{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T21:00:45Z","timestamp":1774904445587,"version":"3.50.1"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402267"],"award-info":[{"award-number":["62402267"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62432004"],"award-info":[{"award-number":["62432004"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372472"],"award-info":[{"award-number":["62372472"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62306109"],"award-info":[{"award-number":["62306109"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100019091","name":"Key Research and Development Program of Hunan Province of China","doi-asserted-by":"publisher","award":["2023SK2020"],"award-info":[{"award-number":["2023SK2020"]}],"id":[{"id":"10.13039\/501100019091","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004761","name":"Natural Science Foundation of Hainan Province","doi-asserted-by":"publisher","award":["2024JJ4068"],"award-info":[{"award-number":["2024JJ4068"]}],"id":[{"id":"10.13039\/501100004761","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100020721","name":"Guoqiang Institute, Tsinghua University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100020721","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3671126","type":"journal-article","created":{"date-parts":[[2026,3,5]],"date-time":"2026-03-05T20:42:22Z","timestamp":1772743342000},"page":"3006-3021","source":"Crossref","is-referenced-by-count":0,"title":["A Fine-Tuning Data Recovery Attack on Generative Language Models via Backdooring"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-4788-7633","authenticated-orcid":false,"given":"Zhenya","family":"Ma","sequence":"first","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3010-3812","authenticated-orcid":false,"given":"Yongheng","family":"Deng","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}]},{"given":"Ziqing","family":"Qiao","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7778-4243","authenticated-orcid":false,"given":"Quan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Software Engineering Institute, East China Normal University, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6446-247X","authenticated-orcid":false,"given":"Chijin","family":"Zhou","sequence":"additional","affiliation":[{"name":"Software Engineering Institute, East China Normal University, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3615-1217","authenticated-orcid":false,"given":"Fan","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Central South University, Changsha, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6717-461X","authenticated-orcid":false,"given":"Yaoxue","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2782-183X","authenticated-orcid":false,"given":"Ju","family":"Ren","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology and the State Key Laboratory of Internet Architecture, Tsinghua University, Beijing, China"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Language models are few-shot learners","author":"Brown","year":"2020","journal-title":"arXiv:2005.14165"},{"key":"ref2","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023","journal-title":"arXiv:2307.09288"},{"key":"ref3","article-title":"OPT: Open pre-trained transformer language models","author":"Zhang","year":"2022","journal-title":"arXiv:2205.01068"},{"key":"ref4","first-page":"39321","article-title":"Counterfactual memorization in neural language models","volume-title":"Proc. NeurIPS","volume":"36","author":"Zhang"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1708"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-short.129"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3606017"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"ref9","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume-title":"Proc. NeurIPS","volume":"33","author":"Geiping"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-emnlp.305"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0555"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref14","first-page":"8130","article-title":"Recovering private text in federated learning of language models","volume":"35","author":"Gupta","year":"2022","journal-title":"NeurIPS"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.765"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.881"},{"key":"ref17","article-title":"SoK: Memorization in general-purpose large language models","author":"Hartmann","year":"2023","journal-title":"arXiv:2310.18362"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179300"},{"key":"ref19","article-title":"Scalable extraction of training data from (production) language models","author":"Nasr","year":"2023","journal-title":"arXiv:2311.17035"},{"key":"ref20","volume-title":"Training Data Extraction Challenge","year":"2022"},{"key":"ref21","first-page":"40306","article-title":"Bag of tricks for training data extraction from language models","volume-title":"Proc. ICML","author":"Yu"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.709"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3764113"},{"key":"ref24","first-page":"2633","article-title":"Extracting training data from large language models","volume-title":"Proc. USENIX Secur.","author":"Carlini"},{"key":"ref25","article-title":"Dataset security for machine learning: Data poisoning, backdoor attacks, and defenses","author":"Goldblum","year":"2020","journal-title":"arXiv:2012.10544"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2024.3486228"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417253"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref29","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao","year":"2020","journal-title":"arXiv:2007.10760"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3521942"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230164"},{"key":"ref32","first-page":"2901","article-title":"On the difficulty of defending contrastive learning against backdoor attacks","volume-title":"Proc. USENIX Secur.","author":"Li"},{"key":"ref33","article-title":"Hijacking attacks against neural networks by analyzing training data","author":"Ge","year":"2024","journal-title":"arXiv:2401.09740"},{"key":"ref34","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. USENIX Secur.","author":"Bagdasaryan"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_7"},{"key":"ref36","first-page":"8068","article-title":"Handcrafted backdoors in deep neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Hong"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref38","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref39","article-title":"Pandora\u2019s white-box: Increased training data leakage in open LLMs","author":"Wang","year":"2024","journal-title":"arXiv:2402.17012"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3694715.3695964"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690279"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/2701415"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3691620.3695060"},{"key":"ref44","article-title":"GPT-NEO: Large scale autoregressive language modeling with Mesh-Tensorflow","author":"Black","year":"2021"},{"key":"ref45","article-title":"Qwen3 technical report","author":"Yang","year":"2025","journal-title":"arXiv:2505.09388"},{"key":"ref46","first-page":"1","article-title":"Pointer sentinel mixture models","volume-title":"Proc. ICLR","author":"Merity"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30115-8_22"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"ref49","article-title":"Neural network acceptability judgments","author":"Warstadt","year":"2018","journal-title":"arXiv:1805.12471"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.154"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.422"},{"key":"ref52","article-title":"LoRA: Low-rank adaptation of large language models","author":"Hu","year":"2021","journal-title":"arXiv:2106.09685"},{"key":"ref53","first-page":"242","article-title":"Imperceptible content poisoning in LLM-powered applications","author":"Zhang","year":"2024","journal-title":"IEEE\/ACM ASE"},{"key":"ref54","article-title":"Baseline defenses for adversarial attacks against aligned language models","author":"Jain","year":"2023","journal-title":"arXiv:2309.00614"},{"key":"ref55","volume-title":"Security: Malware Scanning on the Hugging Face Hub","year":"2025"},{"key":"ref56","volume-title":"ClamAV: Open Source Antivirus Engine","year":"2025"},{"key":"ref57","volume-title":"Bandit: A Security Linter for Python","year":"2025"},{"key":"ref58","first-page":"739","article-title":"Comprehensive privacy analysis of deep learning: Stand-alone and federated learning under passive and active white-box inference attacks","volume-title":"Proc. IEEE S&P","author":"Nasr"},{"key":"ref59","first-page":"267","article-title":"The secret sharer: Evaluating and testing unintended membership leakage in machine learning models","volume-title":"Proc. IEEE S&P","author":"Carlini"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354211"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"ref65","first-page":"299","article-title":"Membership inference attack in face of data transformations","volume-title":"Proc. IEEE Conf. Commun. Netw. Secur. (CNS)","author":"Chen"},{"key":"ref66","article-title":"Detecting pretraining data from large language models","author":"Shi","year":"2023","journal-title":"arXiv:2310.16789"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3088480"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11422005.pdf?arnumber=11422005","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T20:05:33Z","timestamp":1774901133000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11422005\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":67,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3671126","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}