{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T16:11:45Z","timestamp":1782403905822,"version":"3.54.5"},"reference-count":69,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"DSO","award":["DSOCL23216"],"award-info":[{"award-number":["DSOCL23216"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1109\/tdsc.2026.3662097","type":"journal-article","created":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T20:50:47Z","timestamp":1771879847000},"page":"6620-6634","source":"Crossref","is-referenced-by-count":1,"title":["UniFLE: Uniform Fusion of Multiple LoRA Experts for Backdoor Defense in Large Language Models"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5174-5182","authenticated-orcid":false,"given":"Shuai","family":"Zhao","sequence":"first","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5650-0600","authenticated-orcid":false,"given":"Qika","family":"Lin","sequence":"additional","affiliation":[{"name":"Saw Swee Hock School of Public Health, National University of Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-6966-1512","authenticated-orcid":false,"given":"Yanhao","family":"Jia","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0446-1516","authenticated-orcid":false,"given":"Xinyi","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Education, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuwen","family":"Li","sequence":"additional","affiliation":[{"name":"College of Sciences, Northeastern University, Shenyang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6062-207X","authenticated-orcid":false,"given":"Luu Anh","family":"Tuan","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Introducing GPT-4.1 in the API","year":"2025"},{"key":"ref2","article-title":"Llama 3 model card","year":"2024"},{"key":"ref3","article-title":"Qwen2.5: A party of foundation models","author":"Team","year":"2024"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-025-09422-z"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2024.102795"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2025.3536008"},{"key":"ref7","article-title":"Towards robust evaluation of stem education: Leveraging MLLMs in project-based learning","author":"Jia","year":"2025","journal-title":"IEEE Trans. Affect. Comput."},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.acl-long.502"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TAFFC.2025.3565506"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2025.3558446"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-short.8"},{"key":"ref12","article-title":"LoRA: Low-rank adaptation of large language models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Hu","year":"2021"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-naacl.217"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-acl.255"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3639957"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3548970"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.naacl-main.214"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3354736"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.757"},{"key":"ref20","article-title":"The information bottleneck method","author":"Tishby","year":"2000"},{"key":"ref21","first-page":"876","article-title":"Averaging weights leads to wider optima and better generalization","volume-title":"Proc. 34th Conf. Uncertainty Artif. Intell.","author":"Izmailov","year":"2018"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.findings-emnlp.26"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-emnlp.1253"},{"key":"ref24","first-page":"1","article-title":"A survey of recent backdoor attacks and defenses in large language models","author":"Zhao","year":"2025","journal-title":"Trans. Mach. Learn. Res."},{"key":"ref25","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2941376"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TASLP.2024.3407571"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2025.103376"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.165"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.repl4nlp-1.1"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00161"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230164"},{"key":"ref35","article-title":"BadChain: Backdoor chain-of-thought prompting for large language models","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Xiang","year":"2024"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1361"},{"key":"ref37","first-page":"1849","article-title":"Instruction backdoor attacks against customized $\\lbrace${LLMs$\\rbrace$}","volume-title":"Proc. 33rd USENIX Secur. Symp.","volume":"24","author":"Zhang","year":"2024"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.642"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.317"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.27"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.561"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.450"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/taffc.2025.3631581"},{"key":"ref45","first-page":"17783","article-title":"LoRA+: Efficient low rank adaptation of large models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Hayou","year":"2024"},{"key":"ref46","article-title":"VeRA: Vector-based random matrix adaptation","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Kopiczko","year":"2024"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.994"},{"key":"ref48","first-page":"5530","article-title":"LoRA-drop: Efficient LoRA parameter pruning based on output evaluation","volume-title":"Proc. 31st Int. Conf. Comput. Linguistics","author":"Zhou","year":"2025"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-short.107"},{"key":"ref50","article-title":"Delta-LoRA: Fine-tuning high-rank parameters with the delta of low-rank matrices","author":"Zi","year":"2023"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1817"},{"key":"ref52","first-page":"1086","article-title":"Moderate-fitting as a natural backdoor defender for pre-trained language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Zhu","year":"2022"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ITW.2015.7133169"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/BF02288367"},{"key":"ref55","article-title":"What matters in transformers? Not all attention is needed","author":"He","year":"2024"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014073"},{"key":"ref58","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"28","author":"Zhang","year":"2015"},{"key":"ref59","first-page":"142","article-title":"Learning word vectors for sentiment analysis","volume-title":"Proc. 49th Annu. Meeting Assoc. Comput. Linguistics: Hum. Lang. Technol.","author":"Maas","year":"2011"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.3115\/1219840.1219855"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/3596219"},{"key":"ref62","article-title":"Ape210K: A large-scale and template-rich dataset of math word problems","author":"Zhao","year":"2020"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2020"},{"key":"ref64","article-title":"LoBAM: LoRA-based backdoor attack on model merging","volume-title":"Proc. ICLR Workshop Navigating Addressing Data Problems Found. Models","author":"Yin","year":"2025"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-emnlp.716"},{"key":"ref66","article-title":"BackdoorLLM: A comprehensive benchmark for backdoor attacks on large language models","author":"Li","year":"2024"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.514"},{"issue":"120","key":"ref69","first-page":"1","article-title":"Switch Transformers: Scaling to trillion parameter models with simple and efficient sparsity","volume":"23","author":"Fedus","year":"2022","journal-title":"J. Mach. Learn. Res."}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11517592\/11407462.pdf?arnumber=11407462","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T03:07:58Z","timestamp":1778900878000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11407462\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":69,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2026.3662097","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5]]}}}