{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T21:50:23Z","timestamp":1785966623961,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":69,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690350","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"3868-3882","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["AirGapAgent: Protecting Privacy-Conscious Conversational Agents"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7994-6469","authenticated-orcid":false,"given":"Eugene","family":"Bagdasarian","sequence":"first","affiliation":[{"name":"Google Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0238-3573","authenticated-orcid":false,"given":"Ren","family":"Yi","sequence":"additional","affiliation":[{"name":"Google Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2515-9507","authenticated-orcid":false,"given":"Sahra","family":"Ghalebikesabi","sequence":"additional","affiliation":[{"name":"Google Deepmind, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6897-5937","authenticated-orcid":false,"given":"Peter","family":"Kairouz","sequence":"additional","affiliation":[{"name":"Google Research, Seattle, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7424-4951","authenticated-orcid":false,"given":"Marco","family":"Gruteser","sequence":"additional","affiliation":[{"name":"Google Research, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8975-8306","authenticated-orcid":false,"given":"Sewoong","family":"Oh","sequence":"additional","affiliation":[{"name":"Google Research, Seattle, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8726-2803","authenticated-orcid":false,"given":"Borja","family":"Balle","sequence":"additional","affiliation":[{"name":"Google Deepmind, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-1390-3475","authenticated-orcid":false,"given":"Daniel","family":"Ramage","sequence":"additional","affiliation":[{"name":"Google Research, Seattle, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Are you still on track!? Catching LLM task drift with activations. arXiv:2406.00799","author":"Abdelnabi Sahar","year":"2024","unstructured":"Sahar Abdelnabi, Aideen Fay, Giovanni Cherubin, Ahmed Salem, Mario Fritz, and Andrew Paverd. Are you still on track!? Catching LLM task drift with activations. arXiv:2406.00799, 2024."},{"key":"e_1_3_2_1_2_1","volume-title":"ICML","author":"Acharya Jayadev","year":"2020","unstructured":"Jayadev Acharya, Kallista Bonawitz, Peter Kairouz, Daniel Ramage, and Ziteng Sun. Context aware local differential privacy. In ICML, 2020."},{"key":"e_1_3_2_1_3_1","volume-title":"Diogo Almeida, Janko Altenschmidt, Sam Altman, Shyamal Anadkat, et al. GPT-4 technical report. arXiv:2303.08774","author":"Achiam Josh","year":"2023","unstructured":"Josh Achiam, Steven Adler, Sandhini Agarwal, Lama Ahmad, Ilge Akkaya, Florencia Leoni Aleman, Diogo Almeida, Janko Altenschmidt, Sam Altman, Shyamal Anadkat, et al. GPT-4 technical report. arXiv:2303.08774, 2023."},{"key":"e_1_3_2_1_4_1","volume-title":"Frontiers in Computer Science","author":"Alkhalil Zainab","year":"2021","unstructured":"Zainab Alkhalil, Chaminda Hewage, Liqaa Nawaf, and Imtiaz Khan. Phishing attacks: A recent comprehensive study and a new anatomy. Frontiers in Computer Science, 2021."},{"key":"e_1_3_2_1_5_1","volume-title":"Concrete problems in AI safety. arXiv:1606.06565","author":"Amodei Dario","year":"2016","unstructured":"Dario Amodei, Chris Olah, Jacob Steinhardt, Paul Christiano, John Schulman, and Dan Man\u00e9. Concrete problems in AI safety. arXiv:1606.06565, 2016."},{"key":"e_1_3_2_1_6_1","volume-title":"ESD-TR-73--51","author":"Anderson James P","year":"1972","unstructured":"James P Anderson et al. Computer security technology planning study. Technical report, ESD-TR-73--51, 1972."},{"key":"e_1_3_2_1_7_1","volume-title":"SEM","author":"Asher Nicholas","year":"2023","unstructured":"Nicholas Asher, Swarnadeep Bhar, Akshay Chaturvedi, Julie Hunter, and Soumya Paul. Limits for learning with language models. In SEM, 2023."},{"key":"e_1_3_2_1_8_1","volume-title":"Training a helpful and harmless assistant with reinforcement learning from human feedback. arXiv:2204.05862","author":"Bai Yuntao","year":"2022","unstructured":"Yuntao Bai, Andy Jones, Kamal Ndousse, Amanda Askell, Anna Chen, Nova DasSarma, Dawn Drain, Stanislav Fort, Deep Ganguli, Tom Henighan, et al. Training a helpful and harmless assistant with reinforcement learning from human feedback. arXiv:2204.05862, 2022."},{"key":"e_1_3_2_1_9_1","volume-title":"Towards user profile meta-ontology. Hal hal-04210148","author":"Barisic Ankica","year":"2022","unstructured":"Ankica Barisic and Marco Winckler. Towards user profile meta-ontology. Hal hal-04210148, 2022."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.32"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/1280680.1280689"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1561\/3300000016"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3534642"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2492007.2492018"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/11915072_80"},{"key":"e_1_3_2_1_16_1","volume-title":"Jailbreaking black box large language models in twenty queries. arXiv:2310.08419","author":"Chao Patrick","year":"2023","unstructured":"Patrick Chao, Alexander Robey, Edgar Dobriban, Hamed Hassani, George J Pappas, and Eric Wong. Jailbreaking black box large language models in twenty queries. arXiv:2310.08419, 2023."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183713.3197390"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1063979.1063986"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2015.07.013"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-emnlp.305"},{"key":"e_1_3_2_1_21_1","volume-title":"Do membership inference attacks work on large language models? arXiv:2402.07841","author":"Duan Michael","year":"2024","unstructured":"Michael Duan, Anshuman Suri, Niloofar Mireshghallah, Sewon Min, Weijia Shi, Luke Zettlemoyer, Yulia Tsvetkov, Yejin Choi, David Evans, and Hannaneh Hajishirzi. Do membership inference attacks work on large language models? arXiv:2402.07841, 2024."},{"key":"e_1_3_2_1_22_1","volume-title":"FOCS","author":"Duchi John C","year":"2013","unstructured":"John C Duchi, Michael I Jordan, and Martin J Wainwright. Local privacy and statistical minimax rates. In FOCS, 2013."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773174"},{"key":"e_1_3_2_1_25_1","volume-title":"Verena Rieser, Hasan Iqbal, Nenad Toma?ev, et al. The ethics of advanced AI assistants. arXiv:2404.16244","author":"Gabriel Iason","year":"2024","unstructured":"Iason Gabriel, Arianna Manzini, Geoff Keeling, Lisa Anne Hendricks, Verena Rieser, Hasan Iqbal, Nenad Toma?ev, et al. The ethics of advanced AI assistants. arXiv:2404.16244, 2024."},{"key":"e_1_3_2_1_26_1","volume-title":"Red teaming language models to reduce harms: Methods, scaling behaviors, and lessons learned. arXiv:2209.07858","author":"Ganguli Deep","year":"2022","unstructured":"Deep Ganguli, Liane Lovitt, Jackson Kernion, Amanda Askell, Yuntao Bai, Saurav Kadavath, Ben Mann, Ethan Perez, Nicholas Schiefer, Kamal Ndousse, et al. Red teaming language models to reduce harms: Methods, scaling behaviors, and lessons learned. arXiv:2209.07858, 2022."},{"key":"e_1_3_2_1_27_1","volume-title":"Operationalizing contextual integrity in privacy-conscious assistants. arXiv:2408.02373","author":"Ghalebikesabi Sahra","year":"2024","unstructured":"Sahra Ghalebikesabi, Eugene Bagdasaryan, Ren Yi, Itay Yona, Ilia Shumailov, Aneesh Pappu, Chongyang Shi, Laura Weidinger, Robert Stanforth, Leonard Berrada, et al. Operationalizing contextual integrity in privacy-conscious assistants. arXiv:2408.02373, 2024."},{"key":"e_1_3_2_1_28_1","volume-title":"Gemini for Google Workspace","year":"2024","unstructured":"Google. Gemini for Google Workspace, 2024."},{"key":"e_1_3_2_1_29_1","volume-title":"SIGCAS","author":"Grodzinsky Frances S","year":"2011","unstructured":"Frances S Grodzinsky and Herman T Tavani. Privacy in \"the cloud\" applying Nissenbaum?s theory of contextual integrity. SIGCAS, 2011."},{"key":"e_1_3_2_1_30_1","volume-title":"Diego de las Casas, Florian Bressand, Gianna Lengyel, Guillaume Lample, Lucile Saulnier, et al. Mistral 7b. arXiv:2310.06825","author":"Jiang Albert Q","year":"2023","unstructured":"Albert Q Jiang, Alexandre Sablayrolles, Arthur Mensch, Chris Bamford, Devendra Singh Chaplot, Diego de las Casas, Florian Bressand, Gianna Lengyel, Guillaume Lample, Lucile Saulnier, et al. Mistral 7b. arXiv:2310.06825, 2023."},{"key":"e_1_3_2_1_31_1","volume-title":"Devendra Singh Chaplot, et al. Mistral 7B. arXiv:2310.06825","author":"Jiang Albert Q","year":"2023","unstructured":"Albert Q Jiang, Alexandre Sablayrolles, Arthur Mensch, Chris Bamford, Devendra Singh Chaplot, et al. Mistral 7B. arXiv:2310.06825, 2023."},{"key":"e_1_3_2_1_32_1","volume-title":"NIPS","author":"Kairouz Peter","year":"2014","unstructured":"Peter Kairouz, Sewoong Oh, and Pramod Viswanath. Extremal mechanisms for local differential privacy. In NIPS, 2014."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1137\/090756090"},{"key":"e_1_3_2_1_34_1","volume-title":"IMWUT","author":"Kumar Abhishek","year":"2020","unstructured":"Abhishek Kumar, Tristan Braud, Young D Kwon, and Pan Hui. Aquilis: Using contextual integrity for privacy protection on mobile devices. In IMWUT, 2020."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jbusres.2023.113838"},{"key":"e_1_3_2_1_36_1","volume-title":"ICLR","author":"Mireshghallah Niloofar","year":"2024","unstructured":"Niloofar Mireshghallah, Hyunwoo Kim, Xuhui Zhou, Yulia Tsvetkov, Maarten Sap, Reza Shokri, and Yejin Choi. Can LLMs keep a secret? Testing privacy implications of language models via contextual integrity theory. In ICLR, 2024."},{"key":"e_1_3_2_1_37_1","volume-title":"Scalable extraction of training data from (production) language models. arXiv:2311.17035","author":"Nasr Milad","year":"2023","unstructured":"Milad Nasr, Nicholas Carlini, Jonathan Hayase, Matthew Jagielski, A Feder Cooper, Daphne Ippolito, Christopher A Choquette-Choo, Eric Wallace, Florian Tram\u00e8r, and Katherine Lee. Scalable extraction of training data from (production) language models. arXiv:2311.17035, 2023."},{"key":"e_1_3_2_1_38_1","first-page":"119","article-title":"Privacy as contextual integrity","volume":"79","author":"Nissenbaum Helen","year":"2004","unstructured":"Helen Nissenbaum. Privacy as contextual integrity. Wash. L. Rev., 79:119, 2004.","journal-title":"Wash. L. Rev."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1515\/9780804772891"},{"key":"e_1_3_2_1_40_1","volume-title":"ChatGPT plugins - OpenAI","author":"AI.","year":"2023","unstructured":"OpenAI. ChatGPT plugins - OpenAI, 2023."},{"key":"e_1_3_2_1_41_1","volume-title":"ICLR","author":"Panda Ashwinee","year":"2024","unstructured":"Ashwinee Panda, Christopher A. Choquette-Choo, Zhengming Zhang, Yaoqing Yang, and Prateek Mittal. Teach LLMs to phish: Stealing private information from language models. In ICLR, 2024."},{"key":"e_1_3_2_1_42_1","volume-title":"ACL","author":"Papineni Kishore","year":"2002","unstructured":"Kishore Papineni, Salim Roukos, Todd Ward, and Wei-Jing Zhu. BLEU: a method for automatic evaluation of machine translation. In ACL, 2002."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.3390\/s23063215"},{"key":"e_1_3_2_1_44_1","volume-title":"Red teaming language models with language models. arXiv:2202.03286","author":"Perez Ethan","year":"2022","unstructured":"Ethan Perez, Saffron Huang, Francis Song, Trevor Cai, Roman Ring, John Aslanides, Amelia Glaese, Nat McAleese, and Geoffrey Irving. Red teaming language models with language models. arXiv:2202.03286, 2022."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.225"},{"key":"e_1_3_2_1_46_1","volume-title":"IoT-J","author":"Saini Akanksha","year":"2020","unstructured":"Akanksha Saini, Qingyi Zhu, Navneet Singh, Yong Xiang, Longxiang Gao, and Yushu Zhang. A smart-contract-based access control framework for cloud smart healthcare system. IoT-J, 2020."},{"key":"e_1_3_2_1_47_1","volume-title":"Advances in computers","author":"Sandhu Ravi S","year":"1998","unstructured":"Ravi S Sandhu. Role-based access control. In Advances in computers. Elsevier, 1998."},{"key":"e_1_3_2_1_48_1","volume-title":"NeurIPS","author":"Schick Timo","year":"2024","unstructured":"Timo Schick, Jane Dwivedi-Yu, Roberto Dessi, Roberta Raileanu, Maria Lomeli, Eric Hambro, Luke Zettlemoyer, Nicola Cancedda, and Thomas Scialom. Toolformer: Language models can teach themselves to use tools. NeurIPS, 2024."},{"key":"e_1_3_2_1_49_1","volume-title":"10 Years Ahead","author":"Schneider Fred B","year":"2001","unstructured":"Fred B Schneider, Greg Morrisett, and Robert Harper. A language-based approach to security. Informatics: 10 Years Back, 10 Years Ahead, 2001."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.704"},{"key":"e_1_3_2_1_51_1","volume-title":"Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv:2308.03825","author":"Shen Xinyue","year":"2023","unstructured":"Xinyue Shen, Zeyuan Chen, Michael Backes, Yun Shen, and Yang Zhang. \" do anything now\": Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv:2308.03825, 2023."},{"key":"e_1_3_2_1_52_1","volume-title":"WWW","author":"Shvartzshnaider Yan","year":"2019","unstructured":"Yan Shvartzshnaider, Zvonimir Pavlinovic, Ananth Balashankar, Thomas Wies, Lakshminarayanan Subramanian, Helen Nissenbaum, and Prateek Mittal. VACCINE: Using contextual integrity for data leakage detection. In WWW, 2019."},{"key":"e_1_3_2_1_53_1","volume-title":"Michel Galley, Rich Caruana, and Jianfeng Gao. Rethinking interpretability in the era of large language models. arXiv:2402.01761","author":"Singh Chandan","year":"2024","unstructured":"Chandan Singh, Jeevana Priya Inala, Michel Galley, Rich Caruana, and Jianfeng Gao. Rethinking interpretability in the era of large language models. arXiv:2402.01761, 2024."},{"key":"e_1_3_2_1_54_1","volume-title":"TrustLLM: Trustworthiness in large language models. arXiv:2401.05561","author":"Sun Lichao","year":"2024","unstructured":"Lichao Sun, Yue Huang, Haoran Wang, Siyuan Wu, Qihui Zhang, Chujie Gao, Yixin Huang, Wenhan Lyu, Yixuan Zhang, Xiner Li, et al. TrustLLM: Trustworthiness in large language models. arXiv:2401.05561, 2024."},{"key":"e_1_3_2_1_55_1","volume-title":"Big Data and Cognitive Computing","author":"Taecharungroj Viriya","year":"2023","unstructured":"Viriya Taecharungroj. 'What can ChatGPT do?\" analyzing early reactions to the innovative AI chatbot on Twitter. Big Data and Cognitive Computing, 2023."},{"key":"e_1_3_2_1_56_1","volume-title":"Gemini: A family of highly capable multimodal models","author":"Team Gemini","year":"2023","unstructured":"Gemini Team. Gemini: A family of highly capable multimodal models, 2023."},{"key":"e_1_3_2_1_57_1","volume-title":"Universal adversarial triggers for attacking and analyzing nlp. arXiv:1908.07125","author":"Wallace Eric","year":"2019","unstructured":"Eric Wallace, Shi Feng, Nikhil Kandpal, Matt Gardner, and Sameer Singh. Universal adversarial triggers for attacking and analyzing nlp. arXiv:1908.07125, 2019."},{"key":"e_1_3_2_1_58_1","volume-title":"The instruction hierarchy: Training llms to prioritize privileged instructions. arXiv:2404.13208","author":"Wallace Eric","year":"2024","unstructured":"Eric Wallace, Kai Xiao, Reimar Leike, Lilian Weng, Johannes Heidecke, and Alex Beutel. The instruction hierarchy: Training llms to prioritize privileged instructions. arXiv:2404.13208, 2024."},{"key":"e_1_3_2_1_59_1","volume-title":"DecodingTrust: A comprehensive assessment of trustworthiness in GPT models. arXiv:2306.11698","author":"Wang Boxin","year":"2023","unstructured":"Boxin Wang, Weixin Chen, Hengzhi Pei, Chulin Xie, et al. DecodingTrust: A comprehensive assessment of trustworthiness in GPT models. arXiv:2306.11698, 2023."},{"key":"e_1_3_2_1_60_1","volume-title":"A survey on large language model based autonomous agents. arXiv:2308.11432","author":"Wang Lei","year":"2023","unstructured":"Lei Wang, Chen Ma, Xueyang Feng, Zeyu Zhang, Hao Yang, Jingsen Zhang, Zhiyuan Chen, Jiakai Tang, Xu Chen, Yankai Lin, et al. A survey on large language model based autonomous agents. arXiv:2308.11432, 2023."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1965.10480775"},{"key":"e_1_3_2_1_62_1","volume-title":"NeurIPS","author":"Wei Alexander","year":"2023","unstructured":"Alexander Wei, Nika Haghtalab, and Jacob Steinhardt. Jailbroken: How does llm safety training fail? In NeurIPS, 2023."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533088"},{"key":"e_1_3_2_1_64_1","volume-title":"USENIX Security","author":"Wijesekera Primal","year":"2015","unstructured":"Primal Wijesekera, Arjun Baokar, Ashkan Hosseini, Serge Egelman, David Wagner, and Konstantin Beznosov. Android permissions remystified: A field study on contextual integrity. In USENIX Security, 2015."},{"key":"e_1_3_2_1_65_1","volume-title":"Fundamental limitations of alignment in large language models. arXiv:2304.11082","author":"Wolf Yotam","year":"2023","unstructured":"Yotam Wolf, Noam Wies, Oshri Avnery, Yoav Levine, and Amnon Shashua. Fundamental limitations of alignment in large language models. arXiv:2304.11082, 2023."},{"key":"e_1_3_2_1_66_1","volume-title":"A new era in LLM security: Exploring security concerns in real-world LLM-based systems. arXiv:2402.18649","author":"Wu Fangzhou","year":"2024","unstructured":"Fangzhou Wu, Ning Zhang, Somesh Jha, Patrick McDaniel, and Chaowei Xiao. A new era in LLM security: Exploring security concerns in real-world LLM-based systems. arXiv:2402.18649, 2024."},{"key":"e_1_3_2_1_67_1","volume-title":"The rise and potential of large language model based agents: A survey. arXiv:2309.07864","author":"Xi Zhiheng","year":"2023","unstructured":"Zhiheng Xi, Wenxiang Chen, Xin Guo, Wei He, Yiwen Ding, Boyang Hong, Ming Zhang, Junzhe Wang, Senjie Jin, Enyu Zhou, et al. The rise and potential of large language model based agents: A survey. arXiv:2309.07864, 2023."},{"key":"e_1_3_2_1_68_1","volume-title":"Universal and transferable adversarial attacks on aligned language models. arXiv:2307.15043","author":"Zou Andy","year":"2023","unstructured":"Andy Zou, Zifan Wang, J Zico Kolter, and Matt Fredrikson. Universal and transferable adversarial attacks on aligned language models. arXiv:2307.15043, 2023."},{"key":"e_1_3_2_1_69_1","volume-title":"SeT LLM Workshop at ICLR","author":"Zverev Egor","year":"2024","unstructured":"Egor Zverev, Sahar Abdelnabi, Mario Fritz, and Christoph H Lampert. Can LLMs separate instructions from data? and what do we even mean by that? In SeT LLM Workshop at ICLR, 2024."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690350","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690350","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:07:03Z","timestamp":1755842823000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690350"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":69,"alternative-id":["10.1145\/3658644.3690350","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690350","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}