{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:13:21Z","timestamp":1763190801654,"version":"3.45.0"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/ijcnn64981.2025.11227624","type":"proceedings-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T18:46:15Z","timestamp":1763145975000},"page":"1-8","source":"Crossref","is-referenced-by-count":0,"title":["Weakening Prediction Confidence Makes Backdoors Strengthened: A Strong Textual Backdoor Attack on Prefix-tuning"],"prefix":"10.1109","author":[{"given":"Yixin","family":"Tan","sequence":"first","affiliation":[{"name":"Institute of Science,Tokyo"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haoyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Lan-Bridge Communications Ltd"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Sakuma","sequence":"additional","affiliation":[{"name":"RIKEN AIP &#x0026; Institute of Science,Tokyo"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"author":"Devlin","key":"ref1","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-022-1377-5"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3605943"},{"article-title":"Incorporating bert into neural machine translation","year":"2020","author":"Zhu","key":"ref4"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W17-1101"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2124"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.naacl-main.214"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485837"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.353"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-short.8"},{"key":"ref14","article-title":"Not all unlabeled data are equal: Learning to weight data in semi-supervised learning","author":"Ren","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17140-6_22"},{"key":"ref16","article-title":"Xlnet: Generalized autoregressive pretraining for language understanding","volume":"32","author":"Yang","year":"2019","journal-title":"Advances in neural information processing systems"},{"issue":"1","key":"ref17","first-page":"5485","article-title":"Exploring the limits of transfer learning with a unified text-to-text transformer","volume":"21","author":"Raffel","year":"2020","journal-title":"The Journal of Machine Learning Research"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.295"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.346"},{"key":"ref20","article-title":"Language models are few-shot learners","volume-title":"CoRR","author":"Brown","year":"2020"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.aiopen.2023.08.012"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.243"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref24","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume":"33","author":"Nguyen","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548272"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2941376"},{"article-title":"Natural backdoor attack on text data","year":"2020","author":"Sun","key":"ref27"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/2938386"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.241"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.165"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.105"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.659"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.findings-naacl.137"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.757"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/96"},{"key":"ref37","first-page":"37 068","article-title":"Badprompt: Backdoor attacks on continuous prompts","volume":"35","author":"Cai","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.135"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.725"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.500"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-62419-4_30"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-5102"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/S18-1001"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.3115\/1072133.1072221"},{"key":"ref46","article-title":"Distilbert, a distilled version of bert: smaller, faster, cheaper and lighter","author":"Sanh","year":"2019","journal-title":"ArXiv"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1410"},{"article-title":"All english stopwords (700+)","year":"2020","author":"Swami","key":"ref48"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.3115\/1118108.1118117"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.388"},{"article-title":"LoRA: Low-rank adaptation of large language models","volume-title":"International Conference on Learning Representations","author":"Hu","key":"ref51"}],"event":{"name":"2025 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2025,6,30]]},"location":"Rome, Italy","end":{"date-parts":[[2025,7,5]]}},"container-title":["2025 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11227166\/11227148\/11227624.pdf?arnumber=11227624","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:10:34Z","timestamp":1763190634000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11227624\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/ijcnn64981.2025.11227624","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}