{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T08:16:32Z","timestamp":1783671392041,"version":"3.55.0"},"reference-count":36,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Applied Soft Computing"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.asoc.2026.115500","type":"journal-article","created":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T16:26:55Z","timestamp":1779380815000},"page":"115500","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PA","title":["Dynamic attention graph-guided and sensitivity-aware substitution for black-box adversarial text generation"],"prefix":"10.1016","volume":"201","author":[{"given":"Yu","family":"Lu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1170-3911","authenticated-orcid":false,"given":"Lei","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lin","family":"Wei","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8070-5363","authenticated-orcid":false,"given":"Yucheng","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2356-0700","authenticated-orcid":false,"given":"Yufei","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.asoc.2026.115500_bib0005","series-title":"Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers)","first-page":"4171","article-title":"BERT: pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2019"},{"key":"10.1016\/j.asoc.2026.115500_bib0010","series-title":"China National Conference on Chinese Computational Linguistics","first-page":"194","article-title":"How to fine-tune BERT for text classification?","author":"Sun","year":"2019"},{"key":"10.1016\/j.asoc.2026.115500_bib0015","series-title":"Proceedings of the 2013 Conference on Empirical Methods in Natural Language Processing","first-page":"1631","article-title":"Recursive deep models for semantic compositionality over a sentiment treebank","author":"Socher","year":"2013"},{"key":"10.1016\/j.asoc.2026.115500_bib0020","series-title":"Proceedings of the 2016 Conference on Empirical Methods in Natural Language Processing","first-page":"2383","article-title":"SQuAD: 100, 000+ questions for machine comprehension of text","author":"Rajpurkar","year":"2016"},{"key":"10.1016\/j.asoc.2026.115500_bib0025","author":"Goodfellow"},{"key":"10.1016\/j.asoc.2026.115500_bib0030","author":"Szegedy"},{"issue":"3","key":"10.1016\/j.asoc.2026.115500_bib0035","first-page":"1","article-title":"Adversarial attacks on deep-learning models in natural language processing: a survey","volume":"11","author":"Zhang","year":"2020","journal-title":"ACM Transactions on Intelligent Systems and Technology (TIST)"},{"key":"10.1016\/j.asoc.2026.115500_bib0040","series-title":"Proceedings of the 56th Annual Meeting of the Association for Computational Linguistics (Volume 2: Short Papers)","first-page":"31","article-title":"HotFlip: white-box adversarial examples for text classification","author":"Ebrahimi","year":"2018"},{"key":"10.1016\/j.asoc.2026.115500_bib0045","series-title":"Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security","first-page":"506","article-title":"Practical black-box attacks against machine learning","author":"Papernot","year":"2017"},{"key":"10.1016\/j.asoc.2026.115500_bib0050","series-title":"Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing","first-page":"5747","article-title":"Gradient-based adversarial attacks against text transformers","author":"Guo","year":"2021"},{"key":"10.1016\/j.asoc.2026.115500_bib0055","series-title":"Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics","first-page":"1085","article-title":"Generating natural language adversarial examples through probability weighted word saliency","author":"Ren","year":"2019"},{"key":"10.1016\/j.asoc.2026.115500_bib0060","series-title":"Proceedings of the 2018 Conference on Empirical Methods in Natural Language Processing","first-page":"2840","article-title":"Generating natural language adversarial examples","author":"Alzantot","year":"2018"},{"key":"10.1016\/j.asoc.2026.115500_bib0065","series-title":"Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP)","first-page":"6174","article-title":"BAE: BERT-based adversarial examples for text classification","author":"Garg","year":"2020"},{"key":"10.1016\/j.asoc.2026.115500_bib0070","series-title":"26th Annual Network and Distributed System Security Symposium (NDSS 2019)","article-title":"TEXTBUGGER: generating adversarial text against real-world applications","author":"Li","year":"2019"},{"key":"10.1016\/j.asoc.2026.115500_bib0075","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence, 34","first-page":"8018","article-title":"Is BERT really robust? A strong baseline for natural language attack on text classification and entailment","author":"Jin","year":"2020"},{"key":"10.1016\/j.asoc.2026.115500_bib0080","author":"Hou"},{"key":"10.1016\/j.asoc.2026.115500_bib0085","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"3877","article-title":"TextHoaxer: budgeted hard-label adversarial attacks on text","author":"Ye","year":"2022"},{"key":"10.1016\/j.asoc.2026.115500_bib0090","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"13228","article-title":"SSPAttack: a simple and sweet paradigm for black-box hard-label textual adversarial attack","author":"Liu","year":"2023"},{"key":"10.1016\/j.asoc.2026.115500_bib0095","series-title":"Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","first-page":"3093","article-title":"PAT: geometry-aware hard-label black-box adversarial attacks on text","author":"Ye","year":"2023"},{"key":"10.1016\/j.asoc.2026.115500_bib0100","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"19759","article-title":"LimeAttack: local explainable method for textual hard-label adversarial attack","author":"Zhu","year":"2024"},{"key":"10.1016\/j.asoc.2026.115500_bib0105","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106461","article-title":"HyGloadAttack: hard-label black-box textual adversarial attacks via hybrid optimization","volume":"178","author":"Liu","year":"2024","journal-title":"Neural Netw."},{"key":"10.1016\/j.asoc.2026.115500_bib0110","doi-asserted-by":"crossref","first-page":"2398","DOI":"10.1109\/TIFS.2024.3350376","article-title":"FastTextDodger: decision-based adversarial attack against black-box NLP models with extremely high efficiency","volume":"19","author":"Hu","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.asoc.2026.115500_bib0115","author":"Yu"},{"key":"10.1016\/j.asoc.2026.115500_bib0120","author":"Liu"},{"key":"10.1016\/j.asoc.2026.115500_bib0125","article-title":"Attention is all you need","volume":"30","author":"Vaswani","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.asoc.2026.115500_bib0130","series-title":"33rd USENIX Security Symposium (USENIX Security 24)","first-page":"4801","article-title":"DAAP: privacy-preserving model accuracy estimation on unlabeled datasets through distribution-aware adversarial perturbation","author":"Cao","year":"2024"},{"key":"10.1016\/j.asoc.2026.115500_bib0135","author":"Lan"},{"issue":"9","key":"10.1016\/j.asoc.2026.115500_bib0140","doi-asserted-by":"crossref","first-page":"5907","DOI":"10.1007\/s10994-024-06539-6","article-title":"Reversible jump attack to textual classifiers with modification reduction","volume":"113","author":"Ni","year":"2024","journal-title":"Mach. Learn."},{"issue":"4","key":"10.1016\/j.asoc.2026.115500_bib0145","doi-asserted-by":"crossref","first-page":"92","DOI":"10.3390\/computers13040092","article-title":"The explainability of transformers: current status and directions","volume":"13","author":"Fantozzi","year":"2024","journal-title":"Computers"},{"key":"10.1016\/j.asoc.2026.115500_bib0150","series-title":"Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics","first-page":"4190","article-title":"Quantifying attention flow in transformers","author":"Abnar","year":"2020"},{"key":"10.1016\/j.asoc.2026.115500_bib0155","doi-asserted-by":"crossref","first-page":"65202","DOI":"10.52202\/075280-2845","article-title":"Dynamic context pruning for efficient and interpretable autoregressive transformers","volume":"36","author":"Anagnostidis","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"6","key":"10.1016\/j.asoc.2026.115500_bib0160","doi-asserted-by":"crossref","first-page":"4731","DOI":"10.1007\/s10462-021-10010-6","article-title":"A survey on different dimensions for graphical keyword extraction techniques: issues and challenges","volume":"54","author":"Garg","year":"2021","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.asoc.2026.115500_bib0165","series-title":"Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics","first-page":"6066","article-title":"Word-level textual adversarial attacking as combinatorial optimization","author":"Zang","year":"2020"},{"key":"10.1016\/j.asoc.2026.115500_bib0170","series-title":"Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","first-page":"2307","article-title":"LeapAttack: hard-label adversarial attack on text via gradient-based optimization","author":"Ye","year":"2022"},{"issue":"C","key":"10.1016\/j.asoc.2026.115500_bib0175","article-title":"TextJuggler: fooling text classification tasks by generating high-quality adversarial examples","volume":"300","author":"Peng","year":"2024","journal-title":"Know.-Based Syst."},{"key":"10.1016\/j.asoc.2026.115500_bib0180","series-title":"Proceedings of the 2024 Joint International Conference on Computational Linguistics, Language Resources and Evaluation (LREC-COLING 2024)","first-page":"14037","article-title":"Rethinking word-level adversarial attack: the trade-off between efficiency, effectiveness, and imperceptibility","author":"Zhan","year":"2024"}],"container-title":["Applied Soft Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1568494626009488?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1568494626009488?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T07:46:54Z","timestamp":1783669614000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1568494626009488"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":36,"alternative-id":["S1568494626009488"],"URL":"https:\/\/doi.org\/10.1016\/j.asoc.2026.115500","relation":{},"ISSN":["1568-4946"],"issn-type":[{"value":"1568-4946","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Dynamic attention graph-guided and sensitivity-aware substitution for black-box adversarial text generation","name":"articletitle","label":"Article Title"},{"value":"Applied Soft Computing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.asoc.2026.115500","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"115500"}}