{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T03:21:13Z","timestamp":1740108073579,"version":"3.37.3"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T00:00:00Z","timestamp":1732060800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T00:00:00Z","timestamp":1732060800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Guangdong Provincial Key-Area Research and Development Program","award":["2022B0101010005"],"award-info":[{"award-number":["2022B0101010005"]}]},{"name":"Qinghai Provincial Science and Technology Research Program","award":["2021-QY-206"],"award-info":[{"award-number":["2021-QY-206"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62071201"],"award-info":[{"award-number":["62071201"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100021171","name":"Guangdong Basic and Applied Basic Research Foundation","doi-asserted-by":"crossref","award":["2022A1515010119"],"award-info":[{"award-number":["2022A1515010119"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2025,1]]},"DOI":"10.1007\/s00521-024-10669-2","type":"journal-article","created":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T09:48:19Z","timestamp":1732096099000},"page":"1457-1473","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Exploring the vulnerability of black-box adversarial attack on prompt-based learning in language models"],"prefix":"10.1007","volume":"37","author":[{"given":"Zihao","family":"Tan","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qingliang","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenbin","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongjian","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chen","family":"Liang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,20]]},"reference":[{"key":"10669_CR1","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1016\/j.aiopen.2021.08.002","volume":"2","author":"X Han","year":"2021","unstructured":"Han X, Zhang Z, Ding N et al (2021) Pre-trained models: past, present and future. AI Open 2:225\u2013250","journal-title":"AI Open"},{"key":"10669_CR2","doi-asserted-by":"crossref","unstructured":"Kabra A, Liu E, Khanuja S, Cahyawijaya S, et al (2023) Multi-lingual and multi-cultural figurative language understanding. paper presented at findings of the association for computational linguistics: ACL 2023, Toronto, Canada, pp 8269\u20138284","DOI":"10.18653\/v1\/2023.findings-acl.525"},{"key":"10669_CR3","doi-asserted-by":"crossref","unstructured":"Yuan H, Yuan Z, Yu S (2022) Generative biomedical entity linking via knowledge base-guided pre-training and synonyms-aware fine-tuning. Paper presented at proceedings of the 2022 conference of the North American Chapter of the association for computational linguistics: human language technologies, Seattle, United States, pp 4038\u20134048","DOI":"10.18653\/v1\/2022.naacl-main.296"},{"key":"10669_CR4","doi-asserted-by":"crossref","unstructured":"Lam KN, Doan TG, Pham KT, et al (2023) Abstractive text summarization using the BRIO training paradigm. Paper presented at findings of the association for computational linguistics: ACL 2023, Toronto, Canada, pp 92\u201399","DOI":"10.18653\/v1\/2023.findings-acl.7"},{"issue":"9","key":"10669_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3560815","volume":"55","author":"P Liu","year":"2023","unstructured":"Liu P, Yuan W, Fu J et al (2023) Pre-train, prompt, and predict: a systematic survey of prompting methods in natural language processing. ACM Comput Surv 55(9):1\u201335","journal-title":"ACM Comput Surv"},{"key":"10669_CR6","doi-asserted-by":"crossref","unstructured":"Schick T, Sch\u00fctze H (2021) Exploiting cloze-questions for few-shot text classification and natural language inference. Paper presented at proceedings of the 16th conference of the european chapter of the association for computational linguistics, pp 255\u2013269","DOI":"10.18653\/v1\/2021.eacl-main.20"},{"key":"10669_CR7","doi-asserted-by":"crossref","unstructured":"Schick T, Sch\u00fctze H (2021) It\u2019s not just size that matters: small language models are also few-shot learners. Paper presented at proceedings of the 2021 conference of the north american chapter of the association for computational linguistics, pp 2339\u20132352","DOI":"10.18653\/v1\/2021.naacl-main.185"},{"key":"10669_CR8","doi-asserted-by":"crossref","unstructured":"Gao T, Fisch A, Chen D (2021) Making pre-trained language models better few-shot learners. Paper presented at proceedings of the 59th annual meeting of the association for computational linguistics and the 11th international joint conference on natural language processing, pp 3816\u20133830","DOI":"10.18653\/v1\/2021.acl-long.295"},{"key":"10669_CR9","doi-asserted-by":"publisher","unstructured":"White J, Fu Q, Hays S, et al (2023) A Prompt pattern catalog to enhance prompt engineering with ChatGPT. https:\/\/doi.org\/10.48550\/arXiv.2302.11382","DOI":"10.48550\/arXiv.2302.11382"},{"key":"10669_CR10","doi-asserted-by":"crossref","unstructured":"Cai W, Hou C, Liu C et al (2023) PTC: prompt-based continual encrypted traffic classification. Paper presented at 2023 26th international conference on computer supported cooperative work in design, Rio de Janeiro, Brazil, pp 1557\u20131562","DOI":"10.1109\/CSCWD57460.2023.10152661"},{"key":"10669_CR11","doi-asserted-by":"crossref","unstructured":"Ji J, Ren W, Naseem U (2023) Identifying creative harmful memes via prompt based approach. Paper presented at proceedings of the ACM web conference 2023, Austin, Texas, United States, pp 3868\u20133872","DOI":"10.1145\/3543507.3587427"},{"key":"10669_CR12","doi-asserted-by":"crossref","unstructured":"Zhang W, Hu L, Wei Y et al (2023) Verbalizer or classifier? A new prompt learning model for event causality identification. Paper presented at 2023 international joint conference on neural networks, Queensland, Australia, 1\u20137 June 2023","DOI":"10.1109\/IJCNN54540.2023.10191983"},{"key":"10669_CR13","doi-asserted-by":"crossref","unstructured":"Xu L, Chen Y, Cui G et al (2022) Exploring the universal vulnerability of prompt-based learning paradigm. Paper presented at findings of the association for computational linguistics: NAACL 2022, Seattle, United States, pp 1799\u20131810","DOI":"10.18653\/v1\/2022.findings-naacl.137"},{"key":"10669_CR14","doi-asserted-by":"crossref","unstructured":"Shi Y, Li P, Yin C et al (2022) PromptAttack: prompt-based attack for language models via gradient search. Paper presented at the 11th CCF international conference on natural language processing and chinese computing, Guilin, China, pp 682\u2013693","DOI":"10.1007\/978-3-031-17120-8_53"},{"key":"10669_CR15","unstructured":"Lee D, Moon S, Lee J et al (2022) Query-efficient and scalable black-box adversarial attacks on discrete sequential data via Bayesian optimization. Paper presented at 39th international conference on machine learning, Baltimore, Maryland, United States, pp 12478\u201312497, July 2022"},{"key":"10669_CR16","doi-asserted-by":"crossref","unstructured":"Min S, Lewis M, Hajishirzi H et al (2022) Noisy channel language model prompting for few-shot text classification. Paper presented at proceedings of the 60th annual meeting of the association for computational linguistics, Dublin, Ireland, pp 5316\u20135330","DOI":"10.18653\/v1\/2022.acl-long.365"},{"issue":"3","key":"10669_CR17","doi-asserted-by":"publisher","first-page":"464","DOI":"10.1109\/TAI.2022.3207982","volume":"4","author":"S Zhao","year":"2022","unstructured":"Zhao S, Liang Z, Wen J et al (2022) Sparsing and smoothing for the seq2seq Models. IEEE Trans Artif Intell 4(3):464\u2013472","journal-title":"IEEE Trans Artif Intell"},{"key":"10669_CR18","doi-asserted-by":"publisher","unstructured":"Roziere B, Gehring J, Gloeckle F et al (2023) Code llama: open foundation models for code. https:\/\/doi.org\/10.48550\/arXiv.2308.12950","DOI":"10.48550\/arXiv.2308.12950"},{"key":"10669_CR19","doi-asserted-by":"crossref","unstructured":"Behnke H, Fomicheva M, Specia L (2022) Bias mitigation in machine translation quality estimation. Paper presented at proceedings of the 60th annual meeting of the association for computational linguistics, Dublin, Ireland, pp 1475\u20131487","DOI":"10.18653\/v1\/2022.acl-long.104"},{"key":"10669_CR20","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1016\/j.aiopen.2022.11.003","volume":"3","author":"X Han","year":"2022","unstructured":"Han X, Zhao W, Ding N et al (2022) Ptr: prompt tuning with rules for text classification. AI Open 3:182\u2013192","journal-title":"AI Open"},{"key":"10669_CR21","doi-asserted-by":"publisher","unstructured":"Liu X, Zheng Y, Du Z et al (2021) GPT understands, too. https:\/\/doi.org\/10.48550\/arXiv.2103.10385","DOI":"10.48550\/arXiv.2103.10385"},{"key":"10669_CR22","doi-asserted-by":"crossref","unstructured":"Chen Y, Gao H, Cui G, et al (2022) Why Should Adversarial Perturbations be Imperceptible? Rethink the Research Paradigm in Adversarial NLP. Paper presented at proceedings of the 2022 conference on empirical methods in natural language processing, Abu Dhabi, United Arab Emirates, pp 11222\u201311237","DOI":"10.18653\/v1\/2022.emnlp-main.771"},{"key":"10669_CR23","doi-asserted-by":"crossref","unstructured":"Formento B, Foo CS, Luu AT et al (2023) Using punctuation as an adversarial attack on deep learning-based NLP systems: an empirical study. Paper presented at the 17th conference of the european chapter of the association for computational linguistics, Dubrovnik, Croatia, pp 1\u201334","DOI":"10.18653\/v1\/2023.findings-eacl.1"},{"key":"10669_CR24","doi-asserted-by":"crossref","unstructured":"Wang B, Xu C, Liu X et al (2022) SemAttack: natural textual attacks via different semantic spaces. Paper presented at findings of the association for computational linguistics: NAACL 2022, Seattle, United States, pp 176\u2013205","DOI":"10.18653\/v1\/2022.findings-naacl.14"},{"key":"10669_CR25","doi-asserted-by":"crossref","unstructured":"Qi F, Chen Y, Zhang X et al (2021) Mind the style of text! Adversarial and backdoor attacks based on text style transfer. Paper presented at proceedings of the 2021 conference on empirical methods in natural language processing, Online and Punta Cana, Dominican Republic, pp 4569\u20134580","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"10669_CR26","doi-asserted-by":"publisher","unstructured":"Xue J, Zheng M, Hua T, et al (2023) TrojLLM: a black-box trojan prompt attack on large language models. https:\/\/doi.org\/10.48550\/arXiv.2306.06815","DOI":"10.48550\/arXiv.2306.06815"},{"key":"10669_CR27","doi-asserted-by":"publisher","unstructured":"Chao P, Robey A, Dobriban E, et al (2023) Jailbreaking black box large language models in twenty queries. https:\/\/doi.org\/10.48550\/arXiv.2310.08419","DOI":"10.48550\/arXiv.2310.08419"},{"key":"10669_CR28","doi-asserted-by":"publisher","unstructured":"Yang Y, Huang P, Cao J, et al (2022) A prompting-based approach for adversarial example generation and robustness enhancement. https:\/\/doi.org\/10.48550\/arXiv.2203.10714","DOI":"10.48550\/arXiv.2203.10714"},{"key":"10669_CR29","doi-asserted-by":"crossref","unstructured":"Zhu H, Li C, Yang H et al (2023) Prompt makes mask language models better adversarial attackers. Paper presented at 2023 IEEE international conference on acoustics, speech and signal processing, Rhodes Island, Greece, 1\u20135 June 2023","DOI":"10.1109\/ICASSP49357.2023.10095125"},{"key":"10669_CR30","doi-asserted-by":"publisher","unstructured":"Sanh V, Debut L, Chaumond J et al (2019) DistilBERT, a distilled version of BERT: smaller, faster, cheaper and lighter. https:\/\/doi.org\/10.48550\/arXiv.1910.01108","DOI":"10.48550\/arXiv.1910.01108"},{"key":"10669_CR31","doi-asserted-by":"crossref","unstructured":"Wang A, Singh A, Michael J, et al (2018) GLUE: a multi-task benchmark and analysis platform for natural language understanding. Paper presented at proceedings of the 2018 EMNLP workshop BlackboxNLP: analyzing and interpreting neural networks for NLP, Brussels, Belgium, pp 353\u2013355","DOI":"10.18653\/v1\/W18-5446"},{"key":"10669_CR32","unstructured":"Paszke A, Gross S, Massa F, et al (2019) Pytorch: an imperative style, high-performance deep learning library. In: Advances in neural information processing systems 32: annual conference on neural information processing systems 2019, pp 8024\u20138035"},{"key":"10669_CR33","unstructured":"Maas AL, Daly RE, Pham PT et al (2011) Learning word vectors for sentiment analysis. Paper presented at proceedings of the 49th annual meeting of the association for computational linguistics: human language technologies, Portland, Oregon, United States, pp 142\u2013150"},{"key":"10669_CR34","unstructured":"Devlin J, Chang MW, Lee K, et al (2019) BERT: pre-training of deep bidirectional transformers for language understanding. Paper presented at proceedings of the 2019 conference of the north american chapter of the association for computational linguistics: human language technologies, Minneapolis, Minnesota, pp 4171\u20134186"},{"key":"10669_CR35","doi-asserted-by":"publisher","unstructured":"Liu Y, Ott M, Goyal N et al (2019) Roberta: a robustly optimized bert pretraining approach. https:\/\/doi.org\/10.48550\/arXiv.1907.11692","DOI":"10.48550\/arXiv.1907.11692"},{"key":"10669_CR36","unstructured":"Loshchilov I, Hutter F (2019) Decoupled weight decay regularization. Paper presented at the 7th international conference on learning representations, New Orleans, Los Angeles, United States, 1\u201318 May 2019"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-024-10669-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-024-10669-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-024-10669-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,24]],"date-time":"2025-01-24T04:31:09Z","timestamp":1737693069000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-024-10669-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,20]]},"references-count":36,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["10669"],"URL":"https:\/\/doi.org\/10.1007\/s00521-024-10669-2","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"type":"print","value":"0941-0643"},{"type":"electronic","value":"1433-3058"}],"subject":[],"published":{"date-parts":[[2024,11,20]]},"assertion":[{"value":"19 September 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 October 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 November 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All the authors have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}