{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:20:27Z","timestamp":1778498427386,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":28,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819203741","type":"print"},{"value":"9789819203758","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-92-0375-8_28","type":"book-chapter","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:55:45Z","timestamp":1778496945000},"page":"462-477","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["WISP: A Stealthy Word-Level Backdoor Attack via\u00a0Semantic Influence and\u00a0LLM-Guided Injection"],"prefix":"10.1007","author":[{"given":"Zhaoxi","family":"Feng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhengshuo","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhengxian","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Juan","family":"Wen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,12]]},"reference":[{"key":"28_CR1","unstructured":"Languagetool: Open-source grammar, style and spell checker. https:\/\/languagetool.org\/"},{"key":"28_CR2","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1016\/j.neucom.2021.04.105","volume":"452","author":"C Chen","year":"2021","unstructured":"Chen, C., Dai, J.: Mitigating backdoor attacks in LSTM-based text classification systems by backdoor keyword identification. Neurocomputing 452, 253\u2013262 (2021)","journal-title":"Neurocomputing"},{"key":"28_CR3","doi-asserted-by":"publisher","unstructured":"Chen, X., Dong, Y., Sun, Z., Zhai, S., Shen, Q., Wu, Z.: Kallima: a clean-label framework for textual backdoor attacks. In: Atluri, V., Di Pietro, R., Jensen, C.D., Meng, W. (eds.) ESORICS 2022, pp. 447\u2013466. Springer (2022). https:\/\/doi.org\/10.1007\/978-3-031-17140-6_22","DOI":"10.1007\/978-3-031-17140-6_22"},{"key":"28_CR4","doi-asserted-by":"publisher","unstructured":"Chen, X., et al.: BadNL: backdoor attacks against NLP models with semantic-preserving improvements. In: Proceedings of the 37th Annual Computer Security Applications Conference. pp. 554\u2013569. Association for Computing Machinery (2021). https:\/\/doi.org\/10.1145\/3485832.3485837","DOI":"10.1145\/3485832.3485837"},{"key":"28_CR5","doi-asserted-by":"crossref","unstructured":"Cui, G., Yuan, L., He, B., Chen, Y., Liu, Z., Sun, M.: A unified evaluation of textual backdoor learning: Frameworks and benchmarks. In: Advances in Neural Information Processing Systems. vol.\u00a035, pp. 5009\u20135023. Curran Associates, Inc. (2022)","DOI":"10.52202\/068431-0362"},{"key":"28_CR6","doi-asserted-by":"publisher","first-page":"138872","DOI":"10.1109\/ACCESS.2019.2941376","volume":"7","author":"J Dai","year":"2019","unstructured":"Dai, J., Chen, C., Li, Y.: A backdoor attack against LSTM-based text classification systems. IEEE Access 7, 138872\u2013138878 (2019)","journal-title":"IEEE Access"},{"key":"28_CR7","unstructured":"Devlin, J., Chang, M.W., Lee, K., Toutanova, K.: BERT: pre-training of deep bidirectional transformers for language understanding. In: Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers). pp. 4171\u20134186. Association for Computational Linguistics (2019)"},{"issue":"4","key":"28_CR8","doi-asserted-by":"publisher","first-page":"2349","DOI":"10.1109\/TDSC.2021.3055844","volume":"19","author":"Y Gao","year":"2022","unstructured":"Gao, Y., et al.: Design and evaluation of a multi-domain trojan detection method on deep neural networks. IEEE Trans. Dependable Secure Comput. 19(4), 2349\u20132364 (2022)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"28_CR9","doi-asserted-by":"crossref","unstructured":"Gardner, M., et al.: Competency problems: on finding and removing artifacts in language data. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp. 1801\u20131813. Association for Computational Linguistics (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.135"},{"key":"28_CR10","doi-asserted-by":"crossref","unstructured":"de\u00a0Gibert, O., Perez, N., Garc\u00eda-Pablos, A., Cuadros, M.: Hate speech dataset from a white supremacy forum. In: Proceedings of the 2nd Workshop on Abusive Language Online (ALW2), pp. 11\u201320. Association for Computational Linguistics (2018)","DOI":"10.18653\/v1\/W18-5102"},{"key":"28_CR11","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: Badnets: identifying vulnerabilities in the machine learning model supply chain (2017). neurIPS 2017 Machine Learning & Security Workshop \u2013 Best Attack Paper"},{"key":"28_CR12","doi-asserted-by":"crossref","unstructured":"Hovy, E., Gerber, L., Hermjakob, U., Lin, C.Y., Ravichandran, D.: Toward semantics-based answer pinpointing. In: Proceedings of the First International Conference on Human Language Technology Research (2001)","DOI":"10.3115\/1072133.1072221"},{"key":"28_CR13","doi-asserted-by":"crossref","unstructured":"Kurita, K., Michel, P., Neubig, G.: Weight poisoning attacks on pretrained models. In: Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics, pp. 2793\u20132806. Association for Computational Linguistics (2020)","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"28_CR14","doi-asserted-by":"crossref","unstructured":"Li, L., Song, D., Li, X., Zeng, J., Ma, R., Qiu, X.: Backdoor attacks on pre-trained models by layerwise weight poisoning. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp. 3023\u20133032. Association for Computational Linguistics (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.241"},{"key":"28_CR15","doi-asserted-by":"publisher","unstructured":"Li, S., et al.: Hidden backdoors in human-centric language models. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 3123\u20133140. Association for Computing Machinery (2021). https:\/\/doi.org\/10.1145\/3460120.3484576","DOI":"10.1145\/3460120.3484576"},{"issue":"1","key":"28_CR16","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/TNNLS.2022.3182979","volume":"35","author":"Y Li","year":"2024","unstructured":"Li, Y., Jiang, Y., Li, Z., Xia, S.T.: Backdoor learning: a survey. IEEE Trans. Neural Networks Learn. Syst. 35(1), 5\u201322 (2024)","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Mohammad, S., Bravo-Marquez, F., Salameh, M., Kiritchenko, S.: SemEval-2018 task 1: affect in tweets. In: Proceedings of the 12th International Workshop on Semantic Evaluation. pp. 1\u201317. Association for Computational Linguistics (2018)","DOI":"10.18653\/v1\/S18-1001"},{"key":"28_CR18","doi-asserted-by":"crossref","unstructured":"Qi, F., Chen, Y., Li, M., Yao, Y., Liu, Z., Sun, M.: ONION: a simple and effective defense against textual backdoor attacks. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp. 9558\u20139566. Association for Computational Linguistics (2021). https:\/\/github.com\/thunlp\/ONION","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"28_CR19","doi-asserted-by":"crossref","unstructured":"Qi, F., Chen, Y., Zhang, X., Li, M., Liu, Z., Sun, M.: Mind the style of text! adversarial and backdoor attacks based on text style transfer. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, pp. 4569\u20134580. Association for Computational Linguistics (2021). https:\/\/github.com\/thunlp\/StyleAttack","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"28_CR20","doi-asserted-by":"crossref","unstructured":"Qi, F., Li, M., Chen, Y., Zhang, Z., Liu, Z., Wang, Y., Sun, M.: Hidden killer: Invisible textual backdoor attacks with syntactic trigger. In: Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers), pp. 443\u2013453. Association for Computational Linguistics (2021). https:\/\/github.com\/thunlp\/HiddenKiller","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"28_CR21","doi-asserted-by":"crossref","unstructured":"Qi, F., Yao, Y., Xu, S., Liu, Z., Sun, M.: Turn the combination lock: learnable textual backdoor attacks via word substitution. In: Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers), pp. 4873\u20134883. Association for Computational Linguistics (2021). https:\/\/github.com\/thunlp\/BkdAtk-LWS","DOI":"10.18653\/v1\/2021.acl-long.377"},{"key":"28_CR22","unstructured":"Radford, A., Wu, J., Child, R., Luan, D., Amodei, D., Sutskever, I.: Language models are unsupervised multitask learners. OpenAI Technical Report (2019)"},{"key":"28_CR23","doi-asserted-by":"crossref","unstructured":"Schmidt, A., Wiegand, M.: A survey on hate speech detection using natural language processing. In: Proceedings of the Fifth International Workshop on Natural Language Processing for Social Media, pp. 1\u201310. Association for Computational Linguistics (2017)","DOI":"10.18653\/v1\/W17-1101"},{"key":"28_CR24","doi-asserted-by":"crossref","unstructured":"Socher, R., et al.: Recursive deep models for semantic compositionality over a sentiment treebank. In: Proceedings of the 2013 Conference on Empirical Methods in Natural Language Processing, pp. 1631\u20131642. Association for Computational Linguistics (2013)","DOI":"10.18653\/v1\/D13-1170"},{"key":"28_CR25","doi-asserted-by":"crossref","unstructured":"Yan, J., Gupta, V., Ren, X.: BITE: Textual backdoor attacks with iterative trigger injection. In: Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pp. 12951\u201312968. Association for Computational Linguistics (2023)","DOI":"10.18653\/v1\/2023.acl-long.725"},{"key":"28_CR26","doi-asserted-by":"crossref","unstructured":"Yang, W., Li, L., Zhang, Z., Ren, X., Sun, X., He, B.: Be careful about poisoned word embeddings: exploring the vulnerability of the embedding layers in NLP models. In: Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, pp. 2048\u20132058. Association for Computational Linguistics (2021). https:\/\/github.com\/lancopku\/Embedding-Poisoning","DOI":"10.18653\/v1\/2021.naacl-main.165"},{"key":"28_CR27","doi-asserted-by":"crossref","unstructured":"Yang, W., Lin, Y., Li, P., Zhou, J., Sun, X.: Rethinking stealthiness of backdoor attack against NLP models. In: Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers), pp. 5543\u20135557. Association for Computational Linguistics (2021). https:\/\/github.com\/lancopku\/SOS","DOI":"10.18653\/v1\/2021.acl-long.431"},{"key":"28_CR28","doi-asserted-by":"crossref","unstructured":"Zhang, X., Zhang, Z., Ji, S., Wang, T.: Trojaning language models for fun and profit. In: 2021 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 179\u2013197 (2021)","DOI":"10.1109\/EuroSP51992.2021.00022"}],"container-title":["Lecture Notes in Computer Science","Database Systems for Advanced Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-0375-8_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:55:58Z","timestamp":1778496958000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-0375-8_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819203741","9789819203758"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-0375-8_28","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"12 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"DASFAA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Database Systems for Advanced Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jeju","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 April 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dasfaa2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dasfaa2026.github.io\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}