{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T08:01:06Z","timestamp":1780473666938,"version":"3.54.1"},"reference-count":54,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,12]]},"DOI":"10.1016\/j.eswa.2026.133033","type":"journal-article","created":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T15:58:07Z","timestamp":1779897487000},"page":"133033","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Multi-hop semantic association-based adversarial attack and defense method for natural language processing systems"],"prefix":"10.1016","volume":"330","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2587-3567","authenticated-orcid":false,"given":"Jiacheng","family":"Huang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1614-5119","authenticated-orcid":false,"given":"Ning","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1833-9019","authenticated-orcid":false,"given":"Xiaoyin","family":"Yi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.133033_bib0001","series-title":"International conference on machine learning","first-page":"1","article-title":"Revisiting character-level adversarial attacks for language models","author":"Abad-Rocamora","year":"2024"},{"issue":"2","key":"10.1016\/j.eswa.2026.133033_bib0002","doi-asserted-by":"crossref","first-page":"1347","DOI":"10.1007\/s10207-023-00793-w","article-title":"Security bug reports classification using fasttext","volume":"23","author":"Alqahtani","year":"2024","journal-title":"International Journal of Information Security"},{"key":"10.1016\/j.eswa.2026.133033_bib0003","series-title":"Conference of the european chapter of the association for computational linguistics: Student research workshop","first-page":"137","article-title":"Arabic synonym BERT-based adversarial examples for text classification","author":"Alshahrani","year":"2024"},{"issue":"1","key":"10.1016\/j.eswa.2026.133033_bib0004","first-page":"11:1","article-title":"Exploring the landscape of recommender systems evaluation: Practices and perspectives","volume":"2","author":"Bauer","year":"2024","journal-title":"Transactions on Recommender Systems"},{"key":"10.1016\/j.eswa.2026.133033_bib0005","series-title":"Encyclopedia of evolutionary psychological science","first-page":"404","author":"Bracken","year":"2021"},{"issue":"5","key":"10.1016\/j.eswa.2026.133033_bib0006","article-title":"Learning from mistakes: Improving spelling correction performance with automatic generation of realistic misspellings","volume":"38","author":"B\u00fcy\u00fck","year":"2021","journal-title":"Expert Systems - The Journal of Knowledge Engineering"},{"issue":"1","key":"10.1016\/j.eswa.2026.133033_bib0007","first-page":"79561","article-title":"Wordchange: Adversarial examples generation approach for chinese text classification","volume":"8","author":"Cheng","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.eswa.2026.133033_bib0008","series-title":"Conference of the North American chapter of the association for computational linguistics: Human language technologies","first-page":"1634","article-title":"Text processing like humans do: Visually attacking and shielding nlp systems","author":"Eger","year":"2019"},{"key":"10.1016\/j.eswa.2026.133033_bib0009","series-title":"International conference on learning representations","first-page":"1","article-title":"Confidence elicitation: A new attack vector for large language models","author":"Formento","year":"2025"},{"key":"10.1016\/j.eswa.2026.133033_bib0010","series-title":"Findings of the association for computational linguistics","first-page":"1","article-title":"Using punctuation as an adversarial attack on deep learning-based nlp systems: An empirical study","author":"Formento","year":"2023"},{"key":"10.1016\/j.eswa.2026.133033_bib0011","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.126688","article-title":"FGRCAT: A fine-grained reasoning framework through causality and adversarial training","volume":"272","author":"Guo","year":"2025","journal-title":"Expert Systems with Applications"},{"issue":"2","key":"10.1016\/j.eswa.2026.133033_bib0012","doi-asserted-by":"crossref","first-page":"931","DOI":"10.1177\/14614448231187529","article-title":"Effects of #coronavirus content moderation on misinformation and anti-asian hate on instagram","volume":"27","author":"Hong","year":"2025","journal-title":"New Media and Society"},{"key":"10.1016\/j.eswa.2026.133033_bib0013","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2025.113159","article-title":"Subattack: A word-level adversarial textual attack method via antonym substitution","volume":"163","author":"Hua","year":"2026","journal-title":"Engineering Applications of Artificial Intelligence"},{"key":"10.1016\/j.eswa.2026.133033_bib0014","series-title":"Asian conference on machine learning","first-page":"905","article-title":"Chain association-based attacking and shielding natural language processing systems","volume":"vol. 260","author":"Huang","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0015","doi-asserted-by":"crossref","first-page":"4985","DOI":"10.1109\/TIFS.2025.3565993","article-title":"Transferable attention-distracting adversarial attack on data-driven models for power systems","volume":"20","author":"Huang","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"11","key":"10.1016\/j.eswa.2026.133033_bib0016","article-title":"Sentiment classification using bidirectional lstm-snp model and attention mechanism","volume":"221","author":"Huang","year":"2023","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133033_bib0017","series-title":"Findings of the association for computational linguistics: ACL 2023","first-page":"6810","article-title":"\u201cLow-resource\u201d text classification: A parameter-free classification method with compressors","author":"Jiang","year":"2023"},{"key":"10.1016\/j.eswa.2026.133033_bib0018","series-title":"The thirty-fourth AAAI conference on artificial intelligence","first-page":"8018","article-title":"Is BERT really robust? A strong baseline for natural language attack on text classification and entailment","author":"Jin","year":"2020"},{"key":"10.1016\/j.eswa.2026.133033_bib0019","series-title":"Proceedings of the 60th annual meeting of the association for computational linguistics (volume 1: Long papers)","first-page":"6661","article-title":"SHIELD: Defending textual neural networks against multiple black-box adversarial attacks with stochastic multi-expert patcher","author":"Le","year":"2022"},{"key":"10.1016\/j.eswa.2026.133033_bib0020","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113117","article-title":"Tf-attack: Transferable and fast adversarial attacks on large language models","volume":"312","author":"Li","year":"2025","journal-title":"Knowledge-Based Systems"},{"issue":"3","key":"10.1016\/j.eswa.2026.133033_bib0021","doi-asserted-by":"crossref","first-page":"3069","DOI":"10.1007\/s10489-022-03495-3","article-title":"Advanced defensive distillation with ensemble voting and noisy logits","volume":"53","author":"Liang","year":"2023","journal-title":"Applied Intelligence"},{"key":"10.1016\/j.eswa.2026.133033_bib0022","series-title":"Conference on empirical methods in natural language processing","first-page":"7664","article-title":"Character-level white-box adversarial attacks against transformers via attachable subwords substitution","author":"Liu","year":"2022"},{"key":"10.1016\/j.eswa.2026.133033_bib0023","series-title":"Thirty-eighth AAAI conference on artificial intelligence","first-page":"8832","article-title":"Perturbation-invariant adversarial training for neural ranking models: Improving the effectiveness-robustness trade-off","author":"Liu","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0024","series-title":"IEEE International conference on parallel & distributed processing with applications, big data & cloud computing, sustainable computing & communications, social computing & networking","first-page":"554","article-title":"DE-CO: A two-step spelling correction model for combating adversarial typos","author":"Liu","year":"2020"},{"key":"10.1016\/j.eswa.2026.133033_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106461","article-title":"Hygloadattack: Hard-label black-box textual adversarial attacks via hybrid optimization","volume":"178","author":"Liu","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.eswa.2026.133033_bib0026","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.114361","article-title":"Advancing text adversarial example generation using large language models","volume":"329","author":"Madrue\u00f1o","year":"2025","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.eswa.2026.133033_bib0027","series-title":"International conference on information, intelligence, systems & applications","first-page":"1","article-title":"Comparative analysis of movie recommendation systems using filtering techniques on IMDB and rotten tomatoes","author":"Majhi","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0028","series-title":"Proceedings of the 61st annual meeting of the association for computational linguistics (volume 1: Long papers)","first-page":"5145","article-title":"Randomized smoothing with masked inference for adversarially robust text classifications","author":"Moon","year":"2023"},{"issue":"4","key":"10.1016\/j.eswa.2026.133033_bib0029","doi-asserted-by":"crossref","first-page":"1101","DOI":"10.1007\/s10115-022-01652-1","article-title":"Chinese adversarial examples generation approach with multi-strategy based on semantic","volume":"64","author":"Ou","year":"2022","journal-title":"Knowledge and Information Systems"},{"key":"10.1016\/j.eswa.2026.133033_bib0030","series-title":"Annual meeting of the association for computational linguistics","first-page":"5582","article-title":"Combating adversarial misspellings with robust word recognition","author":"Pruthi","year":"2019"},{"key":"10.1016\/j.eswa.2026.133033_bib0031","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113569","article-title":"Fairness and social bias quantification in large language models for sentiment analysis","volume":"319","author":"Radaideh","year":"2025","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.eswa.2026.133033_bib0032","series-title":"Annual meeting of the association for computational linguistics","first-page":"1085","article-title":"Generating natural language adversarial examples through probability weighted word saliency","author":"Ren","year":"2019"},{"key":"10.1016\/j.eswa.2026.133033_bib0033","series-title":"Working notes of the conference and labs of the evaluation forum","first-page":"580","article-title":"MMU NLP at checkthat! 2024: Homoglyphs are adversarial attacks","volume":"vol. 3740","author":"Roadhouse","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0034","series-title":"Conference of the north american chapter of the association for computational linguistics: Human language technologies (volume 1: Long papers)","first-page":"719","article-title":"VertAttack: Taking advantage of text classifiers\u2019 horizontal vision","author":"Rusert","year":"2024"},{"issue":"5","key":"10.1016\/j.eswa.2026.133033_bib0035","doi-asserted-by":"crossref","first-page":"1189","DOI":"10.3233\/IDA-230332","article-title":"A dual-ways feature fusion mechanism enhancing active learning based on textCNN","volume":"28","author":"Shi","year":"2024","journal-title":"Intelligent Data Analysis"},{"key":"10.1016\/j.eswa.2026.133033_bib0036","series-title":"Working notes of the conference and labs of the evaluation forum","first-page":"658","article-title":"SINAI at checkthat! 2024: Stealthy character-level adversarial attacks using homoglyphs and iterative search","volume":"vol. 3740","author":"Valle-Aguilera","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0037","series-title":"Proceedings of the 2024 conference on empirical methods in natural language processing","first-page":"4553","article-title":"Adaptive immune-based sound-shape code substitution for adversarial Chinese text attacks","author":"Wang","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0038","first-page":"1","article-title":"Virtual gyros construction and evaluation method based on BILSTM","volume":"71","author":"Wang","year":"2022","journal-title":"IEEE Transactions on Instrumentation and Measurement"},{"key":"10.1016\/j.eswa.2026.133033_bib0039","series-title":"Advances in neural information processing systems 36: Annual conference on neural information processing systems","first-page":"1","article-title":"Punctuation-level attack: Single-shot and single punctuation can fool text models","author":"Wang","year":"2023"},{"key":"10.1016\/j.eswa.2026.133033_bib0040","series-title":"27th international conference on computer supported cooperative work in design","first-page":"1716","article-title":"Generating valid and natural adversarial examples with large language models","author":"Wang","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0041","series-title":"Joint international conference on computational linguistics, language resources and evaluation (LREC-COLING 2024)","first-page":"16907","article-title":"Typos correction training against misspellings from text-to-text transformers","author":"Xie","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0042","series-title":"The twelfth international conference on learning representations","first-page":"1","article-title":"An LLM can fool itself: A prompt-based adversarial attack","author":"Xu","year":"2024"},{"key":"10.1016\/j.eswa.2026.133033_bib0043","series-title":"Proceedings of the 2021 conference of the north american chapter of the association for computational linguistics: Human language technologies","first-page":"4078","article-title":"Grey-box adversarial attack and defence for sentiment classification","author":"Xu","year":"2021"},{"key":"10.1016\/j.eswa.2026.133033_bib0044","series-title":"Proceedings of the 29th ACM SIGKDD conference on knowledge discovery and data mining","first-page":"3093","article-title":"PAT: Geometry-aware hard-label black-box adversarial attacks on text","author":"Ye","year":"2023"},{"key":"10.1016\/j.eswa.2026.133033_bib0045","series-title":"KDD \u201922: The 28th ACM SIGKDD conference on knowledge discovery and data mining","first-page":"2307","article-title":"Leapattack: Hard-label adversarial attack on text via gradient-based optimization","author":"Ye","year":"2022"},{"key":"10.1016\/j.eswa.2026.133033_bib0046","series-title":"Proceedings of the 58th annual meeting of the association for computational linguistics","first-page":"3465","article-title":"SAFER: A structure-free approach for certified robustness to adversarial word substitutions","author":"Ye","year":"2020"},{"key":"10.1016\/j.eswa.2026.133033_bib0047","doi-asserted-by":"crossref","first-page":"105605","DOI":"10.1109\/ACCESS.2024.3435573","article-title":"IAE: Irony-based adversarial examples for sentiment analysis systems","volume":"12","author":"Yi","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.eswa.2026.133033_bib0048","series-title":"Proceedings of the 58th annual meeting of the association for computational linguistics","first-page":"6066","article-title":"Word-level textual adversarial attacking as combinatorial optimization","author":"Zang","year":"2020"},{"key":"10.1016\/j.eswa.2026.133033_bib0049","series-title":"Proceedings of the 61st annual meeting of the association for computational linguistics (volume 1: Long papers)","first-page":"6493","article-title":"Contrastive learning with adversarial examples for alleviating pathology of language model","author":"Zhan","year":"2023"},{"key":"10.1016\/j.eswa.2026.133033_bib0050","series-title":"Proceedings of the 57th annual meeting of the association for computational linguistics","first-page":"5564","article-title":"Generating fluent adversarial examples for natural languages","author":"Zhang","year":"2019"},{"key":"10.1016\/j.eswa.2026.133033_bib0051","series-title":"Findings of the association for computational linguistics: EMNLP 2022","first-page":"3502","article-title":"RoChBert: Towards robust BERT fine-tuning for Chinese","author":"Zhang","year":"2022"},{"key":"10.1016\/j.eswa.2026.133033_bib0052","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.127429","article-title":"Research on constructing and reasoning the collision knowledge graph of autonomous navigation ship based on enhanced BERT model","volume":"278","author":"Zhang","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.133033_bib0053","doi-asserted-by":"crossref","first-page":"1462","DOI":"10.1109\/TIFS.2025.3526067","article-title":"Enhancing the transferability of adversarial attacks via multi-feature attention","volume":"20","author":"Zheng","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.133033_bib0054","series-title":"Proceedings of the 2019 conference on empirical methods in natural language processing and the 9th international joint conference on natural language processing","first-page":"4904","article-title":"Learning to discriminate perturbations for blocking adversarial attacks in text classification","author":"Zhou","year":"2019"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426019445?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426019445?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T07:05:35Z","timestamp":1780470335000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426019445"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,12]]},"references-count":54,"alternative-id":["S0957417426019445"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.133033","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,12]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Multi-hop semantic association-based adversarial attack and defense method for natural language processing systems","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.133033","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"133033"}}