{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T04:56:14Z","timestamp":1781758574308,"version":"3.54.5"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Research Foundation of Korea (NRF) grant funded by the Korea government","award":["2023R1A2C1003783"],"award-info":[{"award-number":["2023R1A2C1003783"]}]},{"DOI":"10.13039\/501100012659","name":"Foundation for Innovative Research Groups of the National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22B2027"],"award-info":[{"award-number":["U22B2027"]}],"id":[{"id":"10.13039\/501100012659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012659","name":"Foundation for Innovative Research Groups of the National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["W2411053"],"award-info":[{"award-number":["W2411053"]}],"id":[{"id":"10.13039\/501100012659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3699202","type":"journal-article","created":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T20:04:57Z","timestamp":1780430697000},"page":"5583-5596","source":"Crossref","is-referenced-by-count":0,"title":["Trigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language Models"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3030-709X","authenticated-orcid":false,"given":"Zhirun","family":"Zheng","sequence":"first","affiliation":[{"name":"Department of Artificial Intelligence, Ajou University, Suwon, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2240-0892","authenticated-orcid":false,"given":"Young-June","family":"Choi","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, Ajou University, Suwon, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3769-7211","authenticated-orcid":false,"given":"Cheng","family":"Huang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Artificial Intelligence, Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0957-8576","authenticated-orcid":false,"given":"Hangcheng","family":"Cao","sequence":"additional","affiliation":[{"name":"Department of Computer Science, City University of Hong Kong, Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0684-0591","authenticated-orcid":false,"given":"Shujuan","family":"Tian","sequence":"additional","affiliation":[{"name":"School of Computer Science, Xiangtan University, Xiangtan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1205-5899","authenticated-orcid":false,"given":"Tingrui","family":"Pei","sequence":"additional","affiliation":[{"name":"College of Information Science and Technology, Jinan University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635739"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2026.132914"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CSTE62025.2024.00031"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.18260\/1-2-119-46353"},{"key":"ref5","article-title":"Multimodal LLM for intelligent transportation systems","volume-title":"Proc. IEEE Symp. Ser. Comput. Intell.","author":"Le","year":"2025"},{"key":"ref6","article-title":"Leveraging large language models for enhancing public transit services","author":"Wang","year":"2024","journal-title":"arXiv:2410.14147"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3703155"},{"key":"ref8","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive NLP tasks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Lewis"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3777378"},{"key":"ref10","article-title":"From local to global: A graph rag approach to query-focused summarization","author":"Edge","year":"2025","journal-title":"arXiv:2404.16130"},{"key":"ref11","first-page":"3827","article-title":"PoisonedRAG: Knowledge corruption attacks to retrieval-augmented generation of large language models","volume-title":"Proc. 34th USENIX Secur. Symp.","author":"Zou"},{"key":"ref12","article-title":"Badrag: Identifying vulnerabilities in retrieval augmented generation of large language models","author":"Xue","year":"2024","journal-title":"arXiv:2406.00083"},{"key":"ref13","article-title":"TrojanRAG: Retrieval-augmented generation can be backdoor driver in large language models","volume-title":"arXiv:2405.13401","author":"Cheng","year":"2024"},{"key":"ref14","first-page":"1","article-title":"Graphrag under fire","volume-title":"Proc. IEEE Symp. Secur. Privacy","author":"Liang"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.302"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671470"},{"issue":"251","key":"ref17","first-page":"1","article-title":"ATLAS: Few-shot learning with retrieval augmented language models","volume":"24","author":"Izacard","year":"2023","journal-title":"J. Mach. Learn. Res."},{"key":"ref18","first-page":"3929","article-title":"Retrieval augmented language model pre-training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guu"},{"key":"ref19","article-title":"Retrieval-augmented generation with graphs (graphrag)","author":"Han","year":"2025","journal-title":"arXiv:2501.00309"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-naacl.232"},{"key":"ref21","first-page":"1","article-title":"BEIR: A heterogenous benchmark for zero-shot evaluation of information retrieval models","volume-title":"Proc. 35th Conf. Neural Inf. Process. Syst. Track Datasets Benchmarks","author":"Thakur"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.17509\/ijotis.v3i1.43182"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3677389.3702542"},{"key":"ref24","article-title":"Golden-retriever: High-fidelity agentic retrieval augmented generation for industrial knowledge base","author":"An","year":"2024","journal-title":"arXiv:2408.00798"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-024-03445-1"},{"key":"ref26","article-title":"Learning to poison large language models for downstream manipulation","author":"Zhou","year":"2024","journal-title":"arXiv:2402.13459"},{"key":"ref27","first-page":"1","article-title":"Badedit: Backdooring large language models by model editing","volume-title":"Proc. 24th Int. Conf. Learn. Represent.","author":"Li"},{"key":"ref28","article-title":"Backdoored retrievers for prompt injection attacks on retrieval augmented generation of large language models","author":"Clop","year":"2024","journal-title":"arXiv:2410.14479"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3712001"},{"key":"ref30","article-title":"Backdoorllm: A comprehensive benchmark for backdoor attacks and defenses on large language models","volume":"38","author":"Li","year":"2025","journal-title":"Proc. Adv. Neural Inf. Process. Syst."},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825103"},{"issue":"1","key":"ref32","first-page":"26","article-title":"Jailbreaking and mitigation of vulnerabilities in large language models","volume":"1","author":"Peng","year":"2026","journal-title":"Eureka"},{"key":"ref33","article-title":"EasyJailbreak: A unified framework for jailbreaking large language models","author":"Zhou","year":"2024","journal-title":"arXiv:2403.12171"},{"key":"ref34","article-title":"HijackRAG: Hijacking attacks against retrieval-augmented large language models","author":"Zhang","year":"2024","journal-title":"arXiv:2410.22832"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.161"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.96"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00179"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00276"},{"key":"ref40","article-title":"MS MARCO: A human generated machine reading comprehension dataset","author":"Baja","year":"2018","journal-title":"arXiv:1611.09268"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1259"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.292"},{"key":"ref43","first-page":"3259","article-title":"On the security risks of knowledge graph reasoning","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Xi"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-emnlp.568"},{"key":"ref45","article-title":"Practical poisoning attacks against retrieval-augmented generation","author":"Zhang","year":"2026","journal-title":"arXiv:2504.03957"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC67867.2025.00093"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/BigData66926.2025.11402647"},{"key":"ref48","article-title":"TrustRAG: Enhancing robustness and trustworthiness in retrieval-augmented generation","author":"Zhou","year":"2025","journal-title":"arXiv:2501.00879"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/tkde.2026.3690651"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2025.3597216"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11547227.pdf?arnumber=11547227","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T04:50:32Z","timestamp":1781758232000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11547227\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":50,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3699202","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}