Red teaming

Exploiting Class Probabilities for Black-Box Sentence-Level Attacks