Research shows that adding small perturbation information to the deep neural network (DNN) can lead to DNN classification errors, which is called an adversarial sample attack. Adversarial sample attack also exists in the detection of spam messages in deep neural networks. Therefore, this paper proposes an adversarial sample generation method SWordAttacker for spam messages in the black-box situation. This method designed a new calculation method of word importance, found key clauses by combining attention mechanisms, and used the scoring function to find keywords in key clauses. Finally, the adversarial samples were generated by combining attack strategies such as insertion, exchange, and similar substitution. The experiments were conducted on two DNN models, long-short memory networks(LSTM) and convolutional neural networks(CNN), using short message service(SMS) Spam datasets, and AG’s News datasets to verify the effectiveness of the proposed method. The experimental results show that SWordAttacker can greatly reduce the accuracy of the model with small perturbations and improve efficiency.