Character-level perturbations (homoglyphs, invisible Unicode characters) - Word-level substitutions that preserve meaning to humans but fool NLP models - Sentence-level paraphrasing that evades content filters