\begin{figure}[t]
\centering
\includegraphics[width=\linewidth]{figs/pdf/ag_news_unk.pdf}
\caption{The classification accuracy (\%) on benign samples and the corresponding adversarial examples generated by Textfooler by randomly substituting the words with ``UNK'' token (\textcolor{blue}{blue line}) or synonyms (\textcolor{red}{red line}) for different rates. The results are evaluated on 1,000 correctly classified samples from AG's News test set for Word-CNN.}
% \caption{The classification accuracy (\%) on $1,000$ correctly classified benign samples and the corresponding adversarial examples generated by Textfooler attack randomly sampled from IMDB test set by randomly substituting the words with ``UNK'' token (\textcolor{blue}{blue line}) or synonyms (\textcolor{red}{red line}) for different ratios on the Word-CNN model.}
\label{fig:unk}

\end{figure}