{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T16:37:23Z","timestamp":1778258243241,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,4,19]],"date-time":"2021-04-19T00:00:00Z","timestamp":1618790400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,4,19]]},"DOI":"10.1145\/3442381.3450034","type":"proceedings-article","created":{"date-parts":[[2021,6,3]],"date-time":"2021-06-03T19:35:17Z","timestamp":1622748917000},"page":"3638-3650","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["A Targeted Attack on Black-Box Neural Machine Translation with Parallel Data Poisoning"],"prefix":"10.1145","author":[{"given":"Chang","family":"Xu","sequence":"first","affiliation":[{"name":"University of Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Wang","sequence":"additional","affiliation":[{"name":"University of Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuqing","family":"Tang","sequence":"additional","affiliation":[{"name":"Facebook AI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francisco","family":"Guzm\u00e1n","sequence":"additional","affiliation":[{"name":"Facebook AI, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Benjamin I. P.","family":"Rubinstein","sequence":"additional","affiliation":[{"name":"University of Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Trevor","family":"Cohn","sequence":"additional","affiliation":[{"name":"University of Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,6,3]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Ahmed Abdelali Francisco Guzman Hassan Sajjad and Stephan Vogel. 2014. The AMARA Corpus: Building Parallel Language Resources for the Educational Domain. In LREC.  Ahmed Abdelali Francisco Guzman Hassan Sajjad and Stephan Vogel. 2014. The AMARA Corpus: Building Parallel Language Resources for the Educational Domain. In LREC."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Marta Ba\u00f1\u00f3n Pinzhen Chen Barry Haddow Kenneth Heafield Hieu Hoang Miquel Espl\u00e0-Gomis Mikel\u00a0L. Forcada Amir Kamran Faheem Kirefu Philipp Koehn Sergio Ortiz\u00a0Rojas Leopoldo Pla\u00a0Sempere Gema Ram\u00edrez-S\u00e1nchez Elsa Sarr\u00edas Marek Strelec Brian Thompson William Waites Dion Wiggins and Jaume Zaragoza. 2020. ParaCrawl: Web-Scale Acquisition of Parallel Corpora. In ACL.  Marta Ba\u00f1\u00f3n Pinzhen Chen Barry Haddow Kenneth Heafield Hieu Hoang Miquel Espl\u00e0-Gomis Mikel\u00a0L. Forcada Amir Kamran Faheem Kirefu Philipp Koehn Sergio Ortiz\u00a0Rojas Leopoldo Pla\u00a0Sempere Gema Ram\u00edrez-S\u00e1nchez Elsa Sarr\u00edas Marek Strelec Brian Thompson William Waites Dion Wiggins and Jaume Zaragoza. 2020. ParaCrawl: Web-Scale Acquisition of Parallel Corpora. In ACL.","DOI":"10.18653\/v1\/2020.acl-main.417"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W19-5301"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Marco Barreno Blaine Nelson Russell Sears Anthony\u00a0D Joseph and J\u00a0Doug Tygar. 2006. Can machine learning be secure?. In ASIACCS.  Marco Barreno Blaine Nelson Russell Sears Anthony\u00a0D Joseph and J\u00a0Doug Tygar. 2006. Can machine learning be secure?. In ASIACCS.","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/S19-2007"},{"key":"e_1_3_2_1_6_1","unstructured":"Yonatan Belinkov and Yonatan Bisk. 2018. Synthetic and natural noise both break neural machine translation. In ICLR.  Yonatan Belinkov and Yonatan Bisk. 2018. Synthetic and natural noise both break neural machine translation. In ICLR."},{"key":"e_1_3_2_1_7_1","volume-title":"NRC Parallel Corpus Filtering System for WMT 2019. In Proceedings of the Fourth Conference on Machine Translation.","author":"Bernier-Colborne Gabriel","year":"2019","unstructured":"Gabriel Bernier-Colborne and Chi-kiu Lo. 2019 . NRC Parallel Corpus Filtering System for WMT 2019. In Proceedings of the Fourth Conference on Machine Translation. Gabriel Bernier-Colborne and Chi-kiu Lo. 2019. NRC Parallel Corpus Filtering System for WMT 2019. In Proceedings of the Fourth Conference on Machine Translation."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","unstructured":"Davide Canali Marco Cova Giovanni Vigna and Christopher Kruegel. 2011. Prophiler: a fast filter for the large-scale detection of malicious web pages. In WWW.  Davide Canali Marco Cova Giovanni Vigna and Christopher Kruegel. 2011. Prophiler: a fast filter for the large-scale detection of malicious web pages. In WWW.","DOI":"10.1145\/1963405.1963436"},{"key":"e_1_3_2_1_9_1","unstructured":"Isaac Caswell and Bowen Liang. 2020 (accessed August 9 2020). Recent Advances in Google Translate. https:\/\/ai.googleblog.com\/2020\/06\/recent-advances-in-google-translate.html.  Isaac Caswell and Bowen Liang. 2020 (accessed August 9 2020). Recent Advances in Google Translate. https:\/\/ai.googleblog.com\/2020\/06\/recent-advances-in-google-translate.html."},{"key":"e_1_3_2_1_10_1","volume-title":"The IWSLT 2016 evaluation campaign. In International Workshop on Spoken Language Translation.","author":"Cettolo Mauro","year":"2016","unstructured":"Mauro Cettolo , Niehues Jan , St\u00fcker Sebastian , Luisa Bentivogli , Roldano Cattoni , and Marcello Federico . 2016 . The IWSLT 2016 evaluation campaign. In International Workshop on Spoken Language Translation. Mauro Cettolo, Niehues Jan, St\u00fcker Sebastian, Luisa Bentivogli, Roldano Cattoni, and Marcello Federico. 2016. The IWSLT 2016 evaluation campaign. In International Workshop on Spoken Language Translation."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W19-5435"},{"key":"e_1_3_2_1_12_1","unstructured":"Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526(2017).  Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526(2017)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Minhao Cheng Jinfeng Yi Pin-Yu Chen Huan Zhang and Cho-Jui Hsieh. 2020. Seq2sick: Evaluating the robustness of sequence-to-sequence models with adversarial examples. In AAAI.  Minhao Cheng Jinfeng Yi Pin-Yu Chen Huan Zhang and Cho-Jui Hsieh. 2020. Seq2sick: Evaluating the robustness of sequence-to-sequence models with adversarial examples. In AAAI.","DOI":"10.1609\/aaai.v34i04.5767"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Yong Cheng Lu Jiang and Wolfgang Macherey. 2019. Robust Neural Machine Translation with Doubly Adversarial Inputs. In ACL.  Yong Cheng Lu Jiang and Wolfgang Macherey. 2019. Robust Neural Machine Translation with Doubly Adversarial Inputs. In ACL.","DOI":"10.18653\/v1\/P19-1425"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Yong Cheng Lu Jiang Wolfgang Macherey and Jacob Eisenstein. 2020. AdvAug: Robust Adversarial Augmentation for Neural Machine Translation. In ACL.  Yong Cheng Lu Jiang Wolfgang Macherey and Jacob Eisenstein. 2020. AdvAug: Robust Adversarial Augmentation for Neural Machine Translation. In ACL.","DOI":"10.18653\/v1\/2020.acl-main.529"},{"key":"e_1_3_2_1_16_1","unstructured":"Javid Ebrahimi Daniel Lowd and Dejing Dou. 2018. On adversarial examples for character-level neural machine translation. In COLING.  Javid Ebrahimi Daniel Lowd and Dejing Dou. 2018. On adversarial examples for character-level neural machine translation. In COLING."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Sergey Edunov Myle Ott Michael Auli and David Grangier. 2018. Understanding Back-Translation at Scale. In EMNLP.  Sergey Edunov Myle Ott Michael Auli and David Grangier. 2018. Understanding Back-Translation at Scale. In EMNLP.","DOI":"10.18653\/v1\/D18-1045"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Ahmed El-Kishky Vishrav Chaudhary Francisco Guzm\u00e1n and Philipp Koehn. 2020. CCAligned: A Massive Collection of Cross-Lingual Web-Document Pairs. In EMNLP.  Ahmed El-Kishky Vishrav Chaudhary Francisco Guzm\u00e1n and Philipp Koehn. 2020. CCAligned: A Massive Collection of Cross-Lingual Web-Document Pairs. In EMNLP.","DOI":"10.18653\/v1\/2020.emnlp-main.480"},{"key":"e_1_3_2_1_19_1","unstructured":"Jonas Gehring Michael Auli David Grangier Denis Yarats and Yann\u00a0N Dauphin. 2017. Convolutional sequence to sequence learning. In ICML.  Jonas Gehring Michael Auli David Grangier Denis Yarats and Yann\u00a0N Dauphin. 2017. Convolutional sequence to sequence learning. In ICML."},{"key":"e_1_3_2_1_20_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733(2017).","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733(2017). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733(2017)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W19-5404"},{"key":"e_1_3_2_1_22_1","volume-title":"Moses: Open Source Toolkit for Statistical Machine Translation. In ACL (Demo and Poster Sessions).","author":"Koehn Philipp","year":"2007","unstructured":"Philipp Koehn , Hieu Hoang , Alexandra Birch , Chris Callison-Burch , Marcello Federico , Nicola Bertoldi , Brooke Cowan , Wade Shen , Christine Moran , Richard Zens , Chris Dyer , Ond\u0159ej Bojar , Alexandra Constantin , and Evan Herbst . 2007 . Moses: Open Source Toolkit for Statistical Machine Translation. In ACL (Demo and Poster Sessions). Philipp Koehn, Hieu Hoang, Alexandra Birch, Chris Callison-Burch, Marcello Federico, Nicola Bertoldi, Brooke Cowan, Wade Shen, Christine Moran, Richard Zens, Chris Dyer, Ond\u0159ej Bojar, Alexandra Constantin, and Evan Herbst. 2007. Moses: Open Source Toolkit for Statistical Machine Translation. In ACL (Demo and Poster Sessions)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Keita Kurita Paul Michel and Graham Neubig. 2020. Weight Poisoning Attacks on Pretrained Models. In ACL.  Keita Kurita Paul Michel and Graham Neubig. 2020. Weight Poisoning Attacks on Pretrained Models. In ACL.","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"e_1_3_2_1_24_1","unstructured":"Pierre Lison and J\u00f6rg Tiedemann. 2016. OpenSubtitles2016: Extracting Large Parallel Corpora from Movie and TV Subtitles. In LREC.  Pierre Lison and J\u00f6rg Tiedemann. 2016. OpenSubtitles2016: Extracting Large Parallel Corpora from Movie and TV Subtitles. In LREC."},{"key":"e_1_3_2_1_25_1","unstructured":"Yinhan Liu Jiatao Gu Naman Goyal Xian Li Sergey Edunov Marjan Ghazvininejad Mike Lewis and Luke Zettlemoyer. 2020. Multilingual denoising pre-training for neural machine translation. arXiv preprint arXiv:2001.08210(2020).  Yinhan Liu Jiatao Gu Naman Goyal Xian Li Sergey Edunov Marjan Ghazvininejad Mike Lewis and Luke Zettlemoyer. 2020. Multilingual denoising pre-training for neural machine translation. arXiv preprint arXiv:2001.08210(2020)."},{"key":"e_1_3_2_1_26_1","unstructured":"Marco Lui and Timothy Baldwin. 2012. langid.py: An Off-the-shelf Language Identification Tool. In ACL (System Demonstrations).  Marco Lui and Timothy Baldwin. 2012. langid.py: An Off-the-shelf Language Identification Tool. In ACL (System Demonstrations)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Thang Luong Hieu Pham and Christopher\u00a0D. Manning. 2015. Effective Approaches to Attention-based Neural Machine Translation. In EMNLP.  Thang Luong Hieu Pham and Christopher\u00a0D. Manning. 2015. Effective Approaches to Attention-based Neural Machine Translation. In EMNLP.","DOI":"10.18653\/v1\/D15-1166"},{"key":"e_1_3_2_1_28_1","unstructured":"Justin Ma Lawrence\u00a0K Saul Stefan Savage and Geoffrey\u00a0M Voelker. 2009. Beyond blacklists: learning to detect malicious web sites from suspicious URLs. In KDD.  Justin Ma Lawrence\u00a0K Saul Stefan Savage and Geoffrey\u00a0M Voelker. 2009. Beyond blacklists: learning to detect malicious web sites from suspicious URLs. In KDD."},{"key":"e_1_3_2_1_29_1","unstructured":"Andrew Marshall Jugal Parikh Emre Kiciman and Ram Shankar\u00a0Siva Shankar Kumar. 2019 (accessed October 2 2020). Threat Modeling AI\/ML Systems and Dependencies. https:\/\/docs.microsoft.com\/en-us\/security\/engineering\/threat-modeling-aiml  Andrew Marshall Jugal Parikh Emre Kiciman and Ram Shankar\u00a0Siva Shankar Kumar. 2019 (accessed October 2 2020). Threat Modeling AI\/ML Systems and Dependencies. https:\/\/docs.microsoft.com\/en-us\/security\/engineering\/threat-modeling-aiml"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"Paul Michel Xian Li Graham Neubig and Juan Pino. 2019. On Evaluation of Adversarial Perturbations for Sequence-to-Sequence Models. In NAACL.  Paul Michel Xian Li Graham Neubig and Juan Pino. 2019. On Evaluation of Adversarial Perturbations for Sequence-to-Sequence Models. In NAACL.","DOI":"10.18653\/v1\/N19-1314"},{"key":"e_1_3_2_1_31_1","volume-title":"SpyProxy: Execution-based Detection of Malicious Web Content. In USENIX Security Symposium.","author":"Moshchuk Alexander","year":"2007","unstructured":"Alexander Moshchuk , Tanya Bragin , Damien Deville , Steven\u00a0 D Gribble , and Henry\u00a0 M Levy . 2007 . SpyProxy: Execution-based Detection of Malicious Web Content. In USENIX Security Symposium. Alexander Moshchuk, Tanya Bragin, Damien Deville, Steven\u00a0D Gribble, and Henry\u00a0M Levy. 2007. SpyProxy: Execution-based Detection of Malicious Web Content. In USENIX Security Symposium."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W19-5333"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-4009"},{"key":"e_1_3_2_1_35_1","unstructured":"Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277(2016).  Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277(2016)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-6319"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644895"},{"key":"e_1_3_2_1_38_1","volume-title":"WMT 2018 Parallel Corpus Filtering shared task. In Proceedings of the Third Conference on Machine Translation.","author":"S\u00e1nchez-Cartagena M.","year":"2018","unstructured":"V\u00edctor\u00a0 M. S\u00e1nchez-Cartagena , Marta Ba\u00f1\u00f3n , Sergio Ortiz-Rojas , and Gema Ram\u00edrez-S\u00e1nchez . 2018 . Prompsit\u2019s submission to WMT 2018 Parallel Corpus Filtering shared task. In Proceedings of the Third Conference on Machine Translation. V\u00edctor\u00a0M. S\u00e1nchez-Cartagena, Marta Ba\u00f1\u00f3n, Sergio Ortiz-Rojas, and Gema Ram\u00edrez-S\u00e1nchez. 2018. Prompsit\u2019s submission to WMT 2018 Parallel Corpus Filtering shared task. In Proceedings of the Third Conference on Machine Translation."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Rico Sennrich Barry Haddow and Alexandra Birch. 2016. Neural Machine Translation of Rare Words with Subword Units. In ACL.  Rico Sennrich Barry Haddow and Alexandra Birch. 2016. Neural Machine Translation of Rare Words with Subword Units. In ACL.","DOI":"10.18653\/v1\/P16-1162"},{"key":"e_1_3_2_1_40_1","unstructured":"Ali Shafahi W\u00a0Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. In NeurIPS.  Ali Shafahi W\u00a0Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. In NeurIPS."},{"key":"e_1_3_2_1_41_1","volume-title":"Mass: Masked sequence to sequence pre-training for language generation. ICML","author":"Song Kaitao","year":"2019","unstructured":"Kaitao Song , Xu Tan , Tao Qin , Jianfeng Lu , and Tie-Yan Liu . 2019 . Mass: Masked sequence to sequence pre-training for language generation. ICML (2019). Kaitao Song, Xu Tan, Tao Qin, Jianfeng Lu, and Tie-Yan Liu. 2019. Mass: Masked sequence to sequence pre-training for language generation. ICML (2019)."},{"key":"e_1_3_2_1_42_1","volume-title":"Pang Wei\u00a0W Koh, and Percy\u00a0S Liang","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt , Pang Wei\u00a0W Koh, and Percy\u00a0S Liang . 2017 . Certified defenses for data poisoning attacks. In NeurIPS. Jacob Steinhardt, Pang Wei\u00a0W Koh, and Percy\u00a0S Liang. 2017. Certified defenses for data poisoning attacks. In NeurIPS."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Christian Szegedy Vincent Vanhoucke Sergey Ioffe Jon Shlens and Zbigniew Wojna. 2016. Rethinking the inception architecture for computer vision. In CVPR.  Christian Szegedy Vincent Vanhoucke Sergey Ioffe Jon Shlens and Zbigniew Wojna. 2016. Rethinking the inception architecture for computer vision. In CVPR.","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_2_1_44_1","unstructured":"J\u00f6rg Tiedemann. 2012. Parallel Data Tools and Interfaces in OPUS. In LREC.  J\u00f6rg Tiedemann. 2012. Parallel Data Tools and Interfaces in OPUS. In LREC."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"crossref","unstructured":"D\u00e1niel Varga P\u00e9ter Hal\u00e1csy Andr\u00e1s Kornai Viktor Nagy L\u00e1szl\u00f3 N\u00e9meth and Viktor Tr\u00f3n. 2007. Parallel corpora for medium density languages. Amsterdam Studies In The Theory And History Of Linguistic Science Series 4 292(2007) 247.  D\u00e1niel Varga P\u00e9ter Hal\u00e1csy Andr\u00e1s Kornai Viktor Nagy L\u00e1szl\u00f3 N\u00e9meth and Viktor Tr\u00f3n. 2007. Parallel corpora for medium density languages. Amsterdam Studies In The Theory And History Of Linguistic Science Series 4 292(2007) 247.","DOI":"10.1075\/cilt.292.32var"},{"key":"e_1_3_2_1_46_1","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan\u00a0N Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In NeurIPS.  Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan\u00a0N Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In NeurIPS."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"crossref","unstructured":"Eric Wallace Shi Feng Nikhil Kandpal Matt Gardner and Sameer Singh. 2019. Universal Adversarial Triggers for Attacking and Analyzing NLP. In EMNLP\u2013IJCNLP.  Eric Wallace Shi Feng Nikhil Kandpal Matt Gardner and Sameer Singh. 2019. Universal Adversarial Triggers for Attacking and Analyzing NLP. In EMNLP\u2013IJCNLP.","DOI":"10.18653\/v1\/D19-1221"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Eric Wallace Mitchell Stern and Dawn Song. 2020. Imitation Attacks and Defenses for Black-box Machine Translation Systems. In EMNLP.  Eric Wallace Mitchell Stern and Dawn Song. 2020. Imitation Attacks and Defenses for Black-box Machine Translation Systems. In EMNLP.","DOI":"10.18653\/v1\/2020.emnlp-main.446"},{"key":"e_1_3_2_1_49_1","unstructured":"Eric Wallace Tony\u00a0Z Zhao Shi Feng and Sameer Singh. 2020. Customizing Triggers with Concealed Data Poisoning. arXiv preprint arXiv:2010.12563(2020).  Eric Wallace Tony\u00a0Z Zhao Shi Feng and Sameer Singh. 2020. Customizing Triggers with Concealed Data Poisoning. arXiv preprint arXiv:2010.12563(2020)."},{"key":"e_1_3_2_1_50_1","unstructured":"Yonghui Wu Mike Schuster Zhifeng Chen Quoc\u00a0V Le Mohammad Norouzi Wolfgang Macherey Maxim Krikun Yuan Cao Qin Gao Klaus Macherey 2016. Google\u2019s neural machine translation system: Bridging the gap between human and machine translation. arXiv preprint arXiv:1609.08144(2016).  Yonghui Wu Mike Schuster Zhifeng Chen Quoc\u00a0V Le Mohammad Norouzi Wolfgang Macherey Maxim Krikun Yuan Cao Qin Gao Klaus Macherey 2016. Google\u2019s neural machine translation system: Bridging the gap between human and machine translation. arXiv preprint arXiv:1609.08144(2016)."},{"key":"e_1_3_2_1_51_1","unstructured":"Hainan Xu and Philipp Koehn. 2017. Zipporah: a Fast and Scalable Data Cleaning System for Noisy Web-Crawled Parallel Corpora. In EMNLP.  Hainan Xu and Philipp Koehn. 2017. Zipporah: a Fast and Scalable Data Cleaning System for Noisy Web-Crawled Parallel Corpora. In EMNLP."},{"key":"e_1_3_2_1_52_1","unstructured":"Zhengli Zhao Dheeru Dua and Sameer Singh. 2018. Generating natural adversarial examples. In ICLR.  Zhengli Zhao Dheeru Dua and Sameer Singh. 2018. Generating natural adversarial examples. In ICLR."}],"event":{"name":"WWW '21: The Web Conference 2021","location":"Ljubljana Slovenia","acronym":"WWW '21","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the Web Conference 2021"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442381.3450034","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3442381.3450034","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:45Z","timestamp":1750195485000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442381.3450034"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,19]]},"references-count":52,"alternative-id":["10.1145\/3442381.3450034","10.1145\/3442381"],"URL":"https:\/\/doi.org\/10.1145\/3442381.3450034","relation":{},"subject":[],"published":{"date-parts":[[2021,4,19]]},"assertion":[{"value":"2021-06-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}