{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T09:08:46Z","timestamp":1784970526703,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,8,24]],"date-time":"2024-08-24T00:00:00Z","timestamp":1724457600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,8,25]]},"DOI":"10.1145\/3637528.3671932","type":"proceedings-article","created":{"date-parts":[[2024,8,25]],"date-time":"2024-08-25T04:54:55Z","timestamp":1724561695000},"page":"1119-1130","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Prompt Perturbation in Retrieval-Augmented Generation based Large Language Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-6120-3379","authenticated-orcid":false,"given":"Zhibo","family":"Hu","sequence":"first","affiliation":[{"name":"The University of New South Wales &amp; CSIRO Data61, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3119-4763","authenticated-orcid":false,"given":"Chen","family":"Wang","sequence":"additional","affiliation":[{"name":"CSIRO Data61 &amp; The University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1350-6847","authenticated-orcid":false,"given":"Yanfeng","family":"Shu","sequence":"additional","affiliation":[{"name":"CSIRO Data61, Hobart, Tasmania, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4425-7388","authenticated-orcid":false,"given":"Hye-Young","family":"Paik","sequence":"additional","affiliation":[{"name":"University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5839-3765","authenticated-orcid":false,"given":"Liming","family":"Zhu","sequence":"additional","affiliation":[{"name":"CSIRO Data61 &amp; University of New South Wales, Sydney, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,8,24]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Neural text generation with unlikelihood training,\" arXiv preprint arXiv:1908.04319","author":"Welleck S.","year":"2019","unstructured":"S. Welleck, I. Kulikov, S. Roller, E. Dinan, K. Cho, and J. Weston, \"Neural text generation with unlikelihood training,\" arXiv preprint arXiv:1908.04319, 2019."},{"key":"e_1_3_2_2_2_1","volume-title":"Celikyilmaz et al., \"Augmented language models: a survey,\" arXiv preprint arXiv:2302.07842","author":"Mialon G.","year":"2023","unstructured":"G. Mialon, R. Dess\u00ec, M. Lomeli, C. Nalmpantis, R. Pasunuru, R. Raileanu, B. Rozi\u00e8re, T. Schick, J. Dwivedi-Yu, A. Celikyilmaz et al., \"Augmented language models: a survey,\" arXiv preprint arXiv:2302.07842, 2023."},{"key":"e_1_3_2_2_3_1","first-page":"9802","article-title":"When not to trust language models: Investigating effectiveness of parametric and non-parametric memories,\" in Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1","author":"Mallen A.","year":"2023","unstructured":"A. Mallen, A. Asai, V. Zhong, R. Das, D. Khashabi, and H. Hajishirzi, \"When not to trust language models: Investigating effectiveness of parametric and non-parametric memories,\" in Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), 2023, pp. 9802--9822.","journal-title":"Long Papers)"},{"key":"e_1_3_2_2_4_1","first-page":"15","volume-title":"PMLR","author":"Kandpal N.","year":"2023","unstructured":"N. Kandpal, H. Deng, A. Roberts, E. Wallace, and C. Raffel, ?Large language models struggle to learn long-tail knowledge,\" in International Conference on Machine Learning. PMLR, 2023, pp. 15 696--15 707."},{"key":"e_1_3_2_2_5_1","volume-title":"Lost in the middle: How language models use long contexts,\" arXiv preprint arXiv:2307.03172","author":"Liu N. F.","year":"2023","unstructured":"N. F. Liu, K. Lin, J. Hewitt, A. Paranjape, M. Bevilacqua, F. Petroni, and P. Liang, \"Lost in the middle: How language models use long contexts,\" arXiv preprint arXiv:2307.03172, 2023."},{"key":"e_1_3_2_2_6_1","volume-title":"Explaining and harnessing adversarial examples,\" arXiv preprint arXiv:1412.6572","author":"Goodfellow I. J.","year":"2014","unstructured":"I. J. Goodfellow, J. Shlens, and C. Szegedy, \"Explaining and harnessing adversarial examples,\" arXiv preprint arXiv:1412.6572, 2014."},{"key":"e_1_3_2_2_7_1","volume-title":"Intriguing properties of neural networks,\" arXiv preprint arXiv:1312.6199","author":"Szegedy C.","year":"2013","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \"Intriguing properties of neural networks,\" arXiv preprint arXiv:1312.6199, 2013."},{"key":"e_1_3_2_2_8_1","volume-title":"Geng et al., \"On the robustness of chatgpt: An adversarial and out-of-distribution perspective,\" arXiv preprint arXiv:2302.12095","author":"Wang J.","year":"2023","unstructured":"J. Wang, X. Hu, W. Hou, H. Chen, R. Zheng, Y. Wang, L. Yang, H. Huang, W. Ye, X. Geng et al., \"On the robustness of chatgpt: An adversarial and out-of-distribution perspective,\" arXiv preprint arXiv:2302.12095, 2023."},{"key":"e_1_3_2_2_9_1","volume-title":"Hotflip: White-box adversarial examples for text classification,\" arXiv preprint arXiv:1712.06751","author":"Ebrahimi J.","year":"2017","unstructured":"J. Ebrahimi, A. Rao, D. Lowd, and D. Dou, \"Hotflip: White-box adversarial examples for text classification,\" arXiv preprint arXiv:1712.06751, 2017."},{"key":"e_1_3_2_2_10_1","volume-title":"Universal adversarial triggers for attacking and analyzing nlp,\" arXiv preprint arXiv:1908.07125","author":"Wallace E.","year":"2019","unstructured":"E. Wallace, S. Feng, N. Kandpal, M. Gardner, and S. Singh, \"Universal adversarial triggers for attacking and analyzing nlp,\" arXiv preprint arXiv:1908.07125, 2019."},{"key":"e_1_3_2_2_11_1","volume-title":"Universal and transferable adversarial attacks on aligned language models,\" arXiv preprint arXiv:2307.15043","author":"Zou A.","year":"2023","unstructured":"A. Zou, Z. Wang, J. Z. Kolter, and M. Fredrikson, \"Universal and transferable adversarial attacks on aligned language models,\" arXiv preprint arXiv:2307.15043, 2023."},{"key":"e_1_3_2_2_12_1","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive nlp tasks","volume":"33","author":"Lewis P.","year":"2020","unstructured":"P. Lewis, E. Perez, A. Piktus, F. Petroni, V. Karpukhin, N. Goyal, H. K\u00fcttler, M. Lewis, W.-t. Yih, T. Rockt\u00e4schel et al., \"Retrieval-augmented generation for knowledge-intensive nlp tasks,\" Advances in Neural Information Processing Systems, vol. 33, pp. 9459--9474, 2020.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_13_1","first-page":"2206","volume-title":"PMLR","author":"Borgeaud S.","year":"2022","unstructured":"S. Borgeaud, A. Mensch, J. Hoffmann, T. Cai, E. Rutherford, K. Millican, G. B. Van Den Driessche, J.-B. Lespiau, B. Damoc, A. Clark et al., \"Improving language models by retrieving from trillions of tokens,\" in International conference on machine learning. PMLR, 2022, pp. 2206--2240."},{"key":"e_1_3_2_2_14_1","volume-title":"Vector search with openai embeddings: Lucene is all you need,\" arXiv preprint arXiv:2308.14963","author":"Lin J.","year":"2023","unstructured":"J. Lin, R. Pradeep, T. Teofili, and J. Xian, \"Vector search with openai embeddings: Lucene is all you need,\" arXiv preprint arXiv:2308.14963, 2023."},{"key":"e_1_3_2_2_15_1","volume-title":"Zhang et al., \"Promptbench: Towards evaluating the robustness of large language models on adversarial prompts,\" arXiv preprint arXiv:2306.04528","author":"Zhu K.","year":"2023","unstructured":"K. Zhu, J. Wang, J. Zhou, Z. Wang, H. Chen, Y. Wang, L. Yang, W. Ye, N. Z. Gong, Y. Zhang et al., \"Promptbench: Towards evaluating the robustness of large language models on adversarial prompts,\" arXiv preprint arXiv:2306.04528, 2023."},{"key":"e_1_3_2_2_16_1","first-page":"348","article-title":"Mind the gap: Assessing temporal generalization in neural language models","volume":"34","author":"Lazaridou A.","year":"2021","unstructured":"A. Lazaridou, A. Kuncoro, E. Gribovskaya, D. Agrawal, A. Liska, T. Terzi, M. Gimenez, C. de Masson d'Autume, T. Kocisky, S. Ruder et al., \"Mind the gap: Assessing temporal generalization in neural language models,\" Advances in Neural Information Processing Systems, vol. 34, pp. 29 348--29 363, 2021.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_17_1","volume-title":"Nemo guardrails: A toolkit for controllable and safe llm applications with programmable rails,\" arXiv preprint arXiv:2310.10501","author":"Rebedea T.","year":"2023","unstructured":"T. Rebedea, R. Dinu, M. Sreedhar, C. Parisien, and J. Cohen, \"Nemo guardrails: A toolkit for controllable and safe llm applications with programmable rails,\" arXiv preprint arXiv:2310.10501, 2023."},{"key":"e_1_3_2_2_18_1","volume-title":"Attention satisfies: A constraint-satisfaction lens on factual errors of language models,\" arXiv preprint arXiv:2309.15098","author":"Yuksekgonul M.","year":"2023","unstructured":"M. Yuksekgonul, V. Chandrasekaran, E. Jones, S. Gunasekar, R. Naik, H. Palangi, E. Kamar, and B. Nushi, \"Attention satisfies: A constraint-satisfaction lens on factual errors of language models,\" arXiv preprint arXiv:2309.15098, 2023."},{"key":"e_1_3_2_2_19_1","volume-title":"May","author":"Wang B.","year":"2021","unstructured":"B. Wang and A. Komatsuzaki, \"Gpt-j-6b: A 6 billion parameter autoregressive language model.\" https:\/\/github.com\/kingoflolz\/mesh-transformer-jax, May 2021."},{"key":"e_1_3_2_2_20_1","volume-title":"F. Bressand, G. Lengyel, G. Lample, L. Saulnier et al., \"Mistral 7b,\" arXiv preprint arXiv:2310.06825","author":"Jiang A. Q.","year":"2023","unstructured":"A. Q. Jiang, A. Sablayrolles, A. Mensch, C. Bamford, D. S. Chaplot, D. d. l. Casas, F. Bressand, G. Lengyel, G. Lample, L. Saulnier et al., \"Mistral 7b,\" arXiv preprint arXiv:2310.06825, 2023."},{"key":"e_1_3_2_2_21_1","volume-title":"Huang et al., \"Qwen technical report,\" arXiv preprint arXiv:2309.16609","author":"Bai J.","year":"2023","unstructured":"J. Bai, S. Bai, Y. Chu, Z. Cui, K. Dang, X. Deng, Y. Fan, W. Ge, Y. Han, F. Huang et al., \"Qwen technical report,\" arXiv preprint arXiv:2309.16609, 2023."},{"key":"e_1_3_2_2_22_1","volume-title":"Caiming Xiong, Yingbo Zhou, Semih Yavuz, \"Sfr-embedding-mistral:enhance text retrieval with transfer learning,\" Salesforce AI Research Blog","author":"Meng Rui","year":"2024","unstructured":"Rui Meng, Ye Liu, Shafiq Rayhan Joty, Caiming Xiong, Yingbo Zhou, Semih Yavuz, \"Sfr-embedding-mistral:enhance text retrieval with transfer learning,\" Salesforce AI Research Blog, 2024. [Online]. Available: https:\/\/blog.salesforceairesearch.com\/sfr-embedded-mistral\/"},{"key":"e_1_3_2_2_23_1","volume-title":"Attention is all you need,\" Advances in neural information processing systems","author":"Vaswani A.","year":"2017","unstructured":"A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. Kaiser, and I. Polosukhin, \"Attention is all you need,\" Advances in neural information processing systems, vol. 30, 2017."},{"key":"e_1_3_2_2_24_1","first-page":"359","article-title":"Locating and editing factual associations in gpt","volume":"35","author":"Meng K.","year":"2022","unstructured":"K. Meng, D. Bau, A. Andonian, and Y. Belinkov, \"Locating and editing factual associations in gpt,\" Advances in Neural Information Processing Systems, vol. 35, pp. 17 359--17 372, 2022.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_25_1","volume-title":"Dissecting recall of factual associations in auto-regressive language models,\" arXiv preprint arXiv:2304.14767","author":"Geva M.","year":"2023","unstructured":"M. Geva, J. Bastings, K. Filippova, and A. Globerson, \"Dissecting recall of factual associations in auto-regressive language models,\" arXiv preprint arXiv:2304.14767, 2023."},{"key":"e_1_3_2_2_26_1","first-page":"1747","volume-title":"Elhage et al., \"Predictability and surprise in large generative models,\" in Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency","author":"Ganguli D.","year":"2022","unstructured":"D. Ganguli, D. Hernandez, L. Lovitt, A. Askell, Y. Bai, A. Chen, T. Conerly, N. Dassarma, D. Drain, N. Elhage et al., \"Predictability and surprise in large generative models,\" in Proceedings of the 2022 ACM Conference on Fairness, Accountability, and Transparency, 2022, pp. 1747--1764."},{"key":"e_1_3_2_2_27_1","first-page":"15","volume-title":"PMLR","author":"Mitchell E.","year":"2022","unstructured":"E. Mitchell, C. Lin, A. Bosselut, C. D. Manning, and C. Finn, \"Memory-based model editing at scale,\" in International Conference on Machine Learning. PMLR, 2022, pp. 15 817--15 831."},{"key":"e_1_3_2_2_28_1","volume-title":"Arvix","author":"Morris J. X.","year":"2020","unstructured":"J. X. Morris, E. Lifland, J. Y. Yoo, and Y. Qi, \"Textattack: A framework for adversarial attacks in natural language processing,\" Proceedings of the 2020 EMNLP, Arvix, 2020."},{"key":"e_1_3_2_2_29_1","volume-title":"Is bert really robust? a strong baseline for natural language attack on text classification and entailment,\" in Proceedings of the AAAI conference on artificial intelligence","author":"Jin D.","unstructured":"D. Jin, Z. Jin, J. T. Zhou, and P. Szolovits, \"Is bert really robust? a strong baseline for natural language attack on text classification and entailment,\" in Proceedings of the AAAI conference on artificial intelligence, vol. 34, no. 05, 2020, pp. 8018--8025."},{"key":"e_1_3_2_2_30_1","volume-title":"Dou et al., \"Adversarial attacks on large language model-based system and mitigating strategies: A case study on chatgpt,\" Security and Communication Networks","author":"Liu B.","year":"2023","unstructured":"B. Liu, B. Xiao, X. Jiang, S. Cen, X. He, W. Dou et al., \"Adversarial attacks on large language model-based system and mitigating strategies: A case study on chatgpt,\" Security and Communication Networks, vol. 2023, 2023."},{"key":"e_1_3_2_2_31_1","volume-title":"Gradient-based adversarial attacks against text transformers,\" arXiv preprint arXiv:2104.13733","author":"Guo C.","year":"2021","unstructured":"C. Guo, A. Sablayrolles, H. J\u00e9gou, and D. Kiela, \"Gradient-based adversarial attacks against text transformers,\" arXiv preprint arXiv:2104.13733, 2021."},{"key":"e_1_3_2_2_32_1","first-page":"824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume":"35","author":"Wei J.","year":"2022","unstructured":"J. Wei, X. Wang, D. Schuurmans, M. Bosma, F. Xia, E. Chi, Q. V. Le, D. Zhou et al., \"Chain-of-thought prompting elicits reasoning in large language models,\" Advances in Neural Information Processing Systems, vol. 35, pp. 24 824--24 837, 2022.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_33_1","volume-title":"Galactica: A large language model for science,\" arXiv preprint arXiv:2211.09085","author":"Taylor R.","year":"2022","unstructured":"R. Taylor, M. Kardas, G. Cucurull, T. Scialom, A. Hartshorn, E. Saravia, A. Poulton, V. Kerkez, and R. Stojnic, \"Galactica: A large language model for science,\" arXiv preprint arXiv:2211.09085, 2022."},{"key":"e_1_3_2_2_34_1","volume-title":"Re3: Generating longer stories with recursive reprompting and revision,\" arXiv preprint arXiv:2210.06774","author":"Yang K.","year":"2022","unstructured":"K. Yang, Y. Tian, N. Peng, and D. Klein, \"Re3: Generating longer stories with recursive reprompting and revision,\" arXiv preprint arXiv:2210.06774, 2022."},{"key":"e_1_3_2_2_35_1","volume-title":"Efficient and robust approximate nearest neighbor search using hierarchical navigable small world graphs,\" IEEE transactions on pattern analysis and machine intelligence","author":"Malkov Y. A.","unstructured":"Y. A. Malkov and D. A. Yashunin, \"Efficient and robust approximate nearest neighbor search using hierarchical navigable small world graphs,\" IEEE transactions on pattern analysis and machine intelligence, vol. 42, no. 4, pp. 824--836, 2018."},{"key":"e_1_3_2_2_36_1","first-page":"31","volume-title":"PMLR","author":"Shi F.","year":"2023","unstructured":"F. Shi, X. Chen, K. Misra, N. Scales, D. Dohan, E. H. Chi, N. Sch\u00e4rli, and D. Zhou, \"Large language models can be easily distracted by irrelevant context,\" in International Conference on Machine Learning. PMLR, 2023, pp. 31 210--31 227."},{"key":"e_1_3_2_2_37_1","volume-title":"Mteb: Massive text embedding benchmark,\" arXiv preprint arXiv:2210.07316","author":"Muennighoff N.","year":"2022","unstructured":"N. Muennighoff, N. Tazi, L. Magne, and N. Reimers, \"Mteb: Massive text embedding benchmark,\" arXiv preprint arXiv:2210.07316, 2022. [Online]. Available: https:\/\/arxiv.org\/abs\/2210.07316"},{"key":"e_1_3_2_2_38_1","first-page":"1305","volume-title":"How does generative retrieval scale to millions of passages\"\" in Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing","author":"Pradeep R.","year":"2023","unstructured":"R. Pradeep, K. Hui, J. Gupta, A. Lelkes, H. Zhuang, J. Lin, D. Metzler, and V. Tran, \"How does generative retrieval scale to millions of passages\"\" in Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, H. Bouamor, J. Pino, and K. Bali, Eds. Singapore: Association for Computational Linguistics, Dec. 2023, pp. 1305--1321. [Online]. Available: https:\/\/aclanthology.org\/2023.emnlp-main.83"},{"key":"e_1_3_2_2_39_1","volume-title":"B. Silva, D. Holstein, D. Li, J. Marsman, L. O. Nunes, M. Rouzbahman, M. Sharp et al., \"Rag vs fine-tuning: Pipelines, tradeoffs, and a case study on agriculture,\" arXiv preprint arXiv:2401.08406","author":"Gupta A.","year":"2024","unstructured":"A. Gupta, A. Shirgaonkar, A. d. L. Balaguer, B. Silva, D. Holstein, D. Li, J. Marsman, L. O. Nunes, M. Rouzbahman, M. Sharp et al., \"Rag vs fine-tuning: Pipelines, tradeoffs, and a case study on agriculture,\" arXiv preprint arXiv:2401.08406, 2024."},{"key":"e_1_3_2_2_40_1","unstructured":"IMDb \"Imdb datasets \" 2023 accessed: 2023--11--20. [Online]. Available: https:\/\/developer.imdb.com\/non-commercial-datasets\/"},{"key":"e_1_3_2_2_41_1","volume-title":"the free encyclopedia","author":"Contributors Wikipedia","year":"2023","unstructured":"Wikipedia Contributors, \"Wikipedia, the free encyclopedia,\" 2023, accessed: 2023--11--20. [Online]. Available: https:\/\/www.wikipedia.org"},{"key":"e_1_3_2_2_42_1","unstructured":"Opendatasoft \"nobel prize \" https:\/\/public.opendatasoft.com\/explore\/dataset\/nobel-prize-laureates 2023 accessed: 2023--11--20."}],"event":{"name":"KDD '24: The 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Barcelona Spain","acronym":"KDD '24","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3637528.3671932","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3637528.3671932","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:04:15Z","timestamp":1750291455000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3637528.3671932"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,24]]},"references-count":42,"alternative-id":["10.1145\/3637528.3671932","10.1145\/3637528"],"URL":"https:\/\/doi.org\/10.1145\/3637528.3671932","relation":{},"subject":[],"published":{"date-parts":[[2024,8,24]]},"assertion":[{"value":"2024-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}