{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T14:16:52Z","timestamp":1776176212500,"version":"3.50.1"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,11,2]],"date-time":"2023-11-02T00:00:00Z","timestamp":1698883200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,11,2]],"date-time":"2023-11-02T00:00:00Z","timestamp":1698883200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Key Cooperation Project of Chongqing Municipal Education Commission","award":["No. HZ2021008"],"award-info":[{"award-number":["No. HZ2021008"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2024,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Deep neural networks are known to be vulnerable to various types of adversarial attacks, especially word-level attacks, in the field of natural language processing. In recent years, various defense methods are proposed against word-level attacks; however, most of those defense methods only focus on synonyms substitution-based attacks, while word-level attacks are not based on synonym substitution. In this paper, we propose a textual adversarial defense method against word-level adversarial attacks via textual embedding based on the semantic associative field. More specifically, we analyze the reasons why humans can read and understand textual adversarial examples and observe two crucial points: (1) There must be a relation between the original word and the perturbed word or token. (2) Such a kind of relation enables humans to infer original words, while humans have the ability to associations. Motivated by this, we introduce the concept of semantic associative field and propose a new defense method by building a robust word embedding, that is, we calculate the word vector by exerting the related word vector to it with potential function and weighted embedding sampling for simulating the semantic influence between words in same semantic field. We conduct comprehensive experiments and demonstrate that the models using the proposed method can achieve higher accuracy than the baseline defense methods under various adversarial attacks or original testing sets. Moreover, the proposed method is more universal, while it is irrelevant to model structure and will not affect the efficiency of training.<\/jats:p>","DOI":"10.1007\/s00521-023-08946-7","type":"journal-article","created":{"date-parts":[[2023,11,2]],"date-time":"2023-11-02T10:02:29Z","timestamp":1698919349000},"page":"289-301","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Defense against adversarial attacks via textual embeddings based on semantic associative field"],"prefix":"10.1007","volume":"36","author":[{"given":"Jiacheng","family":"Huang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Long","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,11,2]]},"reference":[{"key":"8946_CR1","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 770\u2013778","DOI":"10.1109\/CVPR.2016.90"},{"issue":"6","key":"8946_CR2","doi-asserted-by":"publisher","first-page":"84","DOI":"10.1145\/3065386","volume":"60","author":"A Krizhevsky","year":"2017","unstructured":"Krizhevsky A, Sutskever I, Hinton GE (2017) Imagenet classification with deep convolutional neural networks. Commun ACM 60(6):84\u201390. https:\/\/doi.org\/10.1145\/3065386","journal-title":"Commun ACM"},{"key":"8946_CR3","doi-asserted-by":"crossref","unstructured":"Xue W, Li T (2018) Aspect based sentiment analysis with gated convolutional networks. In: Proceedings of the 56th annual meeting of the association for computational linguistics (ACL). Association for Computational Linguistics, Melbourne, Australia, pp 2514\u20132523","DOI":"10.18653\/v1\/P18-1234"},{"key":"8946_CR4","unstructured":"Bojarski M, Testa DD, Dworakowski D, Firner B, Flepp B, Goyal P, Jackel LD, Monfort M, Muller U, Zhang J, Zhang X, Zhao J, Zieba K (2016) End to end learning for self-driving cars. arXiv:1604.07316"},{"key":"8946_CR5","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, Fergus R (2014) Intriguing properties of neural networks. In: Proceedings of the 2nd international conference on learning representations (ICLR), pp 1\u201310"},{"key":"8946_CR6","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: Proceedings of the 3rd international conference on learning representations (ICLR), pp 1\u201311"},{"key":"8946_CR7","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: Proceedings of the 2017 IEEE symposium on security and privacy (SP), pp 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"8946_CR8","doi-asserted-by":"publisher","unstructured":"Ebrahimi J, Rao A, Lowd D, Dou D (2018) HotFlip: White-box adversarial examples for text classification. In: Proceedings of the 56th annual meeting of the association for computational linguistics (volume 2: short papers). Association for Computational Linguistics, Melbourne, Australia, pp 31\u201336. https:\/\/doi.org\/10.18653\/v1\/P18-2006","DOI":"10.18653\/v1\/P18-2006"},{"key":"8946_CR9","doi-asserted-by":"publisher","unstructured":"Gil Y, Chai Y, Gorodissky O, Berant J (2019) White-to-black: efficient distillation of black-box adversarial attacks. In: Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). Association for Computational Linguistics, Minneapolis, Minnesota, pp 1373\u20131379. https:\/\/doi.org\/10.18653\/v1\/N19-1139","DOI":"10.18653\/v1\/N19-1139"},{"key":"8946_CR10","doi-asserted-by":"publisher","unstructured":"Pruthi D, Dhingra B, Lipton ZC (2019) Combating adversarial misspellings with robust word recognition. In: Proceedings of the 57th annual meeting of the association for computational linguistics. Association for Computational Linguistics, Florence, Italy, pp 5582\u20135591. https:\/\/doi.org\/10.18653\/v1\/P19-1561","DOI":"10.18653\/v1\/P19-1561"},{"key":"8946_CR11","doi-asserted-by":"publisher","unstructured":"Ren S, Deng Y, He K, Che W (2019) Generating natural language adversarial examples through probability weighted word saliency. In: Proceedings of the 57th annual meeting of the association for computational linguistics. Association for Computational Linguistics, Florence, Italy, pp 1085\u20131097. https:\/\/doi.org\/10.18653\/v1\/P19-1103","DOI":"10.18653\/v1\/P19-1103"},{"key":"8946_CR12","doi-asserted-by":"publisher","unstructured":"Zhang H, Zhou H, Miao N, Li L (2019) Generating fluent adversarial examples for natural languages. In: Proceedings of the 57th annual meeting of the association for computational linguistics. Association for Computational Linguistics, Florence, Italy, pp 5564\u20135569. https:\/\/doi.org\/10.18653\/v1\/P19-1559","DOI":"10.18653\/v1\/P19-1559"},{"key":"8946_CR13","doi-asserted-by":"crossref","unstructured":"Zang Y, Qi F, Yang C, Liu Z, Zhang M, Liu Q, Sun M (2020) Word-level textual adversarial attacking as combinatorial optimization. In: Proceedings of the 58th annual meeting of the association for computational linguistics (ACL). Association for Computational Linguistics, pp 6066\u20136080","DOI":"10.18653\/v1\/2020.acl-main.540"},{"key":"8946_CR14","doi-asserted-by":"publisher","unstructured":"Cao Y, Zhou Z, Chakraborty C, Wang M, Wu QMJ, Sun X, Yu K (2022) Generative steganography based on long readable text generation. IEEE Trans Comput Soc Syst 1\u201311. https:\/\/doi.org\/10.1109\/TCSS.2022.3174013","DOI":"10.1109\/TCSS.2022.3174013"},{"key":"8946_CR15","doi-asserted-by":"publisher","first-page":"309","DOI":"10.14257\/ijsia.2016.10.9.30","volume":"10","author":"Z Zhou","year":"2016","unstructured":"Zhou Z, Mu Y, Yang C-N, Zhao N (2016) Coverless multi-keywords information hiding method based on text. Int J Secur Appl 10:309\u2013320. https:\/\/doi.org\/10.14257\/ijsia.2016.10.9.30","journal-title":"Int J Secur Appl"},{"key":"8946_CR16","doi-asserted-by":"crossref","unstructured":"Li J, Ji S, Du T, Li B, Wang T (2019) Textbugger: generating adversarial text against real-world applications. In: Proceedings of the 26th annual network and distributed system security symposium (NDSS). The Internet Society, San Diego, California, pp 1\u201315","DOI":"10.14722\/ndss.2019.23138"},{"key":"8946_CR17","doi-asserted-by":"publisher","unstructured":"Jia R, Raghunathan A, G\u00f6ksel K, Liang P (2019) Certified robustness to adversarial word substitutions. In: Proceedings of the 2019 conference on empirical methods in natural language processing and the 9th international joint conference on natural language processing (EMNLP-IJCNLP). Association for Computational Linguistics, Hong Kong, China, pp 4129\u20134142. https:\/\/doi.org\/10.18653\/v1\/D19-1423","DOI":"10.18653\/v1\/D19-1423"},{"key":"8946_CR18","doi-asserted-by":"publisher","unstructured":"He X, Lyu L, Sun L, Xu Q (2021) Model extraction and adversarial transferability, your BERT is vulnerable! In: Proceedings of the 2021 conference of the North American chapter of the association for computational linguistics: human language technologies. Association for Computational Linguistics, pp 2006\u20132012. https:\/\/doi.org\/10.18653\/v1\/2021.naacl-main.161","DOI":"10.18653\/v1\/2021.naacl-main.161"},{"key":"8946_CR19","doi-asserted-by":"publisher","unstructured":"Eger S, \u015eahin GG, R\u00fcckl\u00e9 A, Lee J-U, Schulz C, Mesgar M, Swarnkar K, Simpson E, Gurevych I (2019) Text processing like humans do: visually attacking and shielding NLP systems. In: Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). Association for Computational Linguistics, Minneapolis, Minnesota, pp 1634\u20131647. https:\/\/doi.org\/10.18653\/v1\/N19-1165","DOI":"10.18653\/v1\/N19-1165"},{"key":"8946_CR20","doi-asserted-by":"publisher","unstructured":"Sato M, Suzuki J, Shindo H, Matsumoto Y (2018) Interpretable adversarial perturbation in input embedding space for text. In: Proceedings of the twenty-seventh international joint conference on artificial intelligence (IJCAI). Stockholm, Sweden, pp 4323\u20134330. https:\/\/doi.org\/10.24963\/ijcai.2018\/601","DOI":"10.24963\/ijcai.2018\/601"},{"key":"8946_CR21","doi-asserted-by":"crossref","unstructured":"Jia R, Liang P (2017) Adversarial examples for evaluating reading comprehension systems. In: Proceedings of the 2017 conference on empirical methods in natural language processing (EMNLP). Association for Computational Linguistics, Copenhagen, Denmark, pp 2021\u20132031","DOI":"10.18653\/v1\/D17-1215"},{"key":"8946_CR22","doi-asserted-by":"publisher","unstructured":"Iyyer M, Wieting J, Gimpel K, Zettlemoyer L (2018) Adversarial example generation with syntactically controlled paraphrase networks. In: Proceedings of the 2018 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long papers). Association for Computational Linguistics, New Orleans, Louisiana, pp 1875\u20131885. https:\/\/doi.org\/10.18653\/v1\/N18-1170","DOI":"10.18653\/v1\/N18-1170"},{"key":"8946_CR23","doi-asserted-by":"publisher","unstructured":"Ribeiro MT, Singh S, Guestrin C (2018) Semantically equivalent adversarial rules for debugging NLP models. In: Proceedings of the 56th annual meeting of the association for computational linguistics (volume 1: long papers). Association for Computational Linguistics, Melbourne, Australia, pp 856\u2013865. https:\/\/doi.org\/10.18653\/v1\/P18-1079","DOI":"10.18653\/v1\/P18-1079"},{"key":"8946_CR24","doi-asserted-by":"publisher","unstructured":"Alzantot M, Sharma Y, Elgohary A, Ho B-J, Srivastava M, Chang K.-W (2018) Generating natural language adversarial examples. In: Proceedings of the 2018 conference on empirical methods in natural language processing. Association for Computational Linguistics, Brussels, Belgium, pp 2890\u20132896. https:\/\/doi.org\/10.18653\/v1\/D18-1316","DOI":"10.18653\/v1\/D18-1316"},{"key":"8946_CR25","doi-asserted-by":"publisher","unstructured":"Dinan E, Humeau S, Chintagunta B, Weston J (2019) Build it break it fix it for dialogue safety: Robustness from adversarial human attack. In: Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP), pp. 4537\u20134546. Association for Computational Linguistics, Hong Kong, China. https:\/\/doi.org\/10.18653\/v1\/D19-1461","DOI":"10.18653\/v1\/D19-1461"},{"key":"8946_CR26","unstructured":"Wang X, Hao J, Yang Y, He K (2021) Natural language adversarial defense through synonym encoding. In: de Campos CP, Maathuis MH, Quaeghebeur E (eds) Proceedings of the thirty-seventh conference on uncertainty in artificial intelligence UAI. Proceedings of machine learning research, vol 161. AUAI Press, Virtual Event, pp 823\u2013833. https:\/\/proceedings.mlr.press\/v161\/wang21a.html"},{"key":"8946_CR27","doi-asserted-by":"publisher","unstructured":"Ye M, Gong C, Liu Q (2020) SAFER: A structure-free approach for certified robustness to adversarial word substitutions. In: Proceedings of the 58th annual meeting of the association for computational linguistics. Association for Computational Linguistics, pp 3465\u20133475. https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.317","DOI":"10.18653\/v1\/2020.acl-main.317"},{"key":"8946_CR28","doi-asserted-by":"publisher","unstructured":"Zhou Y, Zheng X, Hsieh C-J, Chang K-W, Huang X (2021) Defense against synonym substitution-based adversarial attacks via Dirichlet neighborhood ensemble. In: Proceedings of the 59th annual meeting of the association for computational linguistics and the 11th international joint conference on natural language processing (volume 1: long papers). Association for Computational Linguistics, pp 5482\u20135492. https:\/\/doi.org\/10.18653\/v1\/2021.acl-long.426","DOI":"10.18653\/v1\/2021.acl-long.426"},{"issue":"2","key":"8946_CR29","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1109\/69.917563","volume":"13","author":"A Paccanaro","year":"2001","unstructured":"Paccanaro A, Hinton GE (2001) Learning distributed representations of concepts using linear relational embedding. IEEE Trans Knowl Data Eng 13(2):232\u2013244. https:\/\/doi.org\/10.1109\/69.917563","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"8946_CR30","unstructured":"Mikolov T, Chen K, Corrado G, Dean J (2013) Efficient estimation of word representations in vector space. In: Proceedings of the 1st international conference on learning representations (ICLR), pp 1\u201312"},{"key":"8946_CR31","doi-asserted-by":"publisher","unstructured":"Pennington J, Socher R, Manning C (2014) GloVe: global vectors for word representation. In: Proceedings of the 2014 conference on empirical methods in natural language processing (EMNLP). Association for Computational Linguistics, Doha, Qatar, pp 1532\u20131543. https:\/\/doi.org\/10.3115\/v1\/D14-1162","DOI":"10.3115\/v1\/D14-1162"},{"key":"8946_CR32","doi-asserted-by":"publisher","unstructured":"Peters ME, Neumann M, Iyyer M, Gardner M, Clark C, Lee K, Zettlemoyer L Deep contextualized word representations. In: Proceedings of the 2018 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long papers). Association for Computational Linguistics, New Orleans, Louisiana, pp 2227\u20132237 (2018). https:\/\/doi.org\/10.18653\/v1\/N18-1202","DOI":"10.18653\/v1\/N18-1202"},{"key":"8946_CR33","doi-asserted-by":"publisher","unstructured":"Devlin J, Chang M-W, Lee K, Toutanova K (2019) BERT: Pre-training of deep bidirectional transformers for language understanding. In: Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). Association for Computational Linguistics, Minneapolis, Minnesota, pp 4171\u20134186 (2019). https:\/\/doi.org\/10.18653\/v1\/N19-1423","DOI":"10.18653\/v1\/N19-1423"},{"key":"8946_CR34","doi-asserted-by":"publisher","unstructured":"Miller, G.A.: Wordnet: A lexical database for English. In: Proceedings of the workshop on human language technology. HLT \u201993. Association for Computational Linguistics, USA, p 409 (1993). https:\/\/doi.org\/10.3115\/1075671.1075788","DOI":"10.3115\/1075671.1075788"},{"key":"8946_CR35","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2021.101337","volume":"74","author":"M AlMousa","year":"2022","unstructured":"AlMousa M, Benlamri R, Khoury R (2022) A novel word sense disambiguation approach using wordnet knowledge graph. Comput Speech Lang 74:101337. https:\/\/doi.org\/10.1016\/j.csl.2021.101337","journal-title":"Comput Speech Lang"},{"issue":"2","key":"8946_CR36","doi-asserted-by":"publisher","first-page":"2069","DOI":"10.3233\/JIFS-219306","volume":"43","author":"S Butt","year":"2022","unstructured":"Butt S, Bakhtyar M, Noor W, Baber J, Ullah I, Ahmed A, Basit A, Kakar MSH (2022) Semantic similarity based food entities recognition using wordnet. J Intell Fuzzy Syst 43(2):2069\u20132078. https:\/\/doi.org\/10.3233\/JIFS-219306","journal-title":"J Intell Fuzzy Syst"},{"key":"8946_CR37","doi-asserted-by":"publisher","first-page":"675","DOI":"10.1007\/978-3-030-69143-1_51","volume-title":"Information and Communication Technology and Applications","author":"EF Aminu","year":"2021","unstructured":"Aminu EF, Oyefolahan IO, Abdullahi MB, Salaudeen MT (2021) An enhanced wordnet query expansion approach for ontology based information retrieval system. In: Misra S, Muhammad-Bello B (eds) Information and Communication Technology and Applications. Springer, Cham, pp 675\u2013688"},{"issue":"137","key":"8946_CR38","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1515\/ling.1974.12.137.79","volume":"12","author":"LM Vassilyev","year":"1974","unstructured":"Vassilyev LM (1974) The theory of semantic fields: a survey. Linguistics 12(137):79\u201394. https:\/\/doi.org\/10.1515\/ling.1974.12.137.79","journal-title":"Linguistics"},{"key":"8946_CR39","unstructured":"Maas AL, Daly RE, Pham PT, Huang D, Ng AY, Potts C (2011) Learning word vectors for sentiment analysis. In: Proceedings of the 49th annual meeting of the association for computational linguistics: human language technologies. Association for Computational Linguistics, Portland, Oregon, USA, pp 142\u2013150 (2011). https:\/\/aclanthology.org\/P11-1015"},{"key":"8946_CR40","first-page":"1","volume-title":"Advances in Neural Information Processing Systems","author":"X Zhang","year":"2015","unstructured":"Zhang X, Zhao J, LeCun Y (2015) Character-level convolutional networks for text classification. In: Cortes C, Lawrence N, Lee D, Sugiyama M, Garnett R (eds) Advances in Neural Information Processing Systems, vol 28. Curran Associates Inc, Montreal, pp 1\u20139"},{"key":"8946_CR41","doi-asserted-by":"publisher","unstructured":"Bowman SR, Angeli G, Potts C, Manning CD (2015) A large annotated corpus for learning natural language inference. In: Proceedings of the 2015 conference on empirical methods in natural language processing. Association for Computational Linguistics, Lisbon, Portugal, pp 632\u2013642. https:\/\/doi.org\/10.18653\/v1\/D15-1075","DOI":"10.18653\/v1\/D15-1075"},{"key":"8946_CR42","doi-asserted-by":"publisher","unstructured":"Kim, Y.: Convolutional neural networks for sentence classification. In: Proceedings of the 2014 conference on empirical methods in natural language processing (EMNLP). Association for Computational Linguistics, Doha, Qatar, pp 1746\u20131751. (2014). https:\/\/doi.org\/10.3115\/v1\/D14-1181","DOI":"10.3115\/v1\/D14-1181"},{"key":"8946_CR43","doi-asserted-by":"publisher","unstructured":"Conneau A, Kiela D, Schwenk H, Barrault L, Bordes A (2017) Supervised learning of universal sentence representations from natural language inference data. In: Proceedings of the 2017 conference on empirical methods in natural language processing. Association for Computational Linguistics, Copenhagen, Denmark, pp 670\u2013680 (2017). https:\/\/doi.org\/10.18653\/v1\/D17-1070","DOI":"10.18653\/v1\/D17-1070"},{"key":"8946_CR44","doi-asserted-by":"publisher","unstructured":"Zhou P, Shi W, Tian J, Qi Z, Li B, Hao H, Xu B (2016) Attention-based bidirectional long short-term memory networks for relation classification. In: Proceedings of the 54th annual meeting of the association for computational linguistics (volume 2: short papers). Association for Computational Linguistics, Berlin, Germany, pp 207\u2013212. https:\/\/doi.org\/10.18653\/v1\/P16-2034","DOI":"10.18653\/v1\/P16-2034"},{"key":"8946_CR45","unstructured":"Kingma DP, Ba J (2015) Adam: A method for stochastic optimization. In: Bengio Y, LeCun Y (eds) 3rd International conference on learning representations, ICLR 2015, San Diego, CA, USA, May 7\u20139, 2015, conference track proceedings, pp 1\u201315. arXiv:1412.6980"},{"key":"8946_CR46","unstructured":"Reddi SJ, Kale S, Kumar S (2018) On the convergence of Adam and beyond. In: 6th International conference on learning representations, ICLR 2018, Vancouver, BC, Canada, April 30\u2013May 3, 2018, conference track proceedings. OpenReview.net, Vancouver, BC, pp 1\u201323. https:\/\/openreview.net\/forum?id=ryQu7f-RZ"},{"key":"8946_CR47","doi-asserted-by":"publisher","unstructured":"Ren S, Deng Y, He K, Che W (2019) Generating natural language adversarial examples through probability weighted word saliency. In: Proceedings of the 57th annual meeting of the association for computational linguistics. Association for Computational Linguistics, Florence, Italy, pp 1085\u20131097. https:\/\/doi.org\/10.18653\/v1\/P19-1103","DOI":"10.18653\/v1\/P19-1103"},{"key":"8946_CR48","doi-asserted-by":"publisher","unstructured":"Zang Y, Qi F, Yang C, Liu Z, Zhang M, Liu Q, Sun M (2020) Word-level textual adversarial attacking as combinatorial optimization. In: Proceedings of the 58th annual meeting of the association for computational linguistics. Association for Computational Linguistics, pp 6066\u20136080. https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.540","DOI":"10.18653\/v1\/2020.acl-main.540"},{"key":"8946_CR49","doi-asserted-by":"crossref","unstructured":"Maheshwary R, Maheshwary S, Pudi V (2021) Generating natural language attacks in a hard label black box setting. In: Thirty-fifth AAAI conference on artificial intelligence, AAAI 2021, thirty-third conference on innovative applications of artificial intelligence, IAAI 2021, the eleventh symposium on educational advances in artificial intelligence, EAAI 2021, virtual event, February 2\u20139, 2021. AAAI Press, Virtual Event, pp 13525\u201313533. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/17595","DOI":"10.1609\/aaai.v35i15.17595"},{"key":"8946_CR50","unstructured":"Dong X, Luu AT, Ji R, Liu H (2021) Towards robustness against natural language word substitutions. In: 9th International conference on learning representations, ICLR 2021, Virtual Event, Austria, May 3\u20137, 2021. pp 1\u201314 (2021). https:\/\/openreview.net\/forum?id=ks5nebunVn_"},{"key":"8946_CR51","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel P, Goodfellow I, Jha S, Celik ZB, Swami A (2017) Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia conference on computer and communications security. ASIA CCS \u201917. Association for Computing Machinery, New York, NY, USA, pp 506\u2013519. https:\/\/doi.org\/10.1145\/3052973.3053009","DOI":"10.1145\/3052973.3053009"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-023-08946-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-023-08946-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-023-08946-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,4]],"date-time":"2024-01-04T17:10:44Z","timestamp":1704388244000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-023-08946-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,2]]},"references-count":51,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,1]]}},"alternative-id":["8946"],"URL":"https:\/\/doi.org\/10.1007\/s00521-023-08946-7","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,2]]},"assertion":[{"value":"13 October 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 August 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 November 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}