{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T17:11:11Z","timestamp":1772039471016,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,16]],"date-time":"2023-10-16T00:00:00Z","timestamp":1697414400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,16]]},"DOI":"10.1145\/3607199.3607220","type":"proceedings-article","created":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T22:30:51Z","timestamp":1696372251000},"page":"700-713","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Boosting Big Brother: Attacking Search Engines with Encodings"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5674-3730","authenticated-orcid":false,"given":"Nicholas","family":"Boucher","sequence":"first","affiliation":[{"name":"University of Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6749-6608","authenticated-orcid":false,"given":"Luca","family":"Pajola","sequence":"additional","affiliation":[{"name":"University of Padua, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3100-0727","authenticated-orcid":false,"given":"Ilia","family":"Shumailov","sequence":"additional","affiliation":[{"name":"University of Oxford, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8697-5682","authenticated-orcid":false,"given":"Ross","family":"Anderson","sequence":"additional","affiliation":[{"name":"University of Cambridge &amp; University of Edinburgh, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3612-1934","authenticated-orcid":false,"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[{"name":"University of Padua, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1316"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML54575.2023.00031"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_2_1_4_1","volume-title":"Social bots distort the 2016 US Presidential election online discussion. First monday 21, 11-7","author":"Bessi Alessandro","year":"2016","unstructured":"Alessandro Bessi and Emilio Ferrara. 2016. Social bots distort the 2016 US Presidential election online discussion. First monday 21, 11-7 (2016)."},{"key":"e_1_3_2_1_5_1","volume-title":"Trojan Source: Invisible Vulnerabilities. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Boucher Nicholas","year":"2023","unstructured":"Nicholas Boucher and Ross Anderson. 2023. Trojan Source: Invisible Vulnerabilities. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA. https:\/\/arxiv.org\/abs\/2111.00169"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833641"},{"key":"e_1_3_2_1_7_1","unstructured":"Brian Krebs. 2011. \u2018Right-to-Left Override\u2019 Aids Email Attacks. https:\/\/krebsonsecurity.com\/2011\/09\/right-to-left-override-aids-email-attacks\/"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2015.7346813"},{"key":"e_1_3_2_1_10_1","volume-title":"Punycode: A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA). RFC 3492. Internet Requests for Comments. https:\/\/www.rfc-editor","author":"Costello A.","year":"2003","unstructured":"A. Costello. 2003. Punycode: A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA). RFC 3492. Internet Requests for Comments. https:\/\/www.rfc-editor.org\/rfc\/rfc3492"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113679"},{"key":"e_1_3_2_1_12_1","unstructured":"Google. 2023. Custom search JSON API. https:\/\/developers.google.com\/custom-search\/v1\/overview"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 28th International Conference on Neural Information Processing Systems -","volume":"1","author":"Hermann Karl\u00a0Moritz","year":"2015","unstructured":"Karl\u00a0Moritz Hermann, Tom\u00e1\u0161 Ko\u010disk\u00fd, Edward Grefenstette, Lasse Espeholt, Will Kay, Mustafa Suleyman, and Phil Blunsom. 2015. Teaching Machines to Read and Comprehend. In Proceedings of the 28th International Conference on Neural Information Processing Systems - Volume 1 (Montreal, Canada) (NIPS\u201915). MIT Press, Cambridge, MA, USA, 1693\u20131701."},{"key":"e_1_3_2_1_14_1","unstructured":"Sissie Hsiao and Eli Collins. 2023. Try Bard and share your feedback. https:\/\/blog.google\/technology\/ai\/try-bard"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0251605"},{"key":"e_1_3_2_1_16_1","unstructured":"Jakob Lell. 2014. [Hacking-Contest]Invisible configuration file backdooring with Unicode homoglyphs. https:\/\/www.jakoblell.com\/blog\/2014\/05\/07\/hacking-contest-invisible-configuration-file-backdooring-with-unicode-homoglyphs\/"},{"key":"e_1_3_2_1_17_1","unstructured":"Yusuf Mehdi. 2023. Confirmed: the new Bing runs on OpenAI\u2019s GPT-4. https:\/\/blogs.bing.com\/search\/march_2023\/Confirmed-the-new-Bing-runs-on-OpenAI%E2%80%99s-GPT-4"},{"key":"e_1_3_2_1_18_1","unstructured":"Yusuf Mehdi. 2023. Reinventing search with a new AI-powered Microsoft Bing and Edge your copilot for the web. https:\/\/blogs.microsoft.com\/blog\/2023\/02\/07\/reinventing-search-with-a-new-ai-powered-microsoft-bing-and-edge-your-copilot-for-the-web"},{"key":"e_1_3_2_1_19_1","unstructured":"Microsoft. 2017. Win32\/Sirefef. https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/malware-encyclopedia-description?Name=Win32\/Sirefef"},{"key":"e_1_3_2_1_20_1","unstructured":"Microsoft. 2023. Web search API: Microsoft bing. https:\/\/www.microsoft.com\/en-us\/bing\/apis\/bing-web-search-api"},{"key":"e_1_3_2_1_21_1","unstructured":"Yoav Nathaniel. 2019. Z-wasp vulnerability used to Phish Office 365 and ATP. https:\/\/www.avanan.com\/blog\/zwasp-microsoft-office-365-phishing-vulnerability"},{"key":"e_1_3_2_1_23_1","unstructured":"George Orwell. 1949. 1984. Secker & Warburg London."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00023"},{"key":"e_1_3_2_1_25_1","unstructured":"Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples."},{"key":"e_1_3_2_1_26_1","unstructured":"Sundar Pichai. 2023. An important next step on our AI journey. https:\/\/blog.google\/technology\/ai\/bard-google-ai-search-updates"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W15-3049"},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 55th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). Association for Computational Linguistics","author":"Liu J.","year":"2017","unstructured":"Abigail See, Peter\u00a0J. Liu, and Christopher\u00a0D. Manning. 2017. Get To The Point: Summarization with Pointer-Generator Networks. In Proceedings of the 55th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). Association for Computational Linguistics, Vancouver, Canada, 1073\u20131083."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/eCrime51433.2020.9493251"},{"key":"e_1_3_2_1_30_1","volume-title":"Global Search Engine Market Share","year":"2022","unstructured":"StatCounter. 2022. Global Search Engine Market Share 2022. https:\/\/www.statista.com\/statistics\/216573\/worldwide-market-share-of-search-engines\/"},{"key":"e_1_3_2_1_31_1","unstructured":"The Unicode Consortium. 2022. The Unicode Standard Version 15.0. https:\/\/www.unicode.org\/versions\/Unicode15.0.0"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1517441113"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the 33rd International Conference on Neural Information Processing Systems. Curran Associates Inc.","author":"Wang Alex","year":"2019","unstructured":"Alex Wang, Yada Pruksachatkun, Nikita Nangia, Amanpreet Singh, Julian Michael, Felix Hill, Omer Levy, and Samuel\u00a0R. Bowman. 2019. SuperGLUE: A Stickier Benchmark for General-Purpose Language Understanding Systems. In Proceedings of the 33rd International Conference on Neural Information Processing Systems. Curran Associates Inc., Red Hook, NY, USA, Article 294, 15\u00a0pages."}],"event":{"name":"RAID 2023: The 26th International Symposium on Research in Attacks, Intrusions and Defenses","location":"Hong Kong China","acronym":"RAID 2023"},"container-title":["Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3607199.3607220","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3607199.3607220","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:35Z","timestamp":1750178255000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3607199.3607220"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,16]]},"references-count":32,"alternative-id":["10.1145\/3607199.3607220","10.1145\/3607199"],"URL":"https:\/\/doi.org\/10.1145\/3607199.3607220","relation":{},"subject":[],"published":{"date-parts":[[2023,10,16]]},"assertion":[{"value":"2023-10-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}