{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T14:54:36Z","timestamp":1785336876847,"version":"3.55.0"},"reference-count":69,"publisher":"Springer Science and Business Media LLC","issue":"18","license":[{"start":{"date-parts":[[2025,4,23]],"date-time":"2025-04-23T00:00:00Z","timestamp":1745366400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,4,23]],"date-time":"2025-04-23T00:00:00Z","timestamp":1745366400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2025,6]]},"DOI":"10.1007\/s00521-025-11135-3","type":"journal-article","created":{"date-parts":[[2025,4,23]],"date-time":"2025-04-23T06:21:14Z","timestamp":1745389274000},"page":"12921-12939","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Integrated gradients-based defense against adversarial word substitution attacks"],"prefix":"10.1007","volume":"37","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0741-0710","authenticated-orcid":false,"given":"Murtadha","family":"Ahmed","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Wen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Luo","family":"Ao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunfeng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,23]]},"reference":[{"issue":"7","key":"11135_CR1","doi-asserted-by":"publisher","first-page":"5731","DOI":"10.1007\/s10462-022-10144-1","volume":"55","author":"M Wankhade","year":"2022","unstructured":"Wankhade M, Rao ACS, Kulkarni C (2022) A survey on sentiment analysis methods, applications, and challenges. Artif Intell Rev 55(7):5731\u20135780. https:\/\/doi.org\/10.1007\/s10462-022-10144-1","journal-title":"Artif Intell Rev"},{"key":"11135_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/J.ESWA.2024.125195","volume":"258","author":"A Murtadha","year":"2024","unstructured":"Murtadha A, Wen B, Pan S, Su J, Ao L, Liu Y (2024) BERT-ASC: auxiliary-sentence construction for implicit aspect learning in sentiment analysis. Expert Syst Appl 258:125195. https:\/\/doi.org\/10.1016\/J.ESWA.2024.125195","journal-title":"Expert Syst Appl"},{"key":"11135_CR3","doi-asserted-by":"publisher","first-page":"723","DOI":"10.1162\/TACL_A_00571","volume":"11","author":"Y Wang","year":"2023","unstructured":"Wang Y, Chen Q, Ahmed M, Chen Z, Su J, Pan W, Li Z (2023) Supervised gradual machine learning for aspect-term sentiment analysis. Trans Assoc Comput Linguistics 11:723\u2013739. https:\/\/doi.org\/10.1162\/TACL_A_00571","journal-title":"Trans Assoc Comput Linguistics"},{"key":"11135_CR4","doi-asserted-by":"publisher","unstructured":"Jia R, Liang P (2017) Adversarial examples for evaluating reading comprehension systems. In: Palmer, M., Hwa, R., Riedel, S. (eds.) Proceedings of the 2017 conference on empirical methods in natural language processing, EMNLP, pp. 2021\u20132031 https:\/\/doi.org\/10.18653\/v1\/d17-1215","DOI":"10.18653\/v1\/d17-1215"},{"key":"11135_CR5","doi-asserted-by":"publisher","unstructured":"Iyyer M, Wieting J, Gimpel K, Zettlemoyer L (2018) Adversarial example generation with syntactically controlled paraphrase networks. In: Walker, M.A., Ji, H., Stent, A. (eds.) Proceedings of the 2018 conference of the north american chapter of the association for computational linguistics: human language technologies, NAACL-HLT 2018, pp. 1875\u20131885 https:\/\/doi.org\/10.18653\/v1\/n18-1170","DOI":"10.18653\/v1\/n18-1170"},{"key":"11135_CR6","doi-asserted-by":"publisher","unstructured":"Ribeiro MT, Singh S, Guestrin C (2018) Semantically equivalent adversarial rules for debugging NLP models. In: Gurevych, I., Miyao, Y. (eds.) Proceedings of the 56th annual meeting of the association for computational linguistics, ACL, pp. 856\u2013865 https:\/\/doi.org\/10.18653\/v1\/P18-1079","DOI":"10.18653\/v1\/P18-1079"},{"key":"11135_CR7","doi-asserted-by":"publisher","unstructured":"Alzantot M, Sharma Y, Elgohary A, Ho B, Srivastava MB, Chang K (2018) Generating natural language adversarial examples. In: Riloff, E., Chiang, D., Hockenmaier, J., Tsujii, J. (eds.) Proceedings of the 2018 conference on empirical methods in natural language processing, EMNLP, pp. 2890\u20132896 https:\/\/doi.org\/10.18653\/v1\/d18-1316","DOI":"10.18653\/v1\/d18-1316"},{"key":"11135_CR8","unstructured":"Belinkov Y, Bisk Y (2018) Synthetic and natural noise both break neural machine translation. In: proceedings of 6th international conference on learning representations, ICLR 2018 https:\/\/openreview.net\/forum?id=BJ8vJebC-"},{"key":"11135_CR9","doi-asserted-by":"publisher","unstructured":"Ebrahimi J, Rao A, Lowd D, Dou D (2018) Hotflip: white-box adversarial examples for text classification. In: Gurevych, I., Miyao, Y. (eds.) Proceedings of the 56th annual meeting of the association for computational linguistics, ACL, pp. 31\u201336 https:\/\/doi.org\/10.18653\/v1\/P18-2006","DOI":"10.18653\/v1\/P18-2006"},{"key":"11135_CR10","doi-asserted-by":"publisher","unstructured":"Gao J, Lanchantin J, Soffa ML, Qi Y (2018) Black-Box generation of adversarial text sequences to evade deep learning classifiers. In: 2018 IEEE security and privacy workshops (SPW), pp. 50\u201356 https:\/\/doi.org\/10.1109\/SPW.2018.00016","DOI":"10.1109\/SPW.2018.00016"},{"key":"11135_CR11","doi-asserted-by":"publisher","unstructured":"Ren S, Deng Y, He K, Che W (2019) Generating natural language adversarial examples through probability weighted word saliency. In: Proceedings of the 57th annual meeting of the association for computational linguistics, ACL, Florence, Italy, pp. 1085\u20131097 https:\/\/doi.org\/10.18653\/v1\/P19-1103","DOI":"10.18653\/v1\/P19-1103"},{"key":"11135_CR12","doi-asserted-by":"crossref","unstructured":"Jin D, Jin Z, Zhou JT, Szolovits P (2020) Is bert really robust? A strong baseline for natural language attack on text classification and entailment. In: proceedings of the the thirty-fourth conference on artificial intelligence, AAAI, the thirty-second innovative applications of artificial intelligence conference, IAAI, the tenth symposium on educational advances in artificial intelligence, EAAI, pp. 8018\u20138025 https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/6311","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"11135_CR13","doi-asserted-by":"publisher","unstructured":"Zheng X, Zeng J, Zhou Y, Hsieh C-J, Cheng M, Huang X (2020) Evaluating and enhancing the robustness of neural network-based dependency parsing models with adversarial examples. In: proceedings of the 58th annual meeting of the association for computational linguistics, online, pp. 6600\u20136610 https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.590","DOI":"10.18653\/v1\/2020.acl-main.590"},{"key":"11135_CR14","doi-asserted-by":"publisher","unstructured":"Li L, Ma R, Guo Q, Xue X, Qiu X (2020) BERT-ATTACK: Adversarial attack against BERT using BERT. In: proceedings of the 2020 conference on empirical methods in natural language processing, EMNLP, Online, pp. 6193\u20136202 https:\/\/doi.org\/10.18653\/v1\/2020.emnlp-main.500","DOI":"10.18653\/v1\/2020.emnlp-main.500"},{"key":"11135_CR15","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1162\/tacl_a_00254","volume":"7","author":"Y Belinkov","year":"2019","unstructured":"Belinkov Y, Glass J (2019) Analysis methods in neural language processing: a survey. Trans Assoc Comput Linguistics 7:49\u201372. https:\/\/doi.org\/10.1162\/tacl_a_00254","journal-title":"Trans Assoc Comput Linguistics"},{"key":"11135_CR16","doi-asserted-by":"publisher","unstructured":"Devlin J, Chang M, Lee K, Toutanova K (2019) BERT: pre-training of deep bidirectional transformers for language understanding. In: Burstein, J., Doran, C., Solorio, T. (eds.) Proceedings of the 2019 conference of the north american chapter of the association for computational linguistics: human language technologies, NAACL-HLT, pp. 4171\u20134186 https:\/\/doi.org\/10.18653\/v1\/n19-1423","DOI":"10.18653\/v1\/n19-1423"},{"key":"11135_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.105210","volume":"191","author":"B Alshemali","year":"2020","unstructured":"Alshemali B, Kalita J (2020) Improving the reliability of deep neural networks in NLP: a review. Knowledge-Based Sys 191:105210. https:\/\/doi.org\/10.1016\/j.knosys.2019.105210","journal-title":"Knowledge-Based Sys"},{"key":"11135_CR18","doi-asserted-by":"publisher","unstructured":"Jia R, Raghunathan A, G\u00f6ksel K, Liang P (2019) Certified robustness to adversarial word substitutions. In: Inui, K., Jiang, J., Ng, V., Wan, X. (eds.) Proceedings of the 2019 conference on empirical methods in natural language processing and the 9th international joint conference on natural language processing, EMNLP-IJCNLP 2019, pp. 4127\u20134140 https:\/\/doi.org\/10.18653\/v1\/D19-1423","DOI":"10.18653\/v1\/D19-1423"},{"key":"11135_CR19","doi-asserted-by":"publisher","unstructured":"Ye M, Gong C, Liu Q (2020) SAFER: a structure-free approach for certified robustness to adversarial word substitutions. In: proceedings of the 58th annual meeting of the association for computational linguistics, ACL, Online, pp. 3465\u20133475. https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.317","DOI":"10.18653\/v1\/2020.acl-main.317"},{"key":"11135_CR20","unstructured":"Dong X, Luu AT, Ji R, Liu H (2021) Towards Robustness against natural language word substitutions. In: proceedings of the 9th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=ks5nebunVn_"},{"key":"11135_CR21","unstructured":"Zeng J, Zheng X, Xu J, Li L, Yuan L, Huang X (2021) Certified robustness to text adversarial attacks by randomized [MASK]. CoRR abs\/2105.03743. https:\/\/arxiv.org\/abs\/2105.03743"},{"key":"11135_CR22","doi-asserted-by":"publisher","unstructured":"Li Z, Xu J, Zeng J, Li L, Zheng X, Zhang Q, Chang K, Hsieh C (2021) Searching for an effective defender: benchmarking defense against adversarial word substitution. In: Moens, M., Huang, X., Specia, L., Yih, S.W. (eds.) Proceedings of the 2021 conference on empirical methods in natural language processing, EMNLP, pp. 3137\u20133147 https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.251","DOI":"10.18653\/v1\/2021.emnlp-main.251"},{"key":"11135_CR23","doi-asserted-by":"crossref","unstructured":"Minh DN, Luu AT (2022) Textual manifold-based defense against natural language adversarial examples. In: Goldberg, Y., Kozareva, Z., Zhang, Y. (eds.) Proceedings of the 2022 conference on empirical methods in natural language processing, EMNLP, pp. 6612\u20136625. https:\/\/aclanthology.org\/2022.emnlp-main.443","DOI":"10.18653\/v1\/2022.emnlp-main.443"},{"key":"11135_CR24","unstructured":"Zhu C, Cheng Y, Gan Z, Sun S, Goldstein T, Liu J (2020) FreeLB: enhanced adversarial training for natural language understanding. In: proceedings of the 8th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=BygzbyHFvB"},{"key":"11135_CR25","unstructured":"Wang B, Wang S, Cheng Y, Gan Z, Jia R, Li B, Liu J (2021) Infobert: improving robustness of language models from an information theoretic perspective. In: 9th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=hpH98mK5Puk"},{"key":"11135_CR26","doi-asserted-by":"crossref","unstructured":"Li L, Qiu X (2021) TAVAT:token-aware virtual adversarial training in natural language understanding. In: 35th AAAI conference on artificial intelligence, AAAI 2021, 33rd conference on innovative applications of artificial intelligence, IAAI, the 11th symposium on educational advances in artificial intelligence, EAAI, pp. 8410\u20138418 https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/17022","DOI":"10.1609\/aaai.v35i9.17022"},{"key":"11135_CR27","unstructured":"Sundararajan M, Taly A, Yan Q (2017) Axiomatic attribution for deep networks. In: Precup, D., Teh, Y.W. (eds.) Proceedings of the 34th international conference on machine learning, ICML 2017. Proceedings of machine learning research, vol. 70, pp. 3319\u20133328 http:\/\/proceedings.mlr.press\/v70\/sundararajan17a.html"},{"key":"11135_CR28","doi-asserted-by":"publisher","unstructured":"Li C, Li X, Ouyang J (2021) Semi-supervised text classification with balanced deep representation distributions. In: Zong, C., Xia, F., Li, W., Navigli, R. (eds.) proceedings of the 59th annual meeting of the association for computational linguistics and the 11th international joint conference on natural language processing, ACL\/IJCNLP, pp. 5044\u20135053 https:\/\/doi.org\/10.18653\/v1\/2021.acl-long.391","DOI":"10.18653\/v1\/2021.acl-long.391"},{"key":"11135_CR29","unstructured":"Ahmed M, Pan S, Bo W, Su J, Cao X, Zhang W, Liu Y (2023) Rank-aware negative training for semi-supervised text classification. Transactions of the association for computational linguistics, TACL"},{"key":"11135_CR30","unstructured":"Ganin Y, Lempitsky VS (2015) Unsupervised domain adaptation by backpropagation. In: Bach, F.R., Blei, D.M. (eds.) Proceedings of the 32nd international conference on machine learning, ICML 2015. JMLR workshop and conference proceedings, vol. 37, pp. 1180\u20131189 http:\/\/proceedings.mlr.press\/v37\/ganin15.html"},{"key":"11135_CR31","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, Fergus R (2014) Intriguing properties of neural networks. In: Bengio, Y., LeCun, Y. (eds.) Proceedings of Teh 2nd international conference on learning representations, ICLR. http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"11135_CR32","unstructured":"Zhao Z, Dua D, Singh S (2018) Generating natural adversarial examples. In: proceedings of 6th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=H1BLjgZCb"},{"key":"11135_CR33","doi-asserted-by":"crossref","unstructured":"Cheng M, Yi J, Chen P, Zhang H, Hsieh C (2020) Seq2Sick: evaluating the robustness of sequence-to-sequence models with adversarial examples. In: proceedings of the The 34th conference on artificial intelligence, AAAI 2020, pp. 3601\u20133608 https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/5767","DOI":"10.1609\/aaai.v34i04.5767"},{"key":"11135_CR34","doi-asserted-by":"publisher","unstructured":"Cheng M, Wei W, Hsieh C (2019) Evaluating and enhancing the robustness of dialogue systems: a case study on a negotiation agent. In: Burstein, J., Doran, C., Solorio, T. (eds.) Proceedings of the 2019 conference of the north american chapter of the association for computational linguistics: human language technologies, NAACL-HLT, pp. 3325\u20133335 https:\/\/doi.org\/10.18653\/v1\/n19-1336","DOI":"10.18653\/v1\/n19-1336"},{"key":"11135_CR35","doi-asserted-by":"publisher","unstructured":"Liang B, Li H, Su M, Bian P, Li X, Shi W (2018) Deep text classification can be fooled. In: Lang, J. (ed.) Proceedings of the 27th international joint conference on artificial intelligence, IJCAI, pp. 4208\u20134215 https:\/\/doi.org\/10.24963\/ijcai.2018\/585","DOI":"10.24963\/ijcai.2018\/585"},{"key":"11135_CR36","doi-asserted-by":"crossref","unstructured":"Li J, Ji S, Du T, Li B, Wang T (2019) TextBugger: generating adversarial text against real-world applications. In: proceedings of the 26th annual network and distributed system security symposium, NDSS. https:\/\/www.ndss-symposium.org\/ndss-paper\/textbugger-generating-adversarial-text-against-real-world-applications\/","DOI":"10.14722\/ndss.2019.23138"},{"issue":"11","key":"11135_CR37","doi-asserted-by":"publisher","first-page":"4835","DOI":"10.1109\/TCYB.2019.2914099","volume":"50","author":"H Li","year":"2020","unstructured":"Li H, Li G, Yu Y (2020) ROSA: robust salient object detection against adversarial attacks. IEEE Trans Cybern 50(11):4835\u20134847. https:\/\/doi.org\/10.1109\/TCYB.2019.2914099","journal-title":"IEEE Trans Cybern"},{"issue":"4","key":"11135_CR38","doi-asserted-by":"publisher","first-page":"1473","DOI":"10.1109\/TCYB.2018.2882908","volume":"50","author":"E Yang","year":"2020","unstructured":"Yang E, Liu T, Deng C, Tao D (2020) Adversarial examples for hamming space search. IEEE Trans Cybern 50(4):1473\u20131484. https:\/\/doi.org\/10.1109\/TCYB.2018.2882908","journal-title":"IEEE Trans Cybern"},{"issue":"8","key":"11135_CR39","doi-asserted-by":"publisher","first-page":"5323","DOI":"10.1109\/TCYB.2022.3209175","volume":"53","author":"Z Wang","year":"2023","unstructured":"Wang Z, Shu X, Wang Y, Feng Y, Zhang L, Yi Z (2023) A feature space-restricted attention attack on medical deep learning systems. IEEE Trans Cybern 53(8):5323\u20135335. https:\/\/doi.org\/10.1109\/TCYB.2022.3209175","journal-title":"IEEE Trans Cybern"},{"key":"11135_CR40","doi-asserted-by":"publisher","unstructured":"Li J, Monroe W, Shi T, Jean S, Ritter A, Jurafsky D (2017) Adversarial learning for neural dialogue generation. In: Palmer, M., Hwa, R., Riedel, S. (eds.) Proceedings of the 2017 conference on empirical methods in natural language processing, pp. 2157\u20132169. Association for computational linguistics, Copenhagen, Denmark. https:\/\/doi.org\/10.18653\/v1\/D17-1230","DOI":"10.18653\/v1\/D17-1230"},{"key":"11135_CR41","unstructured":"Mikolov T, Yih W, Zweig G (2013) Linguistic regularities in continuous space word representations. In: Vanderwende, L., III, H.D., Kirchhoff, K. (eds.) Proceedings of human language technologies: conference of the North American chapter of the association of computational linguistics, NAACL, pp. 746\u2013751 https:\/\/aclanthology.org\/N13-1090\/"},{"key":"11135_CR42","doi-asserted-by":"publisher","unstructured":"Pennington J, Socher R, Manning CD (2014) Glove: global vectors for word representation. In: Moschitti, A., Pang, B., Daelemans, W. (eds.) Proceedings of the 2014 conference on empirical methods in natural language processing, EMNLP, pp. 1532\u20131543 https:\/\/doi.org\/10.3115\/v1\/d14-1162","DOI":"10.3115\/v1\/d14-1162"},{"key":"11135_CR43","doi-asserted-by":"publisher","unstructured":"Zang Y, Qi F, Yang C, Liu Z, Zhang M, Liu Q, Sun M (2020) Word-level textual adversarial attacking as combinatorial optimization. In: Jurafsky, D., Chai, J., Schluter, N., Tetreault, J.R. (eds.) Proceedings of the 58th annual meeting of the association for computational linguistics, ACL, pp. 6066\u20136080 https:\/\/doi.org\/10.18653\/v1\/2020.acl-main.540","DOI":"10.18653\/v1\/2020.acl-main.540"},{"key":"11135_CR44","unstructured":"Samanta S, Mehta S (2017) Towards crafting text adversarial samples https:\/\/arxiv.org\/abs\/1707.028121707:02812"},{"key":"11135_CR45","unstructured":"Yang P, Chen J, Hsieh C, Wang J, Jordan MI (2020) Greedy attack and gumbel attack: generating adversarial examples for discrete data. J Mach Learn Respresent 21 https:\/\/arxiv.org\/abs\/1805.12316"},{"key":"11135_CR46","doi-asserted-by":"publisher","unstructured":"Hsieh Y, Cheng M, Juan D, Wei W, Hsu W, Hsieh C (2019) On the robustness of self-attentive models. In: Korhonen, A., Traum, D.R., M\u00e0rquez, L. (eds.) Proceedings of the 57th conference of the association for computational linguistics, ACL 2019, Florence, Italy, July 28, August 2, Volume 1: long papers, pp. 1520\u20131529 https:\/\/doi.org\/10.18653\/v1\/p19-1147","DOI":"10.18653\/v1\/p19-1147"},{"key":"11135_CR47","unstructured":"Lei Q, Wu L, Chen P, Dimakis A, Dhillon IS, Witbrock MJ (2019) Discrete adversarial attacks and submodular optimization with applications to text classification. In: Talwalkar, A., Smith, V., Zaharia, M. (eds.) Proceedings of machine learning and systems 2019, MLSys, Stanford, CA, USA, March 31\u2013April 2 https:\/\/proceedings.mlsys.org\/book\/284.pdf"},{"key":"11135_CR48","doi-asserted-by":"publisher","unstructured":"Wallace E, Feng S, Kandpal N, Gardner M, Singh S (2019) Universal adversarial triggers for attacking and analyzing NLP. In: Inui, K, Jiang, J, Ng, V, Wan, X. (eds.) Proceedings of the 2019 conference on empirical methods in natural language processing and the 9th international joint conference on natural language processing, EMNLP-IJCNLP 2019, Hong Kong, China, November 3\u20137, pp. 2153\u20132162 https:\/\/doi.org\/10.18653\/v1\/D19-1221","DOI":"10.18653\/v1\/D19-1221"},{"key":"11135_CR49","unstructured":"Barham S, Feizi S (2019) Interpretable adversarial training for text. CoRR abs\/1905.12864https:\/\/arxiv.org\/abs\/1905.12864"},{"issue":"9","key":"11135_CR50","doi-asserted-by":"publisher","first-page":"8729","DOI":"10.1109\/TKDE.2022.3207915","volume":"35","author":"Z Zhang","year":"2023","unstructured":"Zhang Z, Liu Q, Huang Z, Wang H, Lee C-K, Chen E (2023) Model inversion attacks against graph neural networks. IEEE Trans Knowledge Data Eng, (TKDE) 35(9):8729\u20138741. https:\/\/doi.org\/10.1109\/TKDE.2022.3207915","journal-title":"IEEE Trans Knowledge Data Eng, (TKDE)"},{"key":"11135_CR51","unstructured":"Gowal S, Dvijotham K, Stanforth R, Bunel R, Qin C, Uesato J, Arandjelovic R, Mann TA, Kohli P (2018) On the effectiveness of interval bound propagation for training verifiably robust models. CoRR abs\/1810.12715 https:\/\/arxiv.org\/abs\/1810.12715"},{"key":"11135_CR52","unstructured":"Dvijotham K, Gowal S, Stanforth R, Arandjelovic R, O\u2019Donoghue B, Uesato J, Kohli P (2018) Training verified learners with learned verifiers. CoRR abs\/1805.10265 https:\/\/arxiv.org\/abs\/1805.10265"},{"key":"11135_CR53","doi-asserted-by":"publisher","unstructured":"Huang P, Stanforth R, Welbl J, Dyer C, Yogatama D, Gowal S, Dvijotham K, Kohli P (2019) Achieving verified robustness to symbol substitutions via interval bound propagation. In: Inui, K., Jiang, J., Ng, V., Wan, X. (eds.) Proceedings of the 2019 conference on empirical methods in natural language processing and the 9th international joint conference on natural language processing, EMNLP-IJCNLP, pp. 4081\u20134091 https:\/\/doi.org\/10.18653\/v1\/D19-1419","DOI":"10.18653\/v1\/D19-1419"},{"key":"11135_CR54","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107102","volume":"226","author":"K Ding","year":"2021","unstructured":"Ding K, Liu X, Niu W, Hu T, Wang Y, Zhang X (2021) A low-query black-box adversarial attack based on transferability. Knowledge-Based Syst 226:107102. https:\/\/doi.org\/10.1016\/j.knosys.2021.107102","journal-title":"Knowledge-Based Syst"},{"key":"11135_CR55","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.106967","volume":"221","author":"Y Hu","year":"2021","unstructured":"Hu Y, Sun S (2021) RL-VAEGAN: adversarial defense for reinforcement learning agents via style transfer. Knowledge-Based Syst 221:106967. https:\/\/doi.org\/10.1016\/j.knosys.2021.106967","journal-title":"Knowledge-Based Syst"},{"key":"11135_CR56","unstructured":"Tjeng V, Xiao KY, Tedrake R (2019) Evaluating robustness of neural networks with mixed integer programming. In: Proceedings of the 7th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=HyGIdiRqtm"},{"key":"11135_CR57","doi-asserted-by":"publisher","unstructured":"Ren S, Deng Y, He K, Che W (2019) Generating natural language adversarial examples through probability weighted word saliency. In: Korhonen, A., Traum, D.R., M\u00e0rquez, L. (eds.) Proceedings of the 57th conference of the association for computational linguistics, ACL, pp. 1085\u20131097 https:\/\/doi.org\/10.18653\/v1\/p19-1103","DOI":"10.18653\/v1\/p19-1103"},{"key":"11135_CR58","doi-asserted-by":"publisher","unstructured":"Zhou Y, Zheng X, Hsieh C, Chang K, Huang X (2021) Defense against synonym substitution-based adversarial attacks via dirichlet neighborhood ensemble. In: Zong, C., Xia, F., Li, W., Navigli, R. (eds.) Proceedings of the 59th annual meeting of the association for computational linguistics and the 11th international joint conference on natural language processing, ACL\/IJCNLP 2021, (Volume 1: Long Papers), virtual event, August 1\u20136, pp. 5482\u20135492. Association for computational linguistics. https:\/\/doi.org\/10.18653\/V1\/2021.ACL-LONG.426","DOI":"10.18653\/V1\/2021.ACL-LONG.426"},{"key":"11135_CR59","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: proceedings of the 6th international conference on learning representations, ICLR. https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"issue":"2","key":"11135_CR60","doi-asserted-by":"publisher","first-page":"1073","DOI":"10.1007\/s11063-017-9762-8","volume":"48","author":"J Su","year":"2018","unstructured":"Su J, Song Z, Lu Y, Xu M, Wu C, Chen Y (2018) Exploring implicit semantic constraints for bilingual word embeddings. Neural Process Lett 48(2):1073\u20131088. https:\/\/doi.org\/10.1007\/s11063-017-9762-8","journal-title":"Neural Process Lett"},{"key":"11135_CR61","doi-asserted-by":"publisher","unstructured":"Wang H, Wang Y, Zhou Z, Ji X, Gong D, Zhou J, Li Z, Liu W (2018) CosFace: large margin cosine loss for deep face recognition. In: 2018 IEEE conference on computer vision and pattern recognition, CVPR 2018, Salt Lake City, UT, USA, June 18\u201322, pp. 5265\u20135274. https:\/\/doi.org\/10.1109\/CVPR.2018.00552. http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Wang_CosFace_Large_Margin_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00552"},{"key":"11135_CR62","doi-asserted-by":"publisher","unstructured":"Kasai J, Qian K, Gurajada S, Li Y, Popa L (2019) Low-resource deep entity resolution with transfer and active learning. In: Korhonen, A., Traum, D.R., M\u00e0rquez, L. (eds.) Proceedings of the 57th conference of the association for computational linguistics, ACL 2019, pp. 5851\u20135861 https:\/\/doi.org\/10.18653\/v1\/p19-1586","DOI":"10.18653\/v1\/p19-1586"},{"key":"11135_CR63","unstructured":"Zhang X, Zhao JJ, LeCun Y (2015) Character-level convolutional networks for text classification. In: proceedings of the annual conference on neural information processing systems, NeurPIS, pp. 649\u2013657 https:\/\/proceedings.neurips.cc\/paper\/2015\/hash\/250cf8b51c773f3f8dc8b4be867a9a02-Abstract.html"},{"key":"11135_CR64","unstructured":"Maas AL, Daly RE, Pham PT, Huang D, Ng AY, Potts C (2011) Learning word vectors for sentiment analysis. In: Lin, D., Matsumoto, Y., Mihalcea, R. (eds.) Proceedings of the The 49th annual meeting of the association for computational linguistics: human language technologies, pp. 142\u2013150 https:\/\/aclanthology.org\/P11-1015\/"},{"key":"11135_CR65","doi-asserted-by":"crossref","unstructured":"Socher R, Perelygin A, Wu J, Chuang J, Manning CD, Ng A, Potts C (2013) Recursive deep models for semantic compositionality over a sentiment treebank. In: Proceedings of the 2013 conference on empirical methods in natural language processing, Seattle, Washington, USA, pp. 1631\u20131642https:\/\/aclanthology.org\/D13-1170","DOI":"10.18653\/v1\/D13-1170"},{"key":"11135_CR66","doi-asserted-by":"publisher","unstructured":"Zhou Y, Zheng X, Hsieh C, Chang K, Huang X (2021) Defense against Synonym substitution-based adversarial attacks via dirichlet neighborhood ensemble. In: Zong, C., Xia, F., Li, W., Navigli, R. (eds.) Proceedings of the 59th annual meeting of the association for computational linguistics and the 11th international joint conference on natural language processing, ACL\/IJCNLP, pp. 5482\u20135492 https:\/\/doi.org\/10.18653\/v1\/2021.acl-long.426","DOI":"10.18653\/v1\/2021.acl-long.426"},{"key":"11135_CR67","unstructured":"Liu Y, Ott M, Goyal N, Du J, Joshi M, Chen D, Levy O, Lewis M, Zettlemoyer L, Stoyanov V (2019) RoBERTa: a robustly optimized BERT pretraining approach. CoRR abs\/1907.11692 https:\/\/arxiv.org\/abs\/1907.11692"},{"key":"11135_CR68","doi-asserted-by":"publisher","unstructured":"Morris J, Lifland E, Yoo JY, Grigsby J, Jin D, Qi Y (2020) TextAttack: a framework for adversarial attacks, data augmentation, and adversarial training in NLP. In: proceedings of the 2020 conference on empirical methods in natural language processing: system demonstrations, Online, pp. 119\u2013126https:\/\/doi.org\/10.18653\/v1\/2020.emnlp-demos.16","DOI":"10.18653\/v1\/2020.emnlp-demos.16"},{"key":"11135_CR69","doi-asserted-by":"publisher","unstructured":"Murtadha A, Chen Q, Wang Y, Nafa Y, Li Z, Duan T (2021) DNN-driven gradual machine learning for aspect-term sentiment analysis. In: Zong, C., Xia, F., Li, W., Navigli, R. (eds.) Findings of the association for computational linguistics: ACL\/IJCNLP 2021, Online Event, August 1\u20136, ACL, vol. ACL\/IJCNLP, pp. 488\u2013497 https:\/\/doi.org\/10.18653\/v1\/2021.findings-acl.43","DOI":"10.18653\/v1\/2021.findings-acl.43"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-025-11135-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-025-11135-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-025-11135-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T14:49:57Z","timestamp":1750171797000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-025-11135-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,23]]},"references-count":69,"journal-issue":{"issue":"18","published-print":{"date-parts":[[2025,6]]}},"alternative-id":["11135"],"URL":"https:\/\/doi.org\/10.1007\/s00521-025-11135-3","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,23]]},"assertion":[{"value":"23 March 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 February 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 April 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}