus(
            text_input_list,
            max_length=self.max_seq_length,
            padding='max_length',
            truncation=True,
            return_tensors='pt',
        )
        doc_tokenized = {f'document__{k}': v for k,v in doc_tokenized.items()}
        with torch.no_grad():
            document_embeddings = self.model.forward_document(batch=doc_tokenized, document_type='document')
            document_to_profile_logits = document_embeddings @ self.profile_embeddings.T.to(model_device)
            document_to_profile_probs = torch.nn.functional.softmax(
                document_to_profile_logits, dim=-1
            )
        assert document_to_profile_probs.shape == (len(text_input_list), len(self.profile_embeddings))
        return document_to_profile_probs
            

## (d) Dataset that loads Wikipedia documents with names as labels

Oh, and it filters out examples that are too long.

In [122]:
from typing import Tuple

from collections import OrderedDict

import datasets

class WikiDataset(textattack.datasets.Dataset):
    dataset: datasets.Dataset
    
    def __init__(self, dm: WikipediaDataModule):
        self.shuffled = True
        self.dataset = [ex for ex in dm.val_dataset]
        self.label_names = list(dm.val_dataset['name'])
    
    def __len__(self) -> int:
        return len(self.dataset)
    
    def __getitem__(self, i: int) -> Tuple[OrderedDict, int]:
        shortened_doc = self.dataset[i]['document']
        words = shortened_doc.split(' ')
        if len(words) > 100:
            words = words[:100]
            shortened_doc = ' '.join(words)
        
        input_dict = OrderedDict([
            ('document', shortened_doc)
        ])
        return input_dict, self.dataset[i]['text_key_id']
        

## 3. Run attack once

In [51]:
model_wrapper = MyModelWrapper(model=model, tokenizer=dm.document_tokenizer)
model_wrapper.to('cuda')

  self.profile_embeddings = torch.tensor(model.val_profile_embeddings)


<__main__.MyModelWrapper at 0x7f7907727670>

In [95]:
from textattack.shared import utils


def get_modified_idxs_in_order(at: textattack.shared.AttackedText) -> List[int]:
    """Traverses linked-list of attacked texts from attack process
    and creates a list of the modified word indices.
    """
    modified_word_idxs = []
    while True:
        if 'newly_modified_indices' not in at.attack_attrs:
            break
        modified_word_idxs.extend(at.attack_attrs['newly_modified_indices'])
        at = at.attack_attrs['prev_attacked_text']
    modified_word_idxs = modified_word_idxs[::-1]
    return modified_word_idxs[::-1]


def diff_color_with_idxs(at: textattack.attack_results.AttackResult, color_method=None):
    """Highlights the difference between two texts using color.
    
    This version also adds idx numbers to show which words were masked in which order.

    Has to account for deletions and insertions from original text to
    perturbed. Relies on the index map stored in
    ``self.original_result.attacked_text.attack_attrs["original_index_map"]``.
    """
    t1 = at.original_result.attacked_text
    t2 = at.perturbed_result.attacked_text

    if color_method is None:
        return t1.printable_text(), t2.printable_text()

    color_1 = at.original_result.get_text_color_input()
    color_2 = at.perturbed_result.get_text_color_perturbed()

    # iterate through and count equal/unequal words
    words_1_idxs = []
    t2_equal_idxs = set()
    original_index_map = t2.attack_attrs["original_index_map"]
    for t1_idx, t2_idx in enumerate(original_index_map):
        if t2_idx == -1:
            # add words in t1 that are not in t2
            words_1_idxs.append(t1_idx)
        else:
            w1 = t1.words[t1_idx]
            w2 = t2.words[t2_idx]
            if w1 == w2:
                t2_equal_idxs.add(t2_idx)
            else:
                words_1_idxs.append(t1_idx)

    # words to color in t2 are all the words that didn't have an equal,
    # mapped word in t1
    words_2_idxs = list(sorted(set(range(t2.num_words)) - t2_equal_idxs))

    # make lists of colored words
    words_1 = [t1.words[i] for i in words_1_idxs]
    words_1 = [utils.color_text(w, color_1, color_method) for w in words_1]
    
    # First, replace words with `word_xx` where xx is the index
    # of the order that word was modified.
    word_modification_order = {word_idx: swap_idx+1 for swap_idx, word_idx in enumerate(get_modified_idxs_in_order(t2))}
    words_2 = [f'{t2.words[i]}__{word_modification_order[i]}' for i in words_2_idxs]
    words_2 = [utils.color_text(w, color_2, color_method) for w in words_2]

    t1 = at.original_result.attacked_text.replace_words_at_indices(
        words_1_idxs, words_1
    )
    t2 = at.perturbed_result.attacked_text.replace_words_at_indices(
        words_2_idxs, words_2
    )

    key_color = ("bold", "underline")
    return (
        t1.printable_text(key_color=key_color, key_color_method=color_method),
        t2.printable_text(key_color=key_color, key_color_method=color_method),
    )

In [53]:
from textattack.loggers import CSVLogger
from textattack.shared import AttackedText

import pandas as pd
class CustomCSVLogger(CSVLogger):
    """Logs attack results to a CSV."""

    def log_attack_result(self, result: textattack.goal_function_results.ClassificationGoalFunctionResult):
        # TODO print like 'mask1', 'mask2',
        original_text, perturbed_text = diff_color_with_idxs(result, color_method=self.color_method)
        original_text = original_text.replace("\n", AttackedText.SPLIT_TOKEN)
        perturbed_text = perturbed_text.replace("\n", AttackedText.SPLIT_TOKEN)
        result_type = result.__class__.__name__.replace("AttackResult", "")
        row = {
            "original_person": result.original_result._processed_output[0],
            "original_text": original_text,
            "original_text_id_bm25": bm25.get_scores(result.original_result.attacked_text.text.split()).argmax(),
            "perturbed_person": result.perturbed_result._processed_output[0],
            "perturbed_text": perturbed_text,
            "perturbed_text_id_bm25": bm25.get_scores(result.perturbed_result.attacked_text.text.split()).argmax(),
            "original_score": result.original_result.score,
            "perturbed_score": result.perturbed_result.score,
            "original_output": result.original_result.output,
            "perturbed_output": result.perturbed_result.output,
            "ground_truth_output": result.original_result.ground_truth_output,
            "num_queries": result.num_queries,
            "result_type": result_type,
        }
        self.df = pd.concat([self.df, pd.DataFrame([row])], ignore_index=True)
        self._flushed = False

In [54]:
from typing import List

from nltk.corpus import stopwords
from rank_bm25 import BM25Okapi

eng_stopwords = stopwords.words('english')
from tqdm.auto import tqdm
tqdm.pandas()


def get_words_from_doc(s: List[str]) -> List[str]:
    words = s.split()
    return [w for w in words if not w in eng_stopwords]

def make_table_str(ex):
    ex['table_str'] = (
        ' '.join(ex['input_text']['table']['column_header'] + ex['input_text']['table']['content'])
    )
    return ex

prof_data = dm.val_dataset.map(make_table_str)
profile_corpus = prof_data['table_str']

tokenized_profile_corpus = [
    get_words_from_doc(prof) for prof in profile_corpus
]

bm25 = BM25Okapi(tokenized_profile_corpus)

  0%|          | 0/14566 [00:00<?, ?ex/s]

In [116]:
import numpy as np

from textattack.goal_function_results import GoalFunctionResultStatus
from textattack.search_methods import SearchMethod

class MyBeamSearch(textattack.search_methods.SearchMethod):
    """An attack that maintinas a beam of the `beam_width` highest scoring
    AttackedTexts, greedily updating the beam with the highest scoring
    transformations from the current beam.
    Args:
        goal_function: A function for determining how well a perturbation is doing at achieving the attack's goal.
        transformation: The type of transformation.
        beam_width (int): the number of candidates to retain at each step
    """

    def __init__(self, beam_width=8):
        self.beam_width = beam_width

    def perform_search(self, initial_result):
        beam = [initial_result.attacked_text]
        best_result = initial_result
        best_score = 0
        while not best_result.goal_status == GoalFunctionResultStatus.SUCCEEDED:
            potential_next_beam = []
            for text in beam:
                transformations = self.get_transformations(
                    text, original_text=initial_result.attacked_text
                )
                potential_next_beam += transformations

            if len(potential_next_beam) == 0:
                # If we did not find any possible perturbations, give up.
                return best_result
            results, search_over = self.get_goal_results(potential_next_beam)
            scores = np.array([r.score for r in results])
            
            current_best_result = results[scores.argmax()]
            current_best_score = scores.max()
            
            # My change: condition to check if we found *any* changes that help maximize
            # the score. If not, we stop!
            if current_best_score > best_score:
                best_score = current_best_score
                best_result = current_best_result
            else:
                search_over = True
            
            if search_over:
                return best_result

            # Refill the beam. This works by sorting the scores
            # in descending order and filling the beam from there.
            best_indices = (-scores).argsort()[: self.beam_width]
            beam = [potential_next_beam[i] for i in best_indices]

        return best_result

    @property
    def is_black_box(self):
        return True

    def extra_repr_keys(self):
        return ["beam_width"]
    

In [119]:
# 
#  Initialize attack
# 

from textattack import Attack
from textattack.constraints.pre_transformation import MaxWordIndexModification, RepeatModification

goal_function = MaximumWordsUnmasked(model_wrapper, k=1)
constraints = [
    RepeatModification(),
    MaxWordIndexModification(max_length=dm.max_seq_length)
]
transformation = UnmaskSingleWord(mask_token=dm.document_tokenizer.mask_token)
# search_method = textattack.search_methods.BeamSearch(beam_width=1)
search_method = MyBeamSearch(beam_width=1)
# search_method = textattack.search_methods.GreedyWordSwapWIR(unk_token=dm.document_tokenizer.mask_token)

attack = Attack(
    goal_function, constraints, transformation, search_method
)

from tqdm import tqdm # tqdm provides us a nice progress bar.
from textattack.attack_results import SuccessfulAttackResult
from textattack import Attacker
from textattack import AttackArgs

attack_args = AttackArgs(num_examples=30, disable_stdout=True)
dataset = WikiDataset(dm)

attacker = Attacker(attack, dataset, attack_args)

results_iterable = attacker.attack_dataset()

logger = CustomCSVLogger(color_method='html')

# 
# Run attack
# 
from tqdm import tqdm
for result in results_iterable:
    tqdm._instances.clear() # Doesn't fix the progress bar :-(
    logger.log_attack_result(result)

from IPython.display import display, HTML

display(HTML(logger.df.to_html(escape=False)))

textattack: No entry found for goal function <class '__main__.MaximumWordsUnmasked'>.
textattack: Unknown if model of class <class 'model.coordinate_ascent.CoordinateAscentModel'> compatible with goal function <class '__main__.MaximumWordsUnmasked'>.
  0%|          | 0/1 [11:47<?, ?it/s]


Attack(
  (search_method): MyBeamSearch(
    (beam_width):  1
  )
  (goal_function):  MaximumWordsUnmasked(
    (maximizable):  True
  )
  (transformation):  UnmaskSingleWord
  (constraints): 
    (0): RepeatModification
    (1): MaxWordIndexModification(
        (max_length):  128
      )
  (is_black_box):  True
) 




  0%|          | 0/30 [00:00<?, ?it/s][A
  3%|▎         | 1/30 [00:19<09:15, 19.14s/it][A
[Succeeded / Failed / Skipped / Total] 1 / 0 / 0 / 1:   3%|▎         | 1/30 [00:19<09:15, 19.15s/it][A
[Succeeded / Failed / Skipped / Total] 1 / 0 / 0 / 1:   7%|▋         | 2/30 [00:19<04:33,  9.76s/it][A
[Succeeded / Failed / Skipped / Total] 2 / 0 / 0 / 2:   7%|▋         | 2/30 [00:19<04:33,  9.76s/it][A
[Succeeded / Failed / Skipped / Total] 2 / 0 / 0 / 2:  10%|█         | 3/30 [00:20<03:06,  6.92s/it][A
[Succeeded / Failed / Skipped / Total] 3 / 0 / 0 / 3:  10%|█         | 3/30 [00:20<03:06,  6.92s/it][A
[Succeeded / Failed / Skipped / Total] 3 / 0 / 0 / 3:  13%|█▎        | 4/30 [00:22<02:29,  5.74s/it][A
[Succeeded / Failed / Skipped / Total] 4 / 0 / 0 / 4:  13%|█▎        | 4/30 [00:22<02:29,  5.74s/it][A
[Succeeded / Failed / Skipped / Total] 4 / 0 / 0 / 4:  17%|█▋        | 5/30 [00:24<02:04,  5.00s/it][A
[Succeeded / Failed / Skipped / Total] 5 / 0 / 0 / 5:  17%|█▋        | 5/30


+-------------------------------+--------+
| Attack Results                |        |
+-------------------------------+--------+
| Number of successful attacks: | 30     |
| Number of failed attacks:     | 0      |
| Number of skipped attacks:    | 0      |
| Original accuracy:            | 100.0% |
| Accuracy under attack:        | 0.0%   |
| Attack success rate:          | 100.0% |
| Average perturbed word %:     | 31.15% |
| Average num. words per input: | 88.77  |
| Avg num queries:              | 2523.6 |
+-------------------------------+--------+


textattack: Logging to CSV at path results.csv
textattack: CSVLogger exiting without calling flush().





Unnamed: 0,original_person,original_text,original_text_id_bm25,perturbed_person,perturbed_text,perturbed_text_id_bm25,original_score,perturbed_score,original_output,perturbed_output,ground_truth_output,num_queries,result_type
0,Michael iii of alexandria,"pope michael iii of alexandria ( also known as khail iii ) was the coptic pope of alexandria and patriarch of the see of st. mark ( 880 -- 907 ) .in 882 , the governor of egypt , ahmad ibn tulun , forced khail to pay heavy contributions , forcing him to sell a church and some attached properties to the local jewish community .this building was at one time believed to have later become the site of the cairo geniza .",0,Bodhendra saraswathi,"pope <mask__1> <mask__2> <mask__3> <mask__4> ( also known as <mask__5> <mask__6> ) was the coptic pope of alexandria <mask__7> patriarch of the see of st. mark ( <mask__8> -- <mask__9> ) .in <mask__10> , the governor of egypt , ahmad ibn tulun , forced khail to pay heavy contributions , forcing him to sell a church and some attached properties to the local jewish community .this building was at one time believed to have later become the site of the cairo geniza .",12300,0,63.928352,0,12867,0,2657,Maximized
1,Hui jun,hui jun is a male former table tennis player from china .,1,Ian lucas,<mask__1> <mask__2> is a <mask__3> former <mask__4> <mask__5> player <mask__6> <mask__7> .,12781,0,4.963614,1,5751,1,46,Maximized
2,Okan öztürk,okan Öztürk ( born 30 november 1977 ) is a turkish professional footballer .he currently plays as a striker for yeni malatyaspor .,2,Diego morales,<mask__1> <mask__2> ( born 30 november <mask__3> ) is <mask__4> <mask__5> professional footballer .he currently plays as a striker for <mask__6> <mask__7> .,5167,0,13.952873,2,9993,2,190,Maximized
3,Marie stephan,"marie stephan , ( born march 14 , 1996 ) is a professional squash player who represents france .she reached a career-high world ranking of world no. 101 in july 2015 .",3,Laura pomportes,"<mask__1> <mask__2> , ( born <mask__3> 14 , <mask__4> ) is a professional squash player who represents <mask__5> .she reached a career-high world ranking of world no. 101 in july <mask__6> .",4624,0,21.843554,3,4726,3,364,Maximized
4,Leonard l. martino,leonard l. martino is a former democratic member of the pennsylvania house of representatives .he was born in butler to michael and angela pitullio martino .,4,Charles n. caputo,<mask__1> <mask__2>. <mask__3> is a former democratic member of the pennsylvania house of representatives .he was <mask__4> in butler to michael and angela pitullio martino .,4,0,21.821201,4,8689,4,320,Maximized
5,Salome jens,"salome jens ( born may 8 , 1935 ) is an american stage , film and television actress .she is perhaps best known for portraying the female changeling on '' '' .",5,Kevin pike,"<mask__1> <mask__2> ( born may 8 , <mask__3> ) is an american stage , film and television actress .she is perhaps best known for portraying the female changeling on '' '' .",6420,0,22.777472,5,9038,5,323,Maximized
6,Carl crawford,"carl demonte crawford ( born august 5 , 1981 ) , nicknamed `` the perfect storm '' , is an american professional baseball left fielder with the los angeles dodgers of major league baseball ( mlb ) .he bats and throws left-handed .crawford was drafted by the tampa bay devil rays in the second round ( 52nd overall ) of the 1999 major league baseball draft .he made his major league debut in 2002 .crawford has more triples ( 121 ) than any other active baseball player .",6,Wade davis,"<mask__1> demonte <mask__2> ( born <mask__3> <mask__4> , <mask__5> ) , nicknamed <mask__6> <mask__7> perfect storm '' , is an american professional baseball <mask__8> <mask__9> with <mask__10> <mask__11> <mask__12> <mask__13> <mask__14> major league baseball ( mlb ) .he bats and throws left-handed .<mask__15> was drafted by the tampa <mask__16> devil rays in the second round ( 52nd overall ) of the <mask__17> major league baseball draft .he made his major league debut in <mask__18> .<mask__19> has more triples ( 121 ) than any other active baseball player .",9148,0,56.751282,6,8580,6,2680,Maximized
7,Jim bob,"jim bob ( born james neil morrison on 22 november 1960 ) is a british musician and author , best known as the singer of indie punk band carter usm .",7,Adam devlin,"<mask__1> <mask__2> ( born <mask__3> neil morrison on <mask__4> <mask__5> <mask__6> ) is a british musician and author , best known as the singer of indie <mask__7> band carter usm .",7,0,20.886332,7,7803,7,358,Maximized
8,Riddick parker,"riddick parker ( born november 20 , 1972 in emporia , virginia ) is a former professional american football defensive lineman for the seattle seahawks , san diego chargers , new england patriots , baltimore ravens , and san francisco 49ers of the national football league .",8,Jerry patton,"<mask__1> <mask__2> ( born <mask__3> <mask__4> , <mask__5> in emporia , <mask__6> ) is a former professional american football defensive lineman for the seattle seahawks , san diego chargers , new england patriots , baltimore ravens , and san francisco 49ers of the national football league .",8,0,32.892704,8,8498,8,727,Maximized
9,Blessed osanna of cattaro -lrb- ozana kotorska -rrb-,blessed osanna of cattaro t.o.s.d. ( ) was a catholic visionary and anchoress from cattaro ( kotor ) .she was a teenage convert from orthodoxy of serbian descent from montenegro ( zeta ) .she became a dominican tertiary and was posthumously venerated as a saint in kotor .she was later beatified in 1934 .,9,Blessed anna maria rubatto,blessed <mask__1> <mask__2> <mask__3> t.o.s.d. ( ) was a catholic visionary and anchoress from cattaro ( <mask__5> ) .she was a teenage convert from orthodoxy of serbian descent from <mask__6> ( zeta ) .she became a dominican tertiary and was posthumously venerated as a saint in <mask__4> .she was later beatified in 1934 .,9,0,44.704853,9,3107,9,1261,Maximized


In [120]:
print("hi")

hi
