{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T09:00:52Z","timestamp":1784797252795,"version":"3.55.0"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T00:00:00Z","timestamp":1778198400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T00:00:00Z","timestamp":1778198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Mach. Intell. Res."],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1007\/s11633-025-1594-9","type":"journal-article","created":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T13:48:25Z","timestamp":1778248105000},"page":"903-915","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Reformulation is All You Need: Addressing Malicious Textual Features in DNNs"],"prefix":"10.1007","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-2677-4062","authenticated-orcid":false,"given":"Yi","family":"Jiang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6572-972X","authenticated-orcid":false,"given":"Oubo","family":"Ma","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3526-560X","authenticated-orcid":false,"given":"Yong","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8163-3050","authenticated-orcid":false,"given":"Tong","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,8]]},"reference":[{"key":"1594_CR1","doi-asserted-by":"publisher","unstructured":"J. Chai, H. Zeng, A. Li, E. W. T. Ngai. Deep learning in computer vision: A critical review of emerging techniques and application scenarios. Machine Learning with Applications, vol. 6, Article number 100134, 2021. DOI: https:\/\/doi.org\/10.1016\/j.mlwa.2021.100134.","DOI":"10.1016\/j.mlwa.2021.100134"},{"key":"1594_CR2","doi-asserted-by":"publisher","first-page":"770","DOI":"10.1109\/CVPR.2016.90","volume-title":"Proceedings of IEEE Conference on Computer Vision and Pattern Recognition","author":"K He","year":"2016","unstructured":"K. He, X. Zhang, S. Ren, J. Sun. Deep residual learning for image recognition. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, USA, pp. 770\u2013778, 2016. DOI: https:\/\/doi.org\/10.1109\/CVPR.2016.90."},{"key":"1594_CR3","volume-title":"Proceedings of the 1st International Conference on Learning Representations","author":"T Mikolov","year":"2013","unstructured":"T. Mikolov, K. Chen, G. Corrado, J. Dean. Efficient estimation of word representations in vector space. In Proceedings of the 1st International Conference on Learning Representations, Scottsdale, USA, 2013."},{"key":"1594_CR4","first-page":"6000","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","author":"A Vaswani","year":"2017","unstructured":"A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. Kaiser, I. Polosukhin. Attention is all you need. In Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, USA, pp. 6000\u20136010, 2017."},{"key":"1594_CR5","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems","author":"T B Brown","year":"2020","unstructured":"T. B. Brown, B. Mann, N. Ryder, M. Subbiah, J. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell, S. Agarwal, A. Herbert-Voss, G. Krueger, T. Henighan, R. Child, A. Ramesh, D. M. Ziegler, J. Wu, C. Winter, C. Hesse, M. Chen, E. Sigler, M. Litwin, S. Gray, B. Chess, J. Clark, C. Berner, S. McCandlish, A. Radford, I. Sutskever, D. Amodei. Language models are few-shot learners. In Proceedings of the 34th International Conference on Neural Information Processing Systems, Vancouver, Canada, Article number 159, 2020."},{"issue":"2","key":"1594_CR6","doi-asserted-by":"publisher","first-page":"217","DOI":"10.1007\/s11633-023-1416-x","volume":"21","author":"B Cao","year":"2024","unstructured":"B. Cao, H. Lin, X. Han, L. Sun. The life cycle of knowledge in big language models: A survey. Machine Intelligence Research, vol.21, no.2, pp.217\u2013238, 2024. DOI: https:\/\/doi.org\/10.1007\/s11633-023-1416-x.","journal-title":"Machine Intelligence Research"},{"key":"1594_CR7","doi-asserted-by":"publisher","first-page":"9556","DOI":"10.1109\/CVPR52733.2024.00913","volume-title":"Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"X Yue","year":"2024","unstructured":"X. Yue, Y. Ni, T. Zhang, K. Zheng, R. Liu, G. Zhang, S. Stevens, D. Jiang, W. Ren, Y. Sun, C. Wei, B. T. Yu, R. Yuan, R. Sun, M. Yin, B. Zheng, Z. Yang, Y. Liu, W. Huang, H. Sun, Y. Su, W. Chen. MMMU: A massive multidiscipline multimodal understanding and reasoning benchmark for expert AGI. In Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, USA, pp. 9556\u20139567, 2024. DOI: https:\/\/doi.org\/10.1109\/CVPR52733.2024.00913."},{"key":"1594_CR8","doi-asserted-by":"publisher","first-page":"1135","DOI":"10.1145\/2939672.2939778","volume-title":"Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"M T Ribeiro","year":"2016","unstructured":"M. T. Ribeiro, S. Singh, C. Guestrin. \u201cWhy should i trust you?\u201d: Explaining the predictions of any classifier. In Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, USA, pp. 1135\u20131144, 2016. DOI: https:\/\/doi.org\/10.1145\/2939672.2939778."},{"key":"1594_CR9","volume-title":"Towards a rigorous science of interpretable machine learning","author":"F Doshi-Velez","year":"2017","unstructured":"F. Doshi-Velez, B. Kim. Towards a rigorous science of interpretable machine learning, [Online], Available: https:\/\/arxiv.org\/abs\/1702.08608, 2017."},{"key":"1594_CR10","volume-title":"Proceedings of the 2nd International Conference on Learning Representations","author":"C Szegedy","year":"2014","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus. Intriguing properties of neural networks. In Proceedings of the 2nd International Conference on Learning Representations, Banff, Canada, 2014."},{"key":"1594_CR11","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1109\/CVPR.2017.17","volume-title":"Proceedings of IEEE Conference on Computer Vision and Pattern Recognition","author":"S M Moosavi-Dezfooli","year":"2017","unstructured":"S. M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, P. Frossard. Universal adversarial perturbations. In Proceedings of IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, USA, pp. 86\u201394, 2017. DOI: https:\/\/doi.org\/10.1109\/CVPR.2017.17."},{"key":"1594_CR12","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"T. Gu, K. Liu, B. Dolan-Gavitt, S. Garg. BadNets: Evaluating backdooring attacks on deep neural networks. IEEE Access, vol. 7, pp. 47230\u201347244, 2019. DOI: https:\/\/doi.org\/10.1109\/ACCESS.2019.2909068.","journal-title":"IEEE Access"},{"key":"1594_CR13","doi-asserted-by":"publisher","first-page":"138872","DOI":"10.1109\/ACCESS.2019.2941376","volume":"1","author":"J Dai","year":"2019","unstructured":"J. Dai, C. Chen, Y. Li. A backdoor against LSTM-based text classification systems IEEE Access, vol. 1, pp. 138872\u2013138878, 2019. DOI: https:\/\/doi.org\/10.1109\/ACCESS.2019.2941376.","journal-title":"IEEE Access"},{"key":"1594_CR14","doi-asserted-by":"publisher","first-page":"443","DOI":"10.18653\/v1\/2021.acl-long.37","volume-title":"Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing","author":"F Qi","year":"2021","unstructured":"F. Qi, M. Li, Y. Chen, Z. Zhang, Z. Liu, Y. Wang, M. Sun. Hidden killer: Invisible textual backdoor attacks with syntactic trigger. In Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing, pp. 443\u2013453, 2021. DOI: https:\/\/doi.org\/10.18653\/v1\/2021.acl-long.37."},{"key":"1594_CR15","doi-asserted-by":"publisher","first-page":"4569","DOI":"10.18653\/v1\/2021.emnlp-main.374","volume-title":"Proceedings of Conference on Empirical Methods in Natural Language Processing","author":"F Qi","year":"2021","unstructured":"F. Qi, Y. Chen, X. Zhang, M. Li, Z. Liu, M. Sun. Mind the style of text! Adversarial and backdoor attacks based on text style transfer. In Proceedings of Conference on Empirical Methods in Natural Language Processing, Punta Cana, Dominican Republic, pp. 4569\u20134580, 2021. DOI: https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.374."},{"key":"1594_CR16","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/SPW.2018.00016","volume-title":"Proceedings of IEEE Security and Privacy Workshops","author":"J Gao","year":"2018","unstructured":"J. Gao, J. Lanchantin, M. L. Soffa, Y. Qi. Black-box generation of adversarial text sequences to evade deep learning classifiers. In Proceedings of IEEE Security and Privacy Workshops, San Francisco, USA, pp. 50\u201356, 2018. DOI: https:\/\/doi.org\/10.1109\/SPW.2018.00016."},{"key":"1594_CR17","doi-asserted-by":"publisher","first-page":"31","DOI":"10.18653\/v1\/P18-2006","volume-title":"Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics","author":"J Ebrahimi","year":"2018","unstructured":"J. Ebrahimi, A. Rao, D. Lowd, D. Dou. HotFlip: White-box adversarial examples for text classification. In Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics, Melbourne, Australia, pp. 31\u201336, 2018. DOI: https:\/\/doi.org\/10.18653\/v1\/P18-2006."},{"key":"1594_CR18","doi-asserted-by":"publisher","unstructured":"S. Goyal, S. Doddapaneni, M. M. Khapra, B. Ravindran. A survey of adversarial defenses and robustness in NLP. ACM Computing Surveys, vol. 55, no. 14s, Article number 332, 2023. DOI: https:\/\/doi.org\/10.1145\/3593042.","DOI":"10.1145\/3593042"},{"key":"1594_CR19","doi-asserted-by":"publisher","unstructured":"W. E. Zhang, Q. Z. Sheng, A. Alhazmi, C. Li. Adversarial attacks on deep-learning models in natural language processing: A survey. ACM Transactions on Intelligent Systems and Technology, vol. 11, no. 3, Article number 24, 2020. DOI: https:\/\/doi.org\/10.1145\/3374217.","DOI":"10.1145\/3374217"},{"key":"1594_CR20","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1016\/j.neucom.2022.04.020","volume":"492","author":"S Qiu","year":"2022","unstructured":"S. Qiu, Q. Liu, S. Zhou, W. Huang. Adversarial attack and defense technologies in natural language processing: A survey. Neurocomputing, vol. 492, pp. 278\u2013307, 2022. DOI: https:\/\/doi.org\/10.1016\/j.neucom.2022.04.020.","journal-title":"Neurocomputing"},{"issue":"6","key":"1594_CR21","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1109\/MNET.2024.3367788","volume":"38","author":"H Yang","year":"2024","unstructured":"H. Yang, K. Xiang, M. Ge, H. Li, R. Lu, S. Yu. A comprehensive overview of backdoor attacks in large language models within communication networks. IEEE Network, vol. 38, no. 6, pp. 211\u2013218, 2024. DOI: https:\/\/doi.org\/10.1109\/MNET.2024.3367788.","journal-title":"IEEE Network"},{"key":"1594_CR22","doi-asserted-by":"publisher","first-page":"809","DOI":"10.1109\/QRS57517.2022.00086","volume-title":"Proceedings of the 22nd IEEE International Conference on Software Quality, Reliability and Security","author":"X Sheng","year":"2022","unstructured":"X. Sheng, Z. Han, P. Li, X. Chang. A survey on backdoor attack and defense in natural language processing. In Proceedings of the 22nd IEEE International Conference on Software Quality, Reliability and Security, Guangzhou, China, pp. 809\u2013820, 2022. DOI: https:\/\/doi.org\/10.1109\/QRS57517.2022.00086."},{"key":"1594_CR23","doi-asserted-by":"publisher","first-page":"13997","DOI":"10.1609\/aaai.v35i16.17648","volume-title":"Proceedings of the 35th AAAI Conference on Artificial Intelligence","author":"X Wang","year":"2021","unstructured":"X. Wang, Y. Yang, Y. Deng, K. He. Adversarial training with fast gradient projection method against synonym substitution based text attacks. In Proceedings of the 35th AAAI Conference on Artificial Intelligence, pp. 13997\u201314005, 2021. DOI: https:\/\/doi.org\/10.1609\/aaai.v35i16.17648."},{"key":"1594_CR24","doi-asserted-by":"publisher","first-page":"6453","DOI":"10.1109\/ACCESS.2020.3048120","volume":"9","author":"H Lee","year":"2021","unstructured":"H. Lee, H. Bae, S. Yoon. Gradient masking of label smoothing in adversarial robustness. IEEE Access, vol. 9, pp. 6453\u20136464, 2021. DOI: https:\/\/doi.org\/10.1109\/ACCESS.2020.3048120.","journal-title":"IEEE Access"},{"issue":"3","key":"1594_CR25","doi-asserted-by":"publisher","first-page":"3159","DOI":"10.1109\/TKDE.2021.3117608","volume":"35","author":"W Wang","year":"2023","unstructured":"W. Wang, R. Wang, L. Wang, Z. Wang, A. Ye. Towards a robust deep neural network against adversarial texts: A survey. IEEE Transactions on Knowledge and Data Engineering, vol. 35, no. 3, pp. 3159\u20133179, 2023. DOI: https:\/\/doi.org\/10.1109\/TKDE.2021.3117608.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"1594_CR26","doi-asserted-by":"publisher","first-page":"3281","DOI":"10.1609\/aaai.v31i1.10970","volume-title":"Proceedings of the 31th AAAI Conference on Artificial Intelligence","author":"K Sakaguchi","year":"2017","unstructured":"K. Sakaguchi, K. Duh, M. Post, B. Van Durme. Robsut wrod reocginiton via semi-character recurrent neural network. In Proceedings of the 31th AAAI Conference on Artificial Intelligence, San Francisco, USA, pp. 3281\u20133287, 2017. DOI: https:\/\/doi.org\/10.1609\/aaai.v31i1.10970."},{"key":"1594_CR27","doi-asserted-by":"publisher","first-page":"5582","DOI":"10.18653\/v1\/P19-1561","volume-title":"Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics","author":"D Pruthi","year":"2019","unstructured":"D. Pruthi, B. Dhingra, Z. C. Lipton. Combating adversarial misspellings with robust word recognition. In Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics, Florence, Italy, pp. 5582\u20135591, 2019. DOI: https:\/\/doi.org\/10.18653\/v1\/P19-1561."},{"key":"1594_CR28","doi-asserted-by":"publisher","first-page":"13981","DOI":"10.18653\/v1\/2023.acl-long.781","volume-title":"Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics","author":"A Gupta","year":"2023","unstructured":"A. Gupta, C. W. Blum, T. Choji, Y. Fei, S. Shah, A. Vempala, V. Srikumar. Don\u2019t retrain, just rewrite: Countering adversarial perturbations by rewriting text. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics, Toronto, Canada, pp. 13981\u201313998, 2023. DOI: https:\/\/doi.org\/10.18653\/v1\/2023.acl-long.781."},{"key":"1594_CR29","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Proceedings of the 21st International Symposium on Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"K. Liu, B. Dolan-Gavitt, S. Garg. Fine-pruning: Defending against backdooring attacks on deep neural networks. In Proceedings of the 21st International Symposium on Research in Attacks, Intrusions, and Defenses, Heraklion, Greece, pp. 273\u2013294, 2018. DOI: https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13."},{"key":"1594_CR30","volume-title":"Proceedings of the 9th International Conference on Learning Representations","author":"Y Li","year":"2021","unstructured":"Y. Li, X. Lyu, N. Koren, L. Lyu, B. Li, X. Ma. Neural attention distillation: Erasing backdoor triggers from deep neural networks. In Proceedings of the 9th International Conference on Learning Representations, 2021."},{"key":"1594_CR31","volume-title":"Proceedings of the 36th International Conference on Neural Information Processing Systems","author":"B Zhu","year":"2022","unstructured":"B. Zhu, Y. Qin, G. Cui, Y. Chen, W. Zhao, C. Fu, Y. Deng, Z. Liu, J. Wang, W. Wu, M. Sun, M. Gu. Moderate-fitting as a natural backdoor defender for pre-trained language models. In Proceedings of the 36th International Conference on Neural Information Processing Systems, New Orleans, USA, Article number 80, 2022."},{"key":"1594_CR32","first-page":"19879","volume-title":"Proceedings of the 39th International Conference on Machine Learning","author":"G Shen","year":"2022","unstructured":"G. Shen, Y. Liu, G. Tao, Q. Xu, Z. Zhang, S. An, S. Ma, X. Zhang. Constrained optimization with dynamic bound-scaling for effective NLP backdoor defense. In Proceedings of the 39th International Conference on Machine Learning, Baltimore, USA, pp. 19879\u201319892, 2022."},{"key":"1594_CR33","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1109\/SP40001.2021.00034","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"X Xu","year":"2021","unstructured":"X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, B. Li. Detecting AI Trojans using meta neural analysis. In Proceedings of IEEE Symposium on Security and Privacy, San Francisco, USA, pp. 103\u2013120, 2021. DOI: https:\/\/doi.org\/10.1109\/SP40001.2021.00034."},{"key":"1594_CR34","doi-asserted-by":"publisher","first-page":"8365","DOI":"10.18653\/v1\/2021.emnlp-main.659","volume-title":"Proceedings of Conference on Empirical Methods in Natural Language Processing","author":"W Yang","year":"2021","unstructured":"W. Yang, Y. Lin, P. Li, J. Zhou, X. Sun. RAP: Robustness-aware perturbations for defending against backdoor attacks on NLP models. In Proceedings of Conference on Empirical Methods in Natural Language Processing, Punta Cana, Dominican Republic, pp. 8365\u20138381, 2021. DOI: https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.659."},{"key":"1594_CR35","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1145\/3359789.3359790","volume-title":"Proceedings of the 35th Annual Computer Security Applications Conference","author":"Y Gao","year":"2019","unstructured":"Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, S. Nepal. STRIP: A defence against Trojan attacks on deep neural networks. In Proceedings of the 35th Annual Computer Security Applications Conference, San Juan, USA, pp. 113\u2013125, 2019. DOI: https:\/\/doi.org\/10.1145\/3359789.3359790."},{"key":"1594_CR36","doi-asserted-by":"publisher","first-page":"9558","DOI":"10.18653\/v1\/2021.emnlp-main.752","volume-title":"Proceedings of Conference on Empirical Methods in Natural Language Processing","author":"F Qi","year":"2021","unstructured":"F. Qi, Y. Chen, M. Li, Y. Yao, Z. Liu, M. Sun. ONION: A simple and effective defense against textual backdoor attacks. In Proceedings of Conference on Empirical Methods in Natural Language Processing, Punta Cana, Dominican Republic, pp. 9558\u20139566, 2021. DOI: https:\/\/doi.org\/10.18653\/v1\/2021.emnlp-main.752."},{"key":"1594_CR37","volume-title":"Proceedings of the 36th International Conference on Neural Information Processing Systems","author":"G Cui","year":"2022","unstructured":"G. Cui, L. Yuan, B. He, Y. Chen, Z. Liu, M. Sun. A unified evaluation of textual backdoor learning: Frameworks and benchmarks. In Proceedings of the 36th International Conference on Neural Information Processing Systems, New Orleans, USA, Article number 362, 2022."},{"issue":"5","key":"1594_CR38","doi-asserted-by":"publisher","first-page":"888","DOI":"10.1007\/s11633-024-1502-8","volume":"21","author":"T Sun","year":"2024","unstructured":"T. Sun, X. Zhang, Z. He, P. Li, Q. Cheng, X. Liu, H. Yan, Y. Shao, Q. Tang, S. Zhang, X. Zhao, K. Chen, Y. Zheng, Z. Zhou, R. Li, J. Zhan, Y. Zhou, L. Li, X. Yang, L. Wu, Z. Yin, X. Huang, Y. G. Jiang, X. Qiu. MOSS: An open conversational large language model. Machine Intelligence Research, vol.21, no.5, pp.888\u2013905, 2024. DOI: https:\/\/doi.org\/10.1007\/s11633-024-1502-8.","journal-title":"Machine Intelligence Research"},{"key":"1594_CR39","volume-title":"A prompt pattern catalog to enhance prompt engineering with ChatGPT","author":"J White","year":"2023","unstructured":"J. White, Q. Fu, S. Hays, M. Sandborn, C. Olea, H. Gilbert, A. Elnashar, J. Spencer-Smith, D. C. Schmidt. A prompt pattern catalog to enhance prompt engineering with ChatGPT, [Online], Available: https:\/\/arxiv.org\/abs\/2302.11382, 2023."},{"key":"1594_CR40","doi-asserted-by":"publisher","first-page":"865","DOI":"10.1609\/aaai.v34i01.5432","volume-title":"Proceedings of the 34th AAAI Conference on Artificial Intelligence","author":"S Pal","year":"2020","unstructured":"S. Pal, Y. Gupta, A. Shukla, A. Kanade, S. Shevade, V. Ganapathy. ActiveThief: Model extraction using active learning and unannotated public data. In Proceedings of the 34th AAAI Conference on Artificial Intelligence, New York, USA, pp. 865\u2013872, 2020. DOI: https:\/\/doi.org\/10.1609\/aaai.v34i01.5432."},{"key":"1594_CR41","first-page":"1309","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"V Chandrasekaran","year":"2020","unstructured":"V. Chandrasekaran, K. Chaudhuri, I. Giacomelli, S. Jha, S. Yan. Exploring connections between active learning and model extraction. In Proceedings of the 29th USENIX Security Symposium, Boston, USA, pp. 1309\u20131326, 2020."},{"issue":"6","key":"1594_CR42","doi-asserted-by":"publisher","first-page":"1789","DOI":"10.1007\/s11263-021-01453-z","volume":"129","author":"J Gou","year":"2021","unstructured":"J. Gou, B. Yu, S. J. Maybank, D. Tao. Knowledge distillation: A survey. International Journal of Computer Vision, vol. 129, no. 6, pp. 1789\u20131819, 2021. DOI: https:\/\/doi.org\/10.1007\/s11263-021-01453-z.","journal-title":"International Journal of Computer Vision"},{"key":"1594_CR43","doi-asserted-by":"publisher","first-page":"4171","DOI":"10.18653\/v1\/N19-1423","volume-title":"Proceedings of Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies","author":"J Devlin","year":"2019","unstructured":"J. Devlin, M. W. Chang, K. Lee, K. Toutanova. BERT: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Minneapolis, USA, pp. 4171\u20134186, 2019. DOI: https:\/\/doi.org\/10.18653\/v1\/N19-1423."},{"key":"1594_CR44","volume-title":"Roberta: A robustly optimized BERT pretraining approach","author":"Y Liu","year":"2019","unstructured":"Y. Liu, M. Ott, N. Goyal, J. Du, M. Joshi, D. Chen, O. Levy, M. Lewis, L. Zettlemoyer, V. Stoyanov. Roberta: A robustly optimized BERT pretraining approach, [Online], Available: https:\/\/arxiv.org\/abs\/1907.11692, 2019."},{"key":"1594_CR45","doi-asserted-by":"publisher","first-page":"1085","DOI":"10.18653\/v1\/P19-1103","volume-title":"Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics","author":"S Ren","year":"2019","unstructured":"S. Ren, Y. Deng, K. He, W. Che. Generating natural language adversarial examples through probability weighted word saliency. In Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics, Florence, Italy, pp. 1085\u20131097, 2019. DOI: https:\/\/doi.org\/10.18653\/v1\/P19-1103."},{"key":"1594_CR46","doi-asserted-by":"publisher","first-page":"8018","DOI":"10.1609\/aaai.v34i05.6311","volume-title":"Proceedings of the 34th AAAI Conference on Artificial Intelligence","author":"D Jin","year":"2020","unstructured":"D. Jin, Z. Jin, J. T. Zhou, P. Szolovits. Is BERT really robust? A strong baseline for natural language attack on text classification and entailment. In Proceedings of the 34th AAAI Conference on Artificial Intelligence, New York, USA, pp. 8018\u20138025, 2020. DOI: https:\/\/doi.org\/10.1609\/aaai.v34i05.6311."},{"key":"1594_CR47","volume-title":"Proceedings of the 26th Annual Network and Distributed System Security Symposium","author":"J Li","year":"2019","unstructured":"J. Li, S. Ji, T. Du, B. Li, T. Wang. TextBugger: Generating adversarial text against real-world applications. In Proceedings of the 26th Annual Network and Distributed System Security Symposium, San Diego, USA, 2019."}],"container-title":["Machine Intelligence Research"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11633-025-1594-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11633-025-1594-9","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11633-025-1594-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T08:02:43Z","timestamp":1784793763000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11633-025-1594-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,8]]},"references-count":47,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,8]]}},"alternative-id":["1594"],"URL":"https:\/\/doi.org\/10.1007\/s11633-025-1594-9","relation":{},"ISSN":["2731-538X","2731-5398"],"issn-type":[{"value":"2731-538X","type":"print"},{"value":"2731-5398","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,8]]},"assertion":[{"value":"6 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declared that they have no conflicts of interest to this work.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations of conflict of interest"}}]}}