% \begin{figure*}[tb]
% !htb
\begin{figure*}[!tb]

\centering
\includegraphics[width=\textwidth]{figs/pdf/frame.pdf}

\caption{The overall framework of the proposed \name method. For an input $x$, we first generate the synonym set $\mathcal{S}(w_i)$ for each word $w_i \in x$ using the GloVe vector as well as WordNet, and randomly substitute a word $w_i \in x$ with its arbitrary synonym $\hat{w}_i^j \in \mathcal{S}(w_i)$ to generate multiple texts. Then we feed these generated texts and accumulate the logits to get the voted label. Finally, we regard $x$ as an adversarial example if the \name label is not consistent with the prediction label for $x$. }

\label{fig:RS}
\end{figure*}