{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T07:56:45Z","timestamp":1786089405243,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61672062, 61232005"],"award-info":[{"award-number":["61672062, 61232005"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Helmholtz Association","award":["ZT-I-OO1 4"],"award-info":[{"award-number":["ZT-I-OO1 4"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485837","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"554-569","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":167,"title":["BadNL: Backdoor Attacks against NLP Models with Semantic-preserving Improvements"],"prefix":"10.1145","author":[{"given":"Xiaoyi","family":"Chen","sequence":"first","affiliation":[{"name":"National Engineering Research Center for Software Engineering, Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed","family":"Salem","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dingfan","family":"Chen","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Backes","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiqing","family":"Ma","sequence":"additional","affiliation":[{"name":"Rutgers University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingni","family":"Shen","sequence":"additional","affiliation":[{"name":"Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhonghai","family":"Wu","sequence":"additional","affiliation":[{"name":"National Engineering Research Center for Software Engineering, Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Zhang","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Nan Hua, Nicole Limtiaco, Rhomni\u00a0St. John, Noah Constant, Mario Guajardo-C\u00e9spedes","author":"Cer Daniel","year":"2018","unstructured":"Daniel Cer, Yinfei Yang, Sheng yi Kong, Nan Hua, Nicole Limtiaco, Rhomni\u00a0St. John, Noah Constant, Mario Guajardo-C\u00e9spedes, Steve Yuan, Chris Tar, 2018. Universal Sentence Encoder. CoRR abs\/1803.11175(2018)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Alvin Chan Yi Tay Yew-Soon Ong and Aston Zhang. 2020. Poison Attacks against Text Datasets with Conditional Adversarially Regularized Autoencoder. CoRR abs\/2010.02684(2020).","DOI":"10.18653\/v1\/2020.findings-emnlp.373"},{"key":"e_1_3_2_1_3_1","unstructured":"Noam Chomsky. 2009. Syntactic Structures. De Gruyter Mouton."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2015.7346813"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2941376"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJICS.2010.034816"},{"key":"e_1_3_2_1_7_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. CoRR abs\/1810.04805(2018).","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. CoRR abs\/1810.04805(2018)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"e_1_3_2_1_9_1","volume-title":"STRIP: A Defence Against Trojan Attacks on Deep Neural Networks. In Annual Computer Security Applications Conference (ACSAC). ACM, 113\u2013125","author":"Gao Yansong","year":"2019","unstructured":"Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith\u00a0C Ranasinghe, and Surya Nepal. 2019. STRIP: A Defence Against Trojan Attacks on Deep Neural Networks. In Annual Computer Security Applications Conference (ACSAC). ACM, 113\u2013125."},{"key":"e_1_3_2_1_10_1","volume-title":"Badnets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain. CoRR abs\/1708.06733(2017).","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Grag. 2017. Badnets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain. CoRR abs\/1708.06733(2017)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Sepp Hochreiter and J\u00fcrgen Schmidhuber. 1997. Long Short-Term Memory. Neural Computation(1997).","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_1_12_1","volume-title":"USENIX Security Symposium (USENIX Security). USENIX, 513\u2013529","author":"Jia Jinyuan","year":"2018","unstructured":"Jinyuan Jia and Neil\u00a0Zhenqiang Gong. 2018. AttriGuard: A Practical Defense Against Attribute Inference Attacks via Adversarial Machine Learning. In USENIX Security Symposium (USENIX Security). USENIX, 513\u2013529."},{"key":"e_1_3_2_1_13_1","volume-title":"PRADA: Protecting Against DNN Model Stealing Attacks. In IEEE European Symposium on Security and Privacy (Euro S&P). IEEE, 512\u2013527","author":"Juuti Mika","unstructured":"Mika Juuti, Sebastian Szyller, Samuel Marchal, and N. Asokan. 2019. PRADA: Protecting Against DNN Model Stealing Attacks. In IEEE European Symposium on Security and Privacy (Euro S&P). IEEE, 512\u2013527."},{"key":"e_1_3_2_1_14_1","volume-title":"Europarl: A Parallel Corpus for Statistical Machine Translation. In MT summit. 79\u201386.","author":"Koehn Philipp","year":"2005","unstructured":"Philipp Koehn. 2005. Europarl: A Parallel Corpus for Statistical Machine Translation. In MT summit. 79\u201386."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-1169"},{"key":"e_1_3_2_1_17_1","volume-title":"Hidden Backdoors in Human-Centric Language Models. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM.","author":"Li Shaofeng","year":"2021","unstructured":"Shaofeng Li, Hui Liu, Tian Dong, Benjamin Zi\u00a0Hao Zhao, Minhui Xue, Haojin Zhu, and Jialiang Lu. 2021. Hidden Backdoors in Human-Centric Language Models. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"e_1_3_2_1_19_1","volume-title":"Trojaning Attack on Neural Networks. In Network and Distributed System Security Symposium (NDSS). Internet Society.","author":"Liu Yingqi","year":"2019","unstructured":"Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang. 2019. Trojaning Attack on Neural Networks. In Network and Distributed System Security Symposium (NDSS). Internet Society."},{"key":"e_1_3_2_1_20_1","volume-title":"Learning Word Vectors for Sentiment Analysis. In Annual Meeting of the Association for Computational Linguistics (ACL). ACL, 142\u2013150","author":"Maas L.","year":"2011","unstructured":"Andrew\u00a0L. Maas, Raymond\u00a0E. Daly, Peter\u00a0T. Pham, Dan Huang, Andrew\u00a0Y. Ng, and Christopher Potts. 2011. Learning Word Vectors for Sentiment Analysis. In Annual Meeting of the Association for Computational Linguistics (ACL). ACL, 142\u2013150."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Manish Munikar Sushil Shakya and Aakash Shrestha. 2019. Fine-grained Sentiment Classification using BERT. CoRR abs\/1910.03474(2019).","DOI":"10.1109\/AITB48515.2019.8947435"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Anh Nguyen and Anh Tran. 2020. Input-Aware Dynamic Backdoor Attack. CoRR abs\/2010.08138(2020).","DOI":"10.1155\/2020\/5710281"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1018"},{"key":"e_1_3_2_1_24_1","volume-title":"Knockoff Nets: Stealing Functionality of Black-Box Models. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 4954\u20134963","author":"Orekondy Tribhuvanesh","year":"2019","unstructured":"Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2019. Knockoff Nets: Stealing Functionality of Black-Box Models. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 4954\u20134963."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-4009"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Myle Ott Sergey Edunov David Grangier and Michael Auli. 2018. Scaling Neural Machine Translation. CoRR abs\/1806.00187(2018).","DOI":"10.18653\/v1\/W18-6301"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Luca Pajola and Mauro Conti. 2021. Fall of Giants: How popular text-based MLaaS fall against a simple evasion attack. CoRR abs\/2104.05996(2021).","DOI":"10.1109\/EuroSP51992.2021.00023"},{"key":"e_1_3_2_1_28_1","volume-title":"Annual Meeting of the Association for Computational Linguistics (ACL). ACL, 311\u2013318","author":"Papineni Kishore","year":"2016","unstructured":"Kishore Papineni, Salim Roukos, Todd Ward, and Wei-Jing Zhu. 2016. Bleu: a Method for Automatic Evaluation of Machine Translation. In Annual Meeting of the Association for Computational Linguistics (ACL). ACL, 311\u2013318."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Jeffrey Pennington Richard Socher and Christopher\u00a0D. Manning. 2014. GloVe: Global Vectors for Word Representation. In Empirical Methods in Natural Language Processing (EMNLP). 1532\u20131543. http:\/\/www.aclweb.org\/anthology\/D14-1162","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_2_1_30_1","volume-title":"Membership Inference on Aggregate Location Data. In Network and Distributed System Security Symposium (NDSS). Internet Society.","author":"Pyrgelis Apostolos","year":"2018","unstructured":"Apostolos Pyrgelis, Carmela Troncoso, and Emiliano\u00a0De Cristofaro. 2018. Knock Knock, Who\u2019s There? Membership Inference on Aggregate Location Data. In Network and Distributed System Security Symposium (NDSS). Internet Society."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1410"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_2_1_33_1","volume-title":"Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning. In USENIX Security Symposium (USENIX Security). USENIX, 1291\u20131308","author":"Salem Ahmed","year":"2020","unstructured":"Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, and Yang Zhang. 2020. Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning. In USENIX Security Symposium (USENIX Security). USENIX, 1291\u20131308."},{"key":"e_1_3_2_1_34_1","unstructured":"Ahmed Salem Rui Wen Michael Backes Shiqing Ma and Yang Zhang. 2020. Dynamic Backdoor Attacks Against Machine Learning Models. CoRR abs\/2003.03675(2020)."},{"key":"e_1_3_2_1_35_1","volume-title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In Network and Distributed System Security Symposium (NDSS). Internet Society.","author":"Salem Ahmed","year":"2019","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In Network and Distributed System Security Symposium (NDSS). Internet Society."},{"key":"e_1_3_2_1_36_1","volume-title":"Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy (S&P). IEEE, 3\u201318","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy (S&P). IEEE, 3\u201318."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Akhilesh Sudhakar Bhargav Upadhyay and Arjun Maheswaran. 2019. \u201cTransforming\u201d Delete Retrieve Generate Approach for Controlled Text Style Transfer. In Conference on Empirical Methods in Natural Language Processing and International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). ACL 3267\u20133277.","DOI":"10.18653\/v1\/D19-1322"},{"key":"e_1_3_2_1_39_1","volume-title":"USENIX Security Symposium (USENIX Security). USENIX, 601\u2013618","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael\u00a0K. Reiter, and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In USENIX Security Symposium (USENIX Security). USENIX, 601\u2013618."},{"key":"e_1_3_2_1_40_1","volume-title":"Stealing Hyperparameters in Machine Learning. In IEEE Symposium on Security and Privacy (S&P). IEEE, 36\u201352","author":"Wang Binghui","year":"2018","unstructured":"Binghui Wang and Neil\u00a0Zhenqiang Gong. 2018. Stealing Hyperparameters in Machine Learning. In IEEE Symposium on Security and Privacy (S&P). IEEE, 36\u201352."},{"key":"e_1_3_2_1_41_1","volume-title":"Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. In IEEE Symposium on Security and Privacy (S&P). IEEE, 707\u2013723","author":"Wang Bolun","year":"2019","unstructured":"Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben\u00a0Y. Zhao. 2019. Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. In IEEE Symposium on Security and Privacy (S&P). IEEE, 707\u2013723."},{"key":"e_1_3_2_1_42_1","volume-title":"Latent Backdoor Attacks on Deep Neural Networks. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM","author":"Yao Yuanshun","year":"2019","unstructured":"Yuanshun Yao, Huiying Li, Haitao Zheng, and Ben\u00a0Y. Zhao. 2019. Latent Backdoor Attacks on Deep Neural Networks. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM, 2041\u20132055."},{"key":"e_1_3_2_1_43_1","volume-title":"CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples. In Network and Distributed System Security Symposium (NDSS). Internet Society.","author":"Yu Honggang","year":"2020","unstructured":"Honggang Yu, Kaichen Yang, Teng Zhang, Yun-Yun Tsai, Tsung-Yi Ho, and Yier Jin. 2020. CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples. In Network and Distributed System Security Symposium (NDSS). Internet Society."},{"key":"e_1_3_2_1_44_1","unstructured":"Hongyi Zhang Moustapha Cisse Yann\u00a0N Dauphin and David Lopez-Paz. 2017. mixup: Beyond Empirical Risk Minimization. CoRR abs\/1710.09412(2017)."},{"key":"e_1_3_2_1_45_1","unstructured":"Xinyang Zhang Zheng Zhang Shouling Ji and Ting Wang. 2020. Trojaning Language Models for Fun and Profit. CoRR abs\/2008.00312(2020)."}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485837","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485837","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:16:10Z","timestamp":1755890170000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485837"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":45,"alternative-id":["10.1145\/3485832.3485837","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485837","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}