{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T16:25:25Z","timestamp":1781886325071,"version":"3.54.5"},"reference-count":63,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Autom Softw Eng"],"published-print":{"date-parts":[[2025,5]]},"DOI":"10.1007\/s10515-024-00485-2","type":"journal-article","created":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T06:39:20Z","timestamp":1738046360000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["BadCodePrompt: backdoor attacks against prompt engineering of large language models for code generation"],"prefix":"10.1007","volume":"32","author":[{"given":"Yubin","family":"Qu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Song","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanzhou","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tongtong","family":"Bai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiang","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingya","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Long","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yongming","family":"Yao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,1,28]]},"reference":[{"key":"485_CR1","unstructured":"Austin, J., Odena, A., Nye, M., Bosma, M., Michalewski, H., Dohan, D., Jiang, E., Cai, C., Terry, M., Le, Q., Sutton, C.: Program Synthesis with Large Language Models. arXiv:2108.07732 [cs] (2021). Accessed 18 March 2024"},{"key":"485_CR2","unstructured":"Brown, T., Mann, B., Ryder, N., Subbiah, M., Kaplan, J.D., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., Askell, A., Agarwal, S., Herbert-Voss, A., Krueger, G., Henighan, T., Child, R., Ramesh, A., Ziegler, D., Wu, J., Winter, C., Hesse, C., Chen, M., Sigler, E., Litwin, M., Gray, S., Chess, B., Clark, J., Berner, C., McCandlish, S., Radford, A., Sutskever, I., Amodei, D.: Language models are few-shot learners. In: Advances in Neural Information Processing Systems (2020)"},{"key":"485_CR3","unstructured":"Cai, X., Xu, H., Xu, S., Zhang, Y., Yuan, X.: BadPrompt: Backdoor attacks on continuous prompts. In: Advances in Neural Information Processing Systems (2022)"},{"key":"485_CR4","doi-asserted-by":"crossref","unstructured":"Cai, H., Zhang, P., Dong, H., Xiao, Y., Koffas, S., Li, Y.: Towards stealthy backdoor attacks against speech recognition via elements of sound. arXiv:2307.08208 (2023)","DOI":"10.1109\/TIFS.2024.3404885"},{"key":"485_CR5","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning (2017). https:\/\/arxiv.org\/abs\/1712.05526v1"},{"key":"485_CR6","doi-asserted-by":"publisher","unstructured":"Chen, X., Salem, A., Chen, D., Backes, M., Ma, S., Shen, Q., Wu, Z., Zhang, Y.: BadNL: Backdoor Attacks against NLP Models with Semantic-preserving Improvements. In: Annual Computer Security Applications Conference, pp. 554\u2013569 (2021a). https:\/\/doi.org\/10.1145\/3485832.3485837. arXiv:2006.01043. Accessed 26 May 2023","DOI":"10.1145\/3485832.3485837"},{"key":"485_CR7","doi-asserted-by":"publisher","unstructured":"Chen, M., Tworek, J., Jun, H., Yuan, Q., Pinto, H.P.d.O., Kaplan, J., Edwards, H., Burda, Y., Joseph, N., Brockman, G., Ray, A., Puri, R., Krueger, G., Petrov, M., Khlaaf, H., Sastry, G., Mishkin, P., Chan, B., Gray, S., Ryder, N., Pavlov, M., Power, A., Kaiser, L., Bavarian, M., Winter, C., Tillet, P., Such, F.P., Cummings, D., Plappert, M., Chantzis, F., Barnes, E., Herbert-Voss, A., Guss, W.H., Nichol, A., Paino, A., Tezak, N., Tang, J., Babuschkin, I., Balaji, S., Jain, S., Saunders, W., Hesse, C., Carr, A.N., Leike, J., Achiam, J., Misra, V., Morikawa, E., Radford, A., Knight, M., Brundage, M., Murati, M., Mayer, K., Welinder, P., McGrew, B., Amodei, D., McCandlish, S., Sutskever, I., Zaremba, W.: Evaluating large language models trained on code (2021b). https:\/\/doi.org\/10.48550\/arXiv.2107.03374","DOI":"10.48550\/arXiv.2107.03374"},{"issue":"3","key":"485_CR8","doi-asserted-by":"publisher","first-page":"2027","DOI":"10.1109\/COMST.2016.2548426","volume":"18","author":"M Conti","year":"2016","unstructured":"Conti, M., Dragoni, N., Lesyk, V.: A survey of man in the middle attacks. IEEE Commun. Surv. Tutor. 18(3), 2027\u20132051 (2016)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"485_CR9","unstructured":"Contributors, D.: DriveLM: Drive on language (2023). https:\/\/github.com\/OpenDriveLab\/DriveLM"},{"key":"485_CR10","first-page":"138872","volume":"7","author":"J Dai","year":"2019","unstructured":"Dai, J., Chen, C., Li, Y.: A backdoor attack against LSTM-based text classification systems. IEEE Access Pract. Innov. Open Solut. 7, 138872\u2013138878 (2019)","journal-title":"IEEE Access Pract. Innov. Open Solut."},{"issue":"3","key":"485_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.19363\/J.CNKI.CN10-1380\/TN.2022.05.01","volume":"7","author":"W Du","year":"2022","unstructured":"Du, W., Liu, G.: A survey of backdoor attack in deep learning. J. Cyber Secur. 7(3), 1\u201316 (2022). https:\/\/doi.org\/10.19363\/J.CNKI.CN10-1380\/TN.2022.05.01","journal-title":"J. Cyber Secur."},{"key":"485_CR12","unstructured":"Fried, D., Aghajanyan, A., Lin, J., Wang, S., Wallace, E., Shi, F., Zhong, R., Yih, W.-t., Zettlemoyer, L., Lewis, M.: InCoder: A Generative Model for Code Infilling and Synthesis. arXiv:2204.05999 [cs] (2023)"},{"key":"485_CR13","first-page":"47230","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: Evaluating backdooring attacks on deep neural networks. IEEE Access Pract. Innov. Open Solut. 7, 47230\u201347244 (2019)","journal-title":"IEEE Access Pract. Innov. Open Solut."},{"key":"485_CR14","unstructured":"Hong, S., Carlini, N., Kurakin, A.: Handcrafted backdoors in deep neural networks. In: Oh, A.H., Agarwal, A., Belgrave, D., Cho, K. (eds.) Advances in Neural Information Processing Systems (2022)"},{"key":"485_CR15","unstructured":"Huang, K., Li, Y., Wu, B., Qin, Z., Ren, K.: Backdoor defense via decoupling the training process. In: International Conference on Learning Representations (ICLR) (2022)"},{"key":"485_CR16","doi-asserted-by":"crossref","unstructured":"Jiang, X., Dong, Y., Wang, L., Zheng, F., Shang, Q., Li, G., Jin, Z., Jiao, W.: Self-planning code generation with large language models. ACM Trans. Softw. Eng. Methodol. (2023)","DOI":"10.1145\/3672456"},{"key":"485_CR17","unstructured":"Kandpal, N., Jagielski, M., Tram\u00e8r, F., Carlini, N.: Backdoor attacks for in-context learning with language models. In: The Second Workshop on New Frontiers in Adversarial Machine Learning (2023)"},{"key":"485_CR18","unstructured":"Kojima, T., Gu, S.S., Reid, M., Matsuo, Y., Iwasawa, Y.: Large language models are zero-shot reasoners. In: Oh, A.H., Agarwal, A., Belgrave, D., Cho, K. (eds.) Advances in Neural Information Processing Systems (2022)"},{"key":"485_CR19","doi-asserted-by":"publisher","unstructured":"Li, Y., Choi, D., Chung, J., Kushman, N., Schrittwieser, J., Leblond, R., Eccles, T., Keeling, J., Gimeno, F., Lago, A.D., Hubert, T., Choy, P., d\u2019Autume, C.d.M., Babuschkin, I., Chen, X., Huang, P.-S., Welbl, J., Gowal, S., Cherepanov, A., Molloy, J., Mankowitz, D.J., Robson, E.S., Kohli, P., Freitas, N., Kavukcuoglu, K., Vinyals, O.: Competition-level code generation with AlphaCode. Science (New York, N.Y.) 378(6624), 1092\u20131097 (2022). https:\/\/doi.org\/10.1126\/science.abq1158","DOI":"10.1126\/science.abq1158"},{"key":"485_CR20","unstructured":"Li, J., Zhao, Y., Li, Y., Li, G., Jin, Z.: Acecoder: Utilizing existing code to enhance code generation. arXiv preprint arXiv:2303.17780 (2023)"},{"key":"485_CR21","doi-asserted-by":"publisher","unstructured":"Liu, Y., Ma, S., Aafer, Y., Lee, W.-C., Zhai, J., Wang, W., Zhang, X.: Trojaning attack on neural networks (2018). https:\/\/doi.org\/10.14722\/NDSS.2018.23291","DOI":"10.14722\/NDSS.2018.23291"},{"key":"485_CR22","doi-asserted-by":"crossref","unstructured":"Liu, J., Shen, D., Zhang, Y., Dolan, B., Carin, L., Chen, W.: What makes good in-context examples for GPT-3? arXiv preprint arXiv:2101.06804 (2021)","DOI":"10.18653\/v1\/2022.deelio-1.10"},{"key":"485_CR23","unstructured":"Lou, Q., Liu, Y., Feng, B.: TrojText: Test-time invisible textual trojan insertion. In: The Eleventh International Conference on Learning Representations (2023)"},{"key":"485_CR24","doi-asserted-by":"crossref","unstructured":"Mei, K., Li, Z., Wang, Z., Zhang, Y., Ma, S.: NOTABLE: Transferable backdoor attacks against prompt-based NLP models. In: Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (volume 1: Long Papers) (2023)","DOI":"10.18653\/v1\/2023.acl-long.867"},{"key":"485_CR25","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1109\/JPROC.2020.2970615","volume":"108","author":"DJ Miller","year":"2020","unstructured":"Miller, D.J., Xiang, Z., Kesidis, G.: Adversarial learning in statistical classification: a comprehensive review of defenses against attacks. Proc. IEEE 108, 402\u2013433 (2020)","journal-title":"Proc. IEEE"},{"key":"485_CR26","doi-asserted-by":"crossref","unstructured":"Min, S., Lyu, X., Holtzman, A., Artetxe, M., Lewis, M., Hajishirzi, H., Zettlemoyer, L.: Rethinking the role of demonstrations: What makes in-context learning work? In: Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.759"},{"key":"485_CR27","unstructured":"Moor, M., Huang, Q., Wu, S., Yasunaga, M., Zakka, C., Dalmia, Y., Reis, E.P., Rajpurkar, P., Leskovec, J.: Med-flamingo: a multimodal medical few-shot learner. arXiv:2307.15189 [cs.CV] (2023)"},{"key":"485_CR28","unstructured":"Nijkamp, E., Pang, B., Hayashi, H., Tu, L., Wang, H., Zhou, Y., Savarese, S., Xiong, C.: CodeGen: An Open Large Language Model for Code with Multi-Turn Program Synthesis. arXiv:2203.13474 [cs] (2023)"},{"key":"485_CR29","unstructured":"OpenAI: GPT-4 technical report. arXiv (2023)"},{"key":"485_CR30","unstructured":"Panda, A., Zhang, Z., Yang, Y., Mittal, P.: Teach GPT to phish. In: The Second Workshop on New Frontiers in Adversarial Machine Learning (2023)"},{"key":"485_CR31","unstructured":"Penedo, G., Malartic, Q., Hesslow, D., Cojocaru, R., Cappelli, A., Alobeidli, H., Pannier, B., Almazrouei, E., Launay, J.: The RefinedWeb dataset for Falcon LLM: outperforming curated corpora with web data, and web data only. arXiv preprint arXiv:2306.01116 (2023)"},{"key":"485_CR32","doi-asserted-by":"publisher","unstructured":"Qi, F., Chen, Y., Zhang, X., Li, M., Liu, Z., Sun, M.: Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style Transfer (2021a). https:\/\/doi.org\/10.48550\/arXiv.2110.07139. arXiv:2110.07139. Accessed 25 April 2023","DOI":"10.48550\/arXiv.2110.07139"},{"key":"485_CR33","doi-asserted-by":"crossref","unstructured":"Qi, F., Li, M., Chen, Y., Zhang, Z., Liu, Z., Wang, Y., Sun, M.: Hidden Killer: Invisible Textual Backdoor Attacks with Syntactic Trigger. arXiv:2105.12400 [cs] (2021b). Accessed 08 May 2024","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"485_CR34","doi-asserted-by":"crossref","unstructured":"Qi, X., Zhu, J., Xie, C., Yang, Y.: Subnet Replacement: Deployment-stage backdoor attack against deep neural networks in gray-box setting. In: International Conference on Learning Representations (ICLR) Workshop on Security and Safety in Machine Learning Systems (2021c)","DOI":"10.1109\/CVPR52688.2022.01299"},{"key":"485_CR35","unstructured":"Ren, S., Guo, D., Lu, S., Zhou, L., Liu, S., Tang, D., Sundaresan, N., Zhou, M., Blanco, A., Ma, S.: Codebleu: a method for automatic evaluation of code synthesis. arXiv preprint arXiv:2009.10297 (2020)"},{"key":"485_CR36","unstructured":"Shen, B., Zhang, J., Chen, T., Zan, D., Geng, B., Fu, A., Zeng, M., Yu, A., Ji, J., Zhao, J., Guo, Y., Wang, Q.: PanGu-Coder2: Boosting Large Language Models for Code with Ranking Feedback. arXiv (2023)"},{"key":"485_CR37","doi-asserted-by":"crossref","unstructured":"Sonoda, Y., Kurokawa, R., Nakamura, Y., Kanzawa, J., Kurokawa, M., Ohizumi, Y., Gonoi, W., Abe, O.: Diagnostic performances of GPT-4o, claude 3 opus, and gemini 1.5 pro in diagnosis please cases. Jpn. J. Radiol. 1\u20135 (2024)","DOI":"10.1101\/2024.05.26.24307915"},{"key":"485_CR38","unstructured":"Team, G., Anil, R., Borgeaud, S., Wu, Y., Alayrac, J.-B., Yu, J., Soricut, R., Schalkwyk, J., Dai, A.M., Hauth, A., et al.: Gemini: a family of highly capable multimodal models. arXiv preprint arXiv:2312.11805 (2023)"},{"key":"485_CR39","unstructured":"Wan, A., Wallace, E., Shen, S., Klein, D.: Poisoning language models during instruction tuning. In: International Conference on Machine Learning (2023)"},{"key":"485_CR40","doi-asserted-by":"crossref","unstructured":"Wang, B., Pei, H., Pan, B., Chen, Q., Wang, S., Li, B.: T3: Tree-autoencoder regularized adversarial text generation for targeted attack. In: Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP), pp. 6134\u20136150 (2020)","DOI":"10.18653\/v1\/2020.emnlp-main.495"},{"key":"485_CR41","unstructured":"Wang, B., Chen, W., Pei, H., Xie, C., Kang, M., Zhang, C., Xu, C., Xiong, Z., Dutta, R., Schaeffer, R., Truong, S.T., Arora, S., Mazeika, M., Hendrycks, D., Lin, Z., Cheng, Y., Koyejo, S., Song, D., Li, B.: DecodingTrust: a comprehensive assessment of trustworthiness in GPT models. arXiv:2306.11698 [cs.CL] (2023)"},{"key":"485_CR42","doi-asserted-by":"crossref","unstructured":"Weber, M., Xu, X., Karla\u0161, B., Zhang, C., Li, B.: RAB: Provable robustness against backdoor attacks. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 640\u2013657 (2023)","DOI":"10.1109\/SP46215.2023.10179451"},{"key":"485_CR43","unstructured":"Wei, J., Wei, J., Tay, Y., Tran, D., Webson, A., Lu, Y., Chen, X., Liu, H., Huang, D., Zhou, D., Ma, T.: Larger language models do in-context learning differently. arXiv:2303.03846 (2023)"},{"key":"485_CR44","doi-asserted-by":"crossref","unstructured":"Wu, J., Gaur, Y., Chen, Z., Zhou, L., Zhu, Y., Wang, T., Li, J., Liu, S., Ren, B., Liu, L., Wu, Y.: On decoder-only architecture for speech-to-text and large language model integration. arXiv:2307.03917 [eess.AS] (2023)","DOI":"10.1109\/ASRU57964.2023.10389705"},{"key":"485_CR45","unstructured":"Xiang, Z., Xiong, Z., Li, B.: CBD: a certified backdoor detector based on local dominant probability. In: Advances in Neural Information Processing Systems (NeurIPS) (2023a)"},{"key":"485_CR46","unstructured":"Xiang, Z., Xiong, Z., Li, B.: UMD: Unsupervised model detection for X2X backdoor attacks. In: International Conference on Machine Learning (ICML) (2023b)"},{"key":"485_CR47","unstructured":"Xiang, Z., Jiang, F., Xiong, Z., Ramasubramanian, B., Poovendran, R., Li, B.: BadChain: Backdoor chain-of-thought prompting for large language models (2024)"},{"key":"485_CR48","doi-asserted-by":"crossref","unstructured":"Xie, T., Wu, C.H., Shi, P., Zhong, R., Scholak, T., Yasunaga, M., Wu, C.-S., Zhong, M., Yin, P., Wang, S.I., Zhong, V., Wang, B., Li, C., Boyle, C., Ni, A., Yao, Z., Radev, D., Xiong, C., Kong, L., Zhang, R., Smith, N.A., Zettlemoyer, L., Yu, T.: UnifiedSKG: Unifying and multi-tasking structured knowledge grounding with text-to-text language models. arXiv: 2201.05966 [cs.CL] (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.39"},{"key":"485_CR49","doi-asserted-by":"crossref","unstructured":"Xu, L., Chen, Y., Cui, G., Gao, H., Liu, Z.: Exploring the universal vulnerability of prompt-based learning paradigm. In: Findings of the Association for Computational Linguistics: NAACL 2022 (2022)","DOI":"10.18653\/v1\/2022.findings-naacl.137"},{"key":"485_CR50","doi-asserted-by":"crossref","unstructured":"Xu, J., Ma, M.D., Wang, F., Xiao, C., Chen, M.: Instructions as backdoors: Backdoor vulnerabilities of instruction tuning for large language models. arXiv:2305.14710 (2023)","DOI":"10.18653\/v1\/2024.naacl-long.171"},{"key":"485_CR51","unstructured":"Yang, C., Wang, X., Lu, Y., Liu, H., Le, Q.V., Zhou, D., Chen, X.: Large language models as optimizers. arXiv:2309.03409 (2023)"},{"key":"485_CR52","unstructured":"Yasunaga, M., Chen, X., Li, Y., Pasupat, P., Leskovec, J., Liang, P., Chi, E.H., Zhou, D.: Large language models as analogical reasoners. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"485_CR53","doi-asserted-by":"publisher","unstructured":"Zeng, G., Qi, F., Zhou, Q., Zhang, T., Ma, Z., Hou, B., Zang, Y., Liu, Z., Sun, M.: OpenAttack: An Open-source Textual Adversarial Attack Toolkit. In: Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing: System Demonstrations, pp. 363\u2013371 (2021). https:\/\/doi.org\/10.18653\/v1\/2021.acl-demo.43. arXiv:2009.09191. Accessed 21 August 2023","DOI":"10.18653\/v1\/2021.acl-demo.43"},{"key":"485_CR54","doi-asserted-by":"publisher","unstructured":"Zhang, H., Huang, J., Li, Z., Naik, M., Xing, E.: Improved logical reasoning of language models via differentiable symbolic programming. In: Rogers, A., Boyd-Graber, J., Okazaki, N. (eds.) Findings of the Association for Computational Linguistics: ACL 2023, pp. 3062\u20133077. Association for Computational Linguistics, Toronto, Canada (2023). https:\/\/doi.org\/10.18653\/v1\/2023.findings-acl.191","DOI":"10.18653\/v1\/2023.findings-acl.191"},{"key":"485_CR55","doi-asserted-by":"crossref","unstructured":"Zhang, K., Li, J., Li, G., Shi, X., Jin, Z.: CodeAgent: Enhancing code generation with tool-integrated agent systems for real-world repo-level coding challenges (2024)","DOI":"10.18653\/v1\/2024.acl-long.737"},{"key":"485_CR56","doi-asserted-by":"crossref","unstructured":"Zhao, S., Ma, X., Zheng, X., Bailey, J., Chen, J., Jiang, Y.-G.: Clean-label backdoor attacks on video recognition models. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2020)","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"485_CR57","unstructured":"Zhao, Z., Wallace, E., Feng, S., Klein, D., Singh, S.: Calibrate before use: Improving few-shot performance of language models. In: International Conference on Machine Learning, pp. 12697\u201312706. PMLR (2021)"},{"key":"485_CR58","doi-asserted-by":"publisher","unstructured":"Zhao, W., Geva, M., Lin, B.Y., Yasunaga, M., Madaan, A., Yu, T.: Complex reasoning in natural language. In: Chen, Y.-N.V., Margot, M., Reddy, S. (eds.) Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (volume 6: Tutorial Abstracts), 11\u201320. Association for Computational Linguistics, Toronto, Canada (2023a). https:\/\/doi.org\/10.18653\/v1\/2023.acl-tutorials.2","DOI":"10.18653\/v1\/2023.acl-tutorials.2"},{"key":"485_CR59","doi-asserted-by":"crossref","unstructured":"Zhao, S., Wen, J., Tuan, L.A., Zhao, J., Fu, J.: Prompt as triggers for backdoor attack: examining the vulnerability in language models. arXiv:2305.01219 [cs.CL] (2023b)","DOI":"10.18653\/v1\/2023.emnlp-main.757"},{"key":"485_CR60","doi-asserted-by":"crossref","unstructured":"Zheng, Q., Xia, X., Zou, X., Dong, Y., Wang, S., Xue, Y., Wang, Z., Shen, L., Wang, A., Li, Y., Su, T., Yang, Z., Tang, J.: CodeGeeX: A Pre-Trained Model for Code Generation with Multilingual Evaluations on HumanEval-X (2023). arXiv:2303.17568. Accessed 28 June 2023","DOI":"10.1145\/3580305.3599790"},{"key":"485_CR61","unstructured":"Zheng, Z., Ning, K., Wang, Y., Zhang, J., Zheng, D., Ye, M., Chen, J.: A Survey of Large Language Models for Code: Evolution, Benchmarking, and Future Trends. arXiv:2311.10372 [cs] (2024). Accessed 29 March 2024"},{"key":"485_CR62","unstructured":"Zhuo, T.Y., Vu, M.C., Chim, J., Hu, H., Yu, W., Widyasari, R., Yusuf, I.N.B., Zhan, H., He, J., Paul, I., et al.: Bigcodebench: Benchmarking code generation with diverse function calls and complex instructions. arXiv preprint arXiv:2406.15877 (2024)"},{"key":"485_CR63","unstructured":"Zou, A., Wang, Z., Kolter, J.Z., Fredrikson, M.: Universal and transferable adversarial attacks on aligned language models. arXiv:2307.15043 [cs.CL] (2023)"}],"container-title":["Automated Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10515-024-00485-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10515-024-00485-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10515-024-00485-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,6]],"date-time":"2025-04-06T01:39:17Z","timestamp":1743903557000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10515-024-00485-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,28]]},"references-count":63,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,5]]}},"alternative-id":["485"],"URL":"https:\/\/doi.org\/10.1007\/s10515-024-00485-2","relation":{},"ISSN":["0928-8910","1573-7535"],"issn-type":[{"value":"0928-8910","type":"print"},{"value":"1573-7535","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,28]]},"assertion":[{"value":"16 November 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"31 December 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 January 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"17"}}