{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T16:17:53Z","timestamp":1778948273490,"version":"3.51.4"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2022YFB3102100"],"award-info":[{"award-number":["2022YFB3102100"]}]},{"name":"NSFC-Yeqisun Science Foundation","award":["U244120033"],"award-info":[{"award-number":["U244120033"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24A20336"],"award-info":[{"award-number":["U24A20336"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402425"],"award-info":[{"award-number":["62402425"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402418"],"award-info":[{"award-number":["62402418"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2024M762829"],"award-info":[{"award-number":["2024M762829"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LD24F020002"],"award-info":[{"award-number":["LD24F020002"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Zhejiang Provincial Priority- Funded Postdoctoral Research","award":["ZJ2024001"],"award-info":[{"award-number":["ZJ2024001"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tdsc.2025.3551162","type":"journal-article","created":{"date-parts":[[2025,3,14]],"date-time":"2025-03-14T14:02:47Z","timestamp":1741960967000},"page":"4671-4684","source":"Crossref","is-referenced-by-count":1,"title":["TextDefense: Adversarial Text Detection Based on Word Importance Score Dispersion"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7685-469X","authenticated-orcid":false,"given":"Lujia","family":"Shen","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2311-4943","authenticated-orcid":false,"given":"Yuwen","family":"Pu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8571-9780","authenticated-orcid":false,"given":"Xuhong","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Software Technology, Zhejiang University, Ningbo, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9274-7325","authenticated-orcid":false,"given":"Chunpeng","family":"Ge","sequence":"additional","affiliation":[{"name":"Joint SDU-NTU Centre for Artificial Intelligence Research (C-FAIR) &#x0026; Software School, Shandong University, Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8824-1356","authenticated-orcid":false,"given":"Xing","family":"Yang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Pulsed Power Laser Technology, National University of Defense Technology, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0586-7132","authenticated-orcid":false,"given":"Hao","family":"Peng","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Zhejiang Normal University, Jinhua, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5974-1589","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation, Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/d18-1316"},{"key":"ref2","first-page":"1","article-title":"Adversarial training and provable defenses: Bridging the gap","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Balunovic"},{"key":"ref3","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen"},{"key":"ref4","first-page":"4171","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","volume-title":"Proc. Conf. North Amer. Chapter Assoc. Comput. Linguistics-Hum. Lang. Technol.","author":"Devlin"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484538"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN52387.2021.9533725"},{"key":"ref7","first-page":"201","article-title":"Why does unsupervised pre-training help deep learning","volume-title":"Proc. 13th Int. Conf. Artif. Intell. Statist.","author":"Erhan"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16904"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v12i1.14991"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.498"},{"key":"ref12","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref13","article-title":"DeBERTa: Decoding-enhanced BERT with disentangled attention","author":"He","year":"2020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.inlg-1.14"},{"key":"ref17","first-page":"3468","article-title":"POPQORN: Quantifying robustness of recurrent neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ko"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/385"},{"issue":"3","key":"ref19","doi-asserted-by":"crossref","DOI":"10.3390\/sym13030428","article-title":"Diversity adversarial training against adversarial attack on deep neural networks","volume":"13","author":"Kwon","year":"2021","journal-title":"Symmetry"},{"key":"ref20","article-title":"ALBERT: A lite BERT for self-supervised learning of language representations","author":"Lan","year":"2019"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1525\/9780520940420-020"},{"key":"ref22","first-page":"1381","article-title":"TextShield: Robust text classification based on multimodal embedding and neural machine translation","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Li"},{"key":"ref23","first-page":"1","article-title":"TextBugger: Generating adversarial text against real-world applications","volume-title":"Proc. 26th Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Li"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.500"},{"key":"ref25","article-title":"RoBERTa: A robustly optimized BERT pretraining approach","author":"Liu","year":"2019"},{"key":"ref26","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Madry"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.eacl-main.13"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2016.7795300"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1561"},{"issue":"140","key":"ref30","first-page":"1","article-title":"Exploring the limits of transfer learning with a unified text-to-text transformer","volume":"21","author":"Raffel","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2012.6289079"},{"key":"ref33","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tram\u00e8r"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3117608"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-55393-7_28"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00290"},{"key":"ref37","first-page":"5518","article-title":"LexicalAT: Lexical-based adversarial reinforcement training for robust sentiment classification","volume-title":"Proc. Conf. Empirical Methods Natural Lang. Process.-9th Int. Joint Conf. Natural Lang. Process.","author":"Xu"},{"key":"ref38","first-page":"5753","article-title":"XLNet: Generalized autoregressive pretraining for language understanding","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Yang"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-021-02800-w"},{"key":"ref40","first-page":"945","article-title":"Towards improving adversarial training of NLP models","volume-title":"Proc. Assoc. Comput. Linguistics","author":"Yoo"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.426"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1496"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11150357\/10924677.pdf?arnumber=10924677","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T22:52:04Z","timestamp":1757371924000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10924677\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":42,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3551162","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}