{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T14:12:10Z","timestamp":1774879930920,"version":"3.50.1"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Speech Technol"],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1007\/s10772-025-10237-6","type":"journal-article","created":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T15:39:27Z","timestamp":1764603567000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Robustness of AraBERT models to black-box adversarial deletions and perturbations"],"prefix":"10.1007","volume":"29","author":[{"given":"Malik","family":"Qasaimeh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saja","family":"Nakhleh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Raad","family":"Al-Qassas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ammar","family":"Abdallah","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muneer Bani","family":"Yasin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,12,1]]},"reference":[{"key":"10237_CR1","unstructured":"Albilali, E., Altwairesh, N., & Hosny, M. (2021). What does BERT Learn from arabic machine reading comprehension datasets? In Proceedings of the sixth Arabic natural language processing workshop (pp. 32\u201341) Kyiv, Ukraine (Virtual)."},{"key":"10237_CR2","doi-asserted-by":"publisher","unstructured":"Alshahrani, N. M., Alshahrani, S., Wali, E., & Matthews, J. (2024). Arabic synonym BERT-based adversarial examples for text classification. In 18th conference of the European chapter of the association for computational linguistics (Student research workshop), March 17\u201322, 2024. https:\/\/doi.org\/10.48550\/arXiv.2402.03477","DOI":"10.48550\/arXiv.2402.03477"},{"key":"10237_CR4","doi-asserted-by":"publisher","unstructured":"Alshalan, H., & Rekabdar, B. (2023). Attacking a transformer-based models for arabic language as low resources language (LRL) using word-substitution methods. In 2023 fifth international conference on transdisciplinary AI (TransAI) (pp. 95\u2013101). Laguna Hills, CA, USA. https:\/\/doi.org\/10.1109\/TransAI60598.2023.00025","DOI":"10.1109\/TransAI60598.2023.00025"},{"key":"10237_CR41","doi-asserted-by":"crossref","unstructured":"Alshemali, B., & Kalita, J. (2019). Adversarial examples in Arabic in 2019. In 2019 International conference on computational science and computational intelligence (CSCI) (pp. 371\u2013376). Las Vegas, NV, USA.","DOI":"10.1109\/CSCI49370.2019.00072"},{"key":"10237_CR5","doi-asserted-by":"publisher","unstructured":"Alshemali, B., & Kalita, J. (2021). Character-level adversarial examples in Arabic. In 20th IEEE international conference on machine learning and applications (ICMLA (pp. 9\u201314). Pasadena, CA, USA. https:\/\/doi.org\/10.1109\/ICMLA52953.2021.00010","DOI":"10.1109\/ICMLA52953.2021.00010"},{"key":"10237_CR7","unstructured":"Aly, M., & Atiya, A. (2013) LABR: A large scale Arabic book reviews dataset. In Proceedings of the 51st annual Meeting of the Association of Computational Linguistics (Vol. 2: Short)."},{"key":"10237_CR8","doi-asserted-by":"crossref","unstructured":"Amayuelas, A., Yang, X., Antoniades, A., Hua, W., Pan, L., & Wang, W. Y. (2024). MultiAgent collaboration attack: Investigating adversarial attacks in large language model collaborations via debate. In Conference on empirical methods in natural Language processing.","DOI":"10.18653\/v1\/2024.findings-emnlp.407"},{"key":"10237_CR9","doi-asserted-by":"publisher","first-page":"3911","DOI":"10.3390\/app13063911","volume":"13","author":"Z. H. Amur","year":"2023","unstructured":"Amur, Z. H., Kwang Hooi, Y., Bhanbhro, H., Dahri, K., & Soomro, G. M. (2023). Short-text semantic similarity (STSS): Techniques, challenges and future perspectives. Applied Sciences, 13, 3911. https:\/\/doi.org\/10.3390\/app13063911","journal-title":"Appl Sci"},{"key":"10237_CR10","unstructured":"Antoun, W., Baly, F., & Hajj, H. (2020). AraBERT: Transformer-based model for Arabic language understanding."},{"key":"10237_CR11","doi-asserted-by":"publisher","first-page":"17507","DOI":"10.1007\/s00521-022-07403-1","volume":"34","author":"F. Colasanto","year":"2022","unstructured":"Colasanto, F., Grilli, L., Santoro, D., & Villani, G. (2022). BERT\u2019s sentiment score for portfolio optimization: A fine-tuned view in black and Litterman model. Neural Computing & Applications, 34, 17507\u201317521. https:\/\/doi.org\/10.1007\/s00521-022-07403-1","journal-title":"Neural Comput &amp; Applic"},{"key":"10237_CR13","unstructured":"Fawzy, M. (n.d.). BERT-LABR unbalanced. [Online]. Available: https:\/\/huggingface.co\/mofawzy\/bert-labr-unbalanced"},{"key":"10237_CR14","doi-asserted-by":"crossref","unstructured":"Gao, J., Lanchantin, J., Soffa, M. L., & Qi, Y. (2018a). Black-box generation of adversarial text sequences to evade deep learning classifiers. In 2018 IEEE security and privacy workshops (SPW) (pp. 50\u201356). San Francisco, CA, USA.","DOI":"10.1109\/SPW.2018.00016"},{"key":"10237_CR15","doi-asserted-by":"crossref","unstructured":"Gao, J., Lanchantin, J., Soffa, M. L., & Qi, Y. (2018b). DeepWordBug: Black-box generation of adversarial text sequences. arXiv preprint arXiv:1801.04354.","DOI":"10.1109\/SPW.2018.00016"},{"key":"10237_CR16","doi-asserted-by":"crossref","unstructured":"Jin, D., Jin, Z., Zhou, J., & Szolovits, P. (2020). Is BERT really robust? A strong baseline for natural language attack on text classification and entailment. AAAI.","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"10237_CR17","doi-asserted-by":"publisher","unstructured":"Khaddaj, A., Hajj, H., & El-Hajj, W. (2019). Improved generalization of Arabic text classifiers. In Proceedings of the fourth Arabic natural language processing workshop (pp. 167\u2013174). Florence, Italy. Association for Computational Linguistics. [Online]. Available: https:\/\/aclanthology.org\/W19-4618\/https:\/\/doi.org\/10.18653\/v1\/W19-4618.","DOI":"10.18653\/v1\/W19-4618"},{"key":"10237_CR18","doi-asserted-by":"publisher","first-page":"14603","DOI":"10.1007\/s00521-021-06100-9","volume":"33","author":"J. A. Kumar","year":"2021","unstructured":"Kumar, J. A., & Abirami, S. (2021). Ensemble application of bidirectional LSTM and GRU for aspect category detection with imbalanced data. Neural Computing & Applications, 33, 14603\u201314621. https:\/\/doi.org\/10.1007\/s00521-021-06100-9","journal-title":"Neural Comput &amp; Applic"},{"key":"10237_CR19","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2009.07502","author":"D. Li","year":"2021","unstructured":"Li, D., Zhang, Y., Peng, H., Chen, L., Brockett, C., Sun, M.-T., & Dolan, B. (2021). Contextualized perturbation for textual adversarial attack. NAACL 2021. https:\/\/doi.org\/10.48550\/arXiv.2009.07502","journal-title":"NAACL 2021"},{"key":"10237_CR20","doi-asserted-by":"crossref","unstructured":"Li, J., Ji, S., Du, T., Li, B., & Wang, T. (2019). TextBugger: Generating adversarial text against real-world applications. NDSS Symposium.","DOI":"10.14722\/ndss.2019.23138"},{"key":"10237_CR21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23138","volume-title":"TextBugger: Generating adversarial text against real-world applications","author":"J. Li","year":"2018","unstructured":"Li, J., Ji, S., Du, T., Li, B., & Wang, T. (2018). TextBugger: Generating adversarial text against real-world applications. https:\/\/doi.org\/10.14722\/ndss.2019.23138"},{"key":"10237_CR42","doi-asserted-by":"crossref","unstructured":"Li, L., Ma, R., Guo, Q., Xue, X., & Qiu, X. (2020). BERT-ATTACK: Adversarial attack against in BERT using BERT. In Proceedings of the 2020 conference on empirical methods in natural language processing (EMNLP) (pp. 6193\u20136202). Online.","DOI":"10.18653\/v1\/2020.emnlp-main.500"},{"key":"10237_CR23","first-page":"1","volume":"55","author":"P. Liu","year":"2021","unstructured":"Liu, P., Yuan, W., Fu, J., Jiang, Z., Hayashi, H., & Neubig, G. (2021). Pre-train, prompt, and predict: A systematic survey of prompting methods in natural language processing. ACM Computing Surveys, 55, 1\u201335.","journal-title":"ACM Computing Surveys"},{"key":"10237_CR24","volume-title":"The impact of large language models in finance: Towards trustworthy adoption","author":"C. Maple","year":"2024","unstructured":"Maple, C., & Sabuncuoglu, A. (2024). The impact of large language models in finance: Towards trustworthy adoption. The Alan Turing Institute."},{"key":"10237_CR25","doi-asserted-by":"publisher","unstructured":"Nakhleh, S., Qasaimeh, M., & Qasaimeh, A. (2024). Character-level adversarial attacks evaluation for AraBERT\u2019s. In 2024 15th international conference on information and communication systems (ICICS) (pp. 1\u20136). Irbid, Jordan. https:\/\/doi.org\/10.1109\/ICICS63486.2024.10638315","DOI":"10.1109\/ICICS63486.2024.10638315"},{"key":"10237_CR26","doi-asserted-by":"crossref","unstructured":"Papernot, N., Mcdaniel, P., Swami, A., & Harang, R. E. (2016). Crafting adversarial input sequences for recurrent neural networks. In MILCOM 2016 \u2013 2016 IEEE military communications conference (pp. 49\u201354).","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"10237_CR27","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1186\/s41239-024-00487-w","volume":"21","author":"M. Perkins","year":"2024","unstructured":"Perkins, M., Roe, J., & Vu, B. H., et al. (2024). Simple techniques to bypass GenAI text detectors: Implications for inclusive education. International Journal of Educational Technology in Higher Education, 21, 53. https:\/\/doi.org\/10.1186\/s41239-024-00487-w","journal-title":"International Journal of Educational Technology in Higher Education"},{"key":"10237_CR28","doi-asserted-by":"crossref","unstructured":"Pires, T., Schlinger, E., & Garrette, D. (2019). How multilingual is multilingual BERT? In Proceedings of the 57th annual meeting of the association for computational linguistics (pp. 4996\u20135001). Florence, Italy. Association for Computational Linguistics.","DOI":"10.18653\/v1\/P19-1493"},{"key":"10237_CR29","doi-asserted-by":"publisher","first-page":"31479","DOI":"10.1007\/s11042-024-20422-5","volume":"84","author":"M. Qasaimeh","year":"2025","unstructured":"Qasaimeh, M., Qtaish, A. A., & Aljawarneh, S. (2025). Robust steganographic approach using generative adversarial network and compressive autoencoder. Multimedia Tools and Applications, 84, 31479\u201331516. https:\/\/doi.org\/10.1007\/s11042-024-20422-5","journal-title":"Multimed Tools Appl"},{"key":"10237_CR30","doi-asserted-by":"crossref","unstructured":"Radman, A., & Duwairi, R. (2024). Towards a robust deep learning framework for Arabic sentiment analysis. Natural Language Processing, 1\u201335.","DOI":"10.1017\/nlp.2024.35"},{"key":"10237_CR31","unstructured":"Rosenthal, S., Bornea, M., & Sil, A. (2021). Are multilingual bert models robust? A case study on adversarial attacks for multilingual question answering."},{"key":"10237_CR32","unstructured":"Su, J. (2024) Enhancing adversarial attacks through chain of thought. arXiv preprint arXiv:2410.21791. [Online]. Available: https:\/\/arxiv.org\/abs\/2410.21791"},{"key":"10237_CR33","unstructured":"Touvron, H., Lavril, T., Izacard, G., Martinet, X., Lachaux, M.-A., Lacroix, T., Rozi\u00e8re, B., Goyal, N., Hambro, E., Azhar, F., Rodriguez, A., Joulin, A., Grave, E., & Lample, G. (2023). LLaMA: Open and efficient foundation language models. ArXiv abs\/2302.13971."},{"key":"10237_CR34","unstructured":"Turetken, C., & Leippold, M. (2024). Battle of transformers: Adversarial attacks on financial sentiment models. Swiss finance institute research paper No. 24-59. [Online]. Available: https:\/\/doi.org\/10.2139\/ssrn.4977483https:\/\/ssrn.com\/abstract=4977483"},{"key":"10237_CR35","unstructured":"Wang, X., Wei, J., Schuurmans, D., Le, Q., Chi, E. H., & Zhou, D. (2022). Self-consistency improves chain of thought reasoning in language models. arXiv, vol. abs\/2203.11171."},{"key":"10237_CR36","unstructured":"Wu, C., Koh, J. Y., Salakhutdinov, R., Fried, D., & Raghunathan, A. (2024) Adversarial attacks on multimodal agents. arXiv, abs\/2406.12814."},{"key":"10237_CR37","unstructured":"Yang, Y., Huang, P., Cao, J., Li, J., Lin, Y., Dong, J. S., Ma, F., & Zhang, J. (2022) A prompting-based approach for adversarial example generation and robustness enhancement. arXiv preprint arXiv:2203.10714. [Online]. Available: https:\/\/arxiv.org\/abs\/2203.10714"},{"issue":"1","key":"10237_CR38","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1038\/s41467-025-64062-1","volume":"16","author":"Y. Yang","year":"2025","unstructured":"Yang, Y., Jin, Q., Huang, F., & Lu, Z. (2025). Adversarial prompt and fine-tuning attacks threaten medical large language models. Nature Communications, 16(1), 1\u201310. https:\/\/doi.org\/10.1038\/s41467-025-64062-1","journal-title":"Nature Communications"},{"key":"10237_CR39","unstructured":"Yang, Y., Jin, Q., Huang, F., & Lu, Z. (2024) Adversarial attacks on large language models in medicine. arXiv preprint arXiv:2406.12259. [Online]. Available: https:\/\/arxiv.org\/abs\/2406.12259"},{"key":"10237_CR40","doi-asserted-by":"publisher","first-page":"205","DOI":"10.3389\/fpsyg.2020.02059","volume":"11","author":"R. Yassin","year":"2020","unstructured":"Yassin, R., Share, D. L., & Shalhoub-Awwad, Y. (2020). Learning to spell in Arabic: The impact of script-specific visual-orthographic features. Frontiers Psychology, 11, 205\u2013215.","journal-title":"Frontiers Psychol"}],"container-title":["International Journal of Speech Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10772-025-10237-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10772-025-10237-6","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10772-025-10237-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T13:22:10Z","timestamp":1774876930000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10772-025-10237-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,1]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["10237"],"URL":"https:\/\/doi.org\/10.1007\/s10772-025-10237-6","relation":{},"ISSN":["1381-2416","1572-8110"],"issn-type":[{"value":"1381-2416","type":"print"},{"value":"1572-8110","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,1]]},"assertion":[{"value":"26 January 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 November 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval"}},{"value":"The authors declare no competing interests.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Research involving human participants and\/or animals"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Informed consent"}},{"value":"Not applicable.","order":6,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent"}}],"article-number":"4"}}