{"id":"https://openalex.org/W4412176752","doi":"https://doi.org/10.1007/s40747-025-02006-4","title":"BDEKD: mitigating backdoor attacks in NLP models via ensemble knowledge distillation","display_name":"BDEKD: mitigating backdoor attacks in NLP models via ensemble knowledge distillation","publication_year":2025,"publication_date":"2025-07-09","ids":{"openalex":"https://openalex.org/W4412176752","doi":"https://doi.org/10.1007/s40747-025-02006-4"},"language":"en","primary_location":{"id":"doi:10.1007/s40747-025-02006-4","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s40747-025-02006-4","pdf_url":"https://link.springer.com/content/pdf/10.1007/s40747-025-02006-4.pdf","source":{"id":"https://openalex.org/S3035462843","display_name":"Complex & Intelligent Systems","issn_l":"2198-6053","issn":["2198-6053","2199-4536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Complex &amp; Intelligent Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://link.springer.com/content/pdf/10.1007/s40747-025-02006-4.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100673890","display_name":"Zijie Zhang","orcid":"https://orcid.org/0000-0003-1254-098X"},"institutions":[{"id":"https://openalex.org/I76569877","display_name":"Southeast University","ror":"https://ror.org/04ct4d772","country_code":"CN","type":"education","lineage":["https://openalex.org/I76569877"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zijie Zhang","raw_affiliation_strings":["Southeast University, No. 2, Southeast University Road, Nanjing, 211189, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Southeast University, No. 2, Southeast University Road, Nanjing, 211189, Jiangsu, China","institution_ids":["https://openalex.org/I76569877"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069470666","display_name":"Xinyuan Miao","orcid":"https://orcid.org/0000-0001-5730-9330"},"institutions":[{"id":"https://openalex.org/I4210155350","display_name":"Purple Mountain Laboratories","ror":"https://ror.org/04zcbk583","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210155350"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xinyuan Miao","raw_affiliation_strings":["Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China","institution_ids":["https://openalex.org/I4210155350"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017920487","display_name":"Chenyu Zhou","orcid":"https://orcid.org/0000-0002-9830-1199"},"institutions":[{"id":"https://openalex.org/I76569877","display_name":"Southeast University","ror":"https://ror.org/04ct4d772","country_code":"CN","type":"education","lineage":["https://openalex.org/I76569877"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chenyu Zhou","raw_affiliation_strings":["Southeast University, No. 2, Southeast University Road, Nanjing, 211189, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Southeast University, No. 2, Southeast University Road, Nanjing, 211189, Jiangsu, China","institution_ids":["https://openalex.org/I76569877"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023899239","display_name":"Chenming Shang","orcid":null},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chenming Shang","raw_affiliation_strings":["Tsinghua University, FIT Building, Shuangqing Road, Beijing, 100084, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua University, FIT Building, Shuangqing Road, Beijing, 100084, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100716241","display_name":"Xi Chen","orcid":"https://orcid.org/0000-0003-2799-1724"},"institutions":[{"id":"https://openalex.org/I4210155350","display_name":"Purple Mountain Laboratories","ror":"https://ror.org/04zcbk583","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210155350"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xi Chen","raw_affiliation_strings":["Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China","institution_ids":["https://openalex.org/I4210155350"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011947851","display_name":"Xianglong Kong","orcid":"https://orcid.org/0000-0002-2448-2214"},"institutions":[{"id":"https://openalex.org/I4210155350","display_name":"Purple Mountain Laboratories","ror":"https://ror.org/04zcbk583","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210155350"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xianglong Kong","raw_affiliation_strings":["Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China","institution_ids":["https://openalex.org/I4210155350"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041966731","display_name":"Wei Huang","orcid":"https://orcid.org/0000-0002-0844-4680"},"institutions":[{"id":"https://openalex.org/I4210155350","display_name":"Purple Mountain Laboratories","ror":"https://ror.org/04zcbk583","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210155350"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wei Huang","raw_affiliation_strings":["Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China","institution_ids":["https://openalex.org/I4210155350"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001797522","display_name":"Yi Cao","orcid":"https://orcid.org/0000-0002-2131-5453"},"institutions":[{"id":"https://openalex.org/I4210155350","display_name":"Purple Mountain Laboratories","ror":"https://ror.org/04zcbk583","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210155350"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yi Cao","raw_affiliation_strings":["Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China"],"affiliations":[{"raw_affiliation_string":"Purple Mountain Laboratories, No. 9, Mozhou East Road, Nanjing, 211111, Jiangsu, China","institution_ids":["https://openalex.org/I4210155350"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5069470666"],"corresponding_institution_ids":["https://openalex.org/I4210155350"],"apc_list":{"value":1320,"currency":"GBP","value_usd":1619},"apc_paid":{"value":1320,"currency":"GBP","value_usd":1619},"fwci":2.5914,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.90759188,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":"11","issue":"9","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9836999773979187,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9726999998092651,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.957801103591919},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.618276834487915},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5917739272117615},{"id":"https://openalex.org/keywords/computational-intelligence","display_name":"Computational intelligence","score":0.5276236534118652},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4764557182788849},{"id":"https://openalex.org/keywords/ensemble-learning","display_name":"Ensemble learning","score":0.42367759346961975},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.37957262992858887},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.08426681160926819}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.957801103591919},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.618276834487915},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5917739272117615},{"id":"https://openalex.org/C139502532","wikidata":"https://www.wikidata.org/wiki/Q1122090","display_name":"Computational intelligence","level":2,"score":0.5276236534118652},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4764557182788849},{"id":"https://openalex.org/C45942800","wikidata":"https://www.wikidata.org/wiki/Q245652","display_name":"Ensemble learning","level":2,"score":0.42367759346961975},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.37957262992858887},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.08426681160926819}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/s40747-025-02006-4","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s40747-025-02006-4","pdf_url":"https://link.springer.com/content/pdf/10.1007/s40747-025-02006-4.pdf","source":{"id":"https://openalex.org/S3035462843","display_name":"Complex & Intelligent Systems","issn_l":"2198-6053","issn":["2198-6053","2199-4536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Complex &amp; Intelligent Systems","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:87f0d5aef0d64402b5a78ed866c9cb2b","is_oa":true,"landing_page_url":"https://doaj.org/article/87f0d5aef0d64402b5a78ed866c9cb2b","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Complex & Intelligent Systems, Vol 11, Iss 9, Pp 1-17 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1007/s40747-025-02006-4","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s40747-025-02006-4","pdf_url":"https://link.springer.com/content/pdf/10.1007/s40747-025-02006-4.pdf","source":{"id":"https://openalex.org/S3035462843","display_name":"Complex & Intelligent Systems","issn_l":"2198-6053","issn":["2198-6053","2199-4536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Complex &amp; Intelligent Systems","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G7899452283","display_name":null,"funder_award_id":"ZL042401","funder_id":"https://openalex.org/F4320325437","funder_display_name":"Jiangsu Science and Technology Department"}],"funders":[{"id":"https://openalex.org/F4320325437","display_name":"Jiangsu Science and Technology Department","ror":null}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4412176752.pdf","grobid_xml":"https://content.openalex.org/works/W4412176752.grobid-xml"},"referenced_works_count":55,"referenced_works":["https://openalex.org/W146900863","https://openalex.org/W2064675550","https://openalex.org/W2081580037","https://openalex.org/W2251939518","https://openalex.org/W2282821441","https://openalex.org/W2294370754","https://openalex.org/W2753783305","https://openalex.org/W2765982206","https://openalex.org/W2807363941","https://openalex.org/W2934843808","https://openalex.org/W2956090150","https://openalex.org/W2962977603","https://openalex.org/W2964082701","https://openalex.org/W2970454332","https://openalex.org/W2970561365","https://openalex.org/W2971296908","https://openalex.org/W2973217491","https://openalex.org/W2990270730","https://openalex.org/W2997336365","https://openalex.org/W3035321581","https://openalex.org/W3035367371","https://openalex.org/W3047587361","https://openalex.org/W3100405174","https://openalex.org/W3105966348","https://openalex.org/W3109409894","https://openalex.org/W3158487140","https://openalex.org/W3173596483","https://openalex.org/W3173784240","https://openalex.org/W3176270593","https://openalex.org/W3196832521","https://openalex.org/W3204619801","https://openalex.org/W3205696278","https://openalex.org/W3207360435","https://openalex.org/W4322760473","https://openalex.org/W4383221550","https://openalex.org/W4385164057","https://openalex.org/W4389347867","https://openalex.org/W4390658962","https://openalex.org/W4390871934","https://openalex.org/W4393029126","https://openalex.org/W4393195438","https://openalex.org/W4393241390","https://openalex.org/W4395056497","https://openalex.org/W4401640074","https://openalex.org/W4401862107","https://openalex.org/W4404783038","https://openalex.org/W4405414096","https://openalex.org/W6600020421","https://openalex.org/W6600175266","https://openalex.org/W6600214982","https://openalex.org/W6600605178","https://openalex.org/W6600757733","https://openalex.org/W6604186633","https://openalex.org/W6604305821","https://openalex.org/W6628082049"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4376643315","https://openalex.org/W4324137541","https://openalex.org/W2900445707","https://openalex.org/W4285741730","https://openalex.org/W1191482210","https://openalex.org/W4285046548"],"abstract_inverted_index":{"Backdoor":[0,45],"attacks":[1,144],"present":[2],"significant":[3],"risks":[4],"to":[5,52,86,122,145],"the":[6,17,22,29,65,88,107,113,124,127,137,153,159],"security":[7],"of":[8,56,68,83,106,115,140,152],"deep":[9],"neural":[10],"networks":[11],"(DNNs)":[12],"in":[13,58,71],"NLP":[14],"domain,":[15],"as":[16,64],"attackers":[18],"can":[19],"covertly":[20],"manipulate":[21],"model\u2019s":[23,34,160],"output":[24],"behavior":[25],"either":[26],"by":[27,103],"poisoning":[28],"training":[30,35,108,154],"data":[31,85,109,164],"or":[32],"tampering":[33],"process.":[36],"This":[37,99],"paper":[38],"introduces":[39],"a":[40,80],"novel":[41],"backdoor":[42,73,125,143],"defence":[43],"strategy,":[44],"Defense":[46],"via":[47],"Ensemble":[48],"Knowledge":[49],"Distillation":[50],"(BDEKD),":[51],"mitigate":[53,123],"various":[54],"types":[55],"backdoors":[57],"compromised":[59,89],"DNNs.":[60],"It":[61],"is":[62,101,176],"marked":[63],"first":[66],"utilization":[67],"ensemble":[69,117],"methods":[70],"enhancing":[72],"mitigation.":[74],"The":[75],"BDEKD":[76,134],"framework":[77],"only":[78,149],"requires":[79],"minimal":[81,168],"subset":[82],"clean":[84,87,163],"model,":[90],"generating":[91],"several":[92],"relatively":[93],"heterogeneous":[94],"and":[95,112],"backdoor-cleaned":[96],"teacher":[97],"models.":[98],"process":[100],"followed":[102],"an":[104,116],"enhancement":[105],"through":[110],"augmentation,":[111],"implementation":[114],"distillation":[118],"technique":[119],"specifically":[120],"designed":[121],"from":[126],"model.":[128],"Our":[129,174],"empirical":[130],"analysis":[131],"demonstrates":[132],"that":[133],"effectively":[135],"lowers":[136],"success":[138],"rate":[139],"six":[141],"sophisticated":[142],"approximately":[146],"17%,":[147],"while":[148],"requiring":[150],"20%":[151],"data.":[155],"Crucially,":[156],"it":[157],"preserves":[158],"accuracy":[161],"on":[162,170],"around":[165],"85%,":[166],"ensuring":[167],"impact":[169],"its":[171],"intended":[172],"functionality.":[173],"code":[175],"available":[177],"at":[178],"https://github.com/quanzhuangdefujinan/BDEKD-Research/tree/BDEKD":[179],".":[180]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-03-23T07:41:27.035349","created_date":"2025-10-10T00:00:00"}
