{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,20]],"date-time":"2026-04-20T10:18:53Z","timestamp":1776680333182,"version":"3.51.2"},"publisher-location":"Singapore","reference-count":16,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819570775","type":"print"},{"value":"9789819570782","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-7078-2_47","type":"book-chapter","created":{"date-parts":[[2026,4,20]],"date-time":"2026-04-20T09:32:48Z","timestamp":1776677568000},"page":"674-681","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["FATS: A Prompt Injection Attack Utilizing Feign Security Agents with\u00a0Deceptive Few-Shots Learning"],"prefix":"10.1007","author":[{"given":"Yupeng","family":"Ren","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiangtao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,4,21]]},"reference":[{"key":"47_CR1","unstructured":"Hurst, A., et al.: GPT-4o system card. arXiv preprint arXiv:2410.21276 (2024)"},{"key":"47_CR2","unstructured":"Liu, A., et al.: Deepseek-v3 technical report. arXiv preprint arXiv:2412.19437 (2024)"},{"key":"47_CR3","unstructured":"Liu, Y., Jia, Y., Geng, R., Jia, J., Gong, N.Z.: Formalizing and benchmarking prompt injection attacks and defenses. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 1831\u20131847. USENIX Association, Philadelphia, PA (2024)"},{"issue":"7","key":"47_CR4","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1007\/s10462-024-10824-0","volume":"57","author":"X Huang","year":"2024","unstructured":"Huang, X., et al.: A survey of safety and trustworthiness of large language models through the lens of verification and validation. Artif. Intell. Rev. 57(7), 175 (2024)","journal-title":"Artif. Intell. Rev."},{"key":"47_CR5","doi-asserted-by":"crossref","unstructured":"Tony, C., Mutas, M., D\u00edaz Ferreyra, N.E., Scandariato, R.: LLMSecEval: a dataset of natural language prompts for security evaluations. In: 2023 IEEE\/ACM 20th International Conference on Mining Software Repositories (MSR), pp. 588\u2013592 (2023)","DOI":"10.1109\/MSR59073.2023.00084"},{"key":"47_CR6","doi-asserted-by":"crossref","unstructured":"Kavian, A., Pourhashem Kallehbasti, M.M., Kazemi, S., Firouzi, E., Ghafari, M.: LLM security guard for code. In: Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering, pp. 600\u2013603. Association for Computing Machinery, New York, NY, USA (2024)","DOI":"10.1145\/3661167.3661263"},{"key":"47_CR7","doi-asserted-by":"crossref","unstructured":"Han, S., et al.: FedSecurity: a benchmark for attacks and defenses in federated learning and federated LLMs. In: Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 5070\u20135081. Association for Computing Machinery, New York, NY, USA (2024)","DOI":"10.1145\/3637528.3671545"},{"key":"47_CR8","doi-asserted-by":"crossref","unstructured":"Kruschwitz, U., Schmidhuber, M.: LLM-Based synthetic datasets: applications and limitations in toxicity detection. In: Kumar, R., et al. (eds.) Proceedings of the Fourth Workshop on Threat, Aggression & Cyberbullying @ LREC-COLING-2024, pp. 37\u201351. ELRA and ICCL, Torino, Italia (2024)","DOI":"10.63317\/4e9jwkpywvi7"},{"key":"47_CR9","doi-asserted-by":"crossref","unstructured":"Chen, Y., et al.: Why should adversarial perturbations be imperceptible$$?$$ rethink the research paradigm in adversarial NLP. In: Goldberg, Y., Kozareva, Z., Zhang, Y. (eds.) Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing, pp. 11222\u201311237. Association for Computational Linguistics, Abu Dhabi, United Arab Emirates (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.771"},{"key":"47_CR10","doi-asserted-by":"publisher","first-page":"11437","DOI":"10.18653\/v1\/2024.findings-acl.679","volume-title":"Findings of the Association for Computational Linguistics: ACL 2024","author":"Q Ren","year":"2024","unstructured":"Ren, Q., et al.: CodeAttack: revealing safety generalization challenges of large language models via code completion. In: Ku, L.W., Martins, A., Srikumar, V. (eds.) Findings of the Association for Computational Linguistics: ACL 2024, pp. 11437\u201311452. Association for Computational Linguistics, Bangkok, Thailand (2024)"},{"key":"47_CR11","doi-asserted-by":"crossref","unstructured":"Rababah, B., Wu, S.T., Kwiatkowski, M., Leung, C.K., Akcora, C.G.: SOK: prompt hacking of large language models. In: 2024 IEEE International Conference on Big Data (BigData), pp. 5392\u20135401 (2024)","DOI":"10.1109\/BigData62323.2024.10825103"},{"key":"47_CR12","doi-asserted-by":"crossref","unstructured":"Pasquini, D., Strohmeier, M., Troncoso, C.: Neural exec: learning (and learning from) execution triggers for prompt injection attacks. In: Proceedings of the 2024 Workshop on Artificial Intelligence and Security, pp. 89\u2013100. Association for Computing Machinery, New York, NY, USA (2024)","DOI":"10.1145\/3689932.3694764"},{"key":"47_CR13","doi-asserted-by":"crossref","unstructured":"Shi, J., et al.: Optimization-based prompt injection attack to LLM-as-a-judge. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, pp. 660\u2013674. Association for Computing Machinery, New York, NY, USA (2024)","DOI":"10.1145\/3658644.3690291"},{"key":"47_CR14","doi-asserted-by":"publisher","first-page":"13111","DOI":"10.18653\/v1\/2024.findings-acl.776","volume-title":"Findings of the Association for Computational Linguistics: ACL 2024","author":"N Varshney","year":"2024","unstructured":"Varshney, N., Dolin, P., Seth, A., Baral, C.: The art of defending: a systematic evaluation and analysis of LLm defense strategies on safety and over-defensiveness. In: Ku, L.W., Martins, A., Srikumar, V. (eds.) Findings of the Association for Computational Linguistics: ACL 2024, pp. 13111\u201313128. Association for Computational Linguistics, Bangkok, Thailand (2024)"},{"key":"47_CR15","unstructured":"Mazeika, M., et al.: HarmBench: a standardized evaluation framework for automated red teaming and robust refusal. In: Proceedings of the 41st International Conference on Machine Learning, vol. 1431. JMLR.org, Vienna, Austria (2024)"},{"key":"47_CR16","unstructured":"Rahman, S., et al.: X-Teaming: multi-turn jailbreaks and defenses with adaptive multi-agents. arXiv preprint arXiv:2504.13203 (2025)"}],"container-title":["Lecture Notes in Computer Science","PRICAI 2025: Trends in Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-7078-2_47","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,20]],"date-time":"2026-04-20T09:33:01Z","timestamp":1776677581000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-7078-2_47"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819570775","9789819570782"],"references-count":16,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-7078-2_47","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"21 April 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"PRICAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Pacific Rim International Conference on Artificial Intelligence","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Wellington","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"New Zealand","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 November 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 November 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"pricai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.pricai.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}