Defending against backdoor attacks in natural language generation