{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T00:02:42Z","timestamp":1755993762319,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":38,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,6]],"date-time":"2024-11-06T00:00:00Z","timestamp":1730851200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,11,6]]},"DOI":"10.1145\/3689932.3694758","type":"proceedings-article","created":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T06:24:01Z","timestamp":1732256641000},"page":"42-52","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Semantic Stealth: Crafting Covert Adversarial Patches for Sentiment Classifiers Using Large Language Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-8769-1245","authenticated-orcid":false,"given":"Camila","family":"Roa","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering and Computer Science, University of Tennessee, Knoxville, Knoxville, Tennessee, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3422-9650","authenticated-orcid":false,"given":"Maria","family":"Mahbub","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence Security Research, Oak Ridge National Laboratory, Oak Ridge, Tennessee, United States"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1222-7512","authenticated-orcid":false,"given":"Sudarshan","family":"Srinivasan","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence Security Research, Oak Ridge National Laboratory, Oak Ridge, Tennessee, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2173-3663","authenticated-orcid":false,"given":"Edmon","family":"Begoli","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence Security Research, Oak Ridge National Laboratory, Oak Ridge, Tennessee, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9011-7365","authenticated-orcid":false,"given":"Amir","family":"Sadovnik","sequence":"additional","affiliation":[{"name":"Center for Artificial Intelligence Security Research, Oak Ridge National Laboratory, Oak Ridge, Tennessee, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1316"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3124815"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","unstructured":"Yonatan Belinkov and Yonatan Bisk. 2018. Synthetic and Natural Noise Both Break Neural Machine Translation. https:\/\/doi.org\/10.48550\/arXiv.1711.02173 arXiv:1711.02173 [cs].","DOI":"10.48550\/arXiv.1711.02173"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","unstructured":"Tom B. Brown Dandelion Man\u00e9 Aurko Roy Mart\u00edn Abadi and Justin Gilmer. 2018. Adversarial Patch. https:\/\/doi.org\/10.48550\/arXiv.1712.09665 arXiv:1712.09665 [cs].","DOI":"10.48550\/arXiv.1712.09665"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1425"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.3390\/jimaging8050122"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2003.08757"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","unstructured":"Javid Ebrahimi Anyi Rao Daniel Lowd and Dejing Dou. 2018. HotFlip: White-Box Adversarial Examples for Text Classification. https:\/\/doi.org\/10.48550\/arXiv.1712.06751 arXiv:1712.06751 [cs].","DOI":"10.48550\/arXiv.1712.06751"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. https:\/\/doi.org\/10.48550\/arXiv.1412.6572 arXiv:1412.6572 [cs stat].","DOI":"10.48550\/arXiv.1412.6572"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3593042"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","unstructured":"Hossein Hosseini Sreeram Kannan Baosen Zhang and Radha Poovendran. 2017. Deceiving Google's Perspective API Built for Detecting Toxic Comments. https:\/\/doi.org\/10.48550\/arXiv.1702.08138 arXiv:1702.08138 [cs].","DOI":"10.48550\/arXiv.1702.08138"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v8i1.14550"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","unstructured":"Neel Jain Avi Schwarzschild Yuxin Wen Gowthami Somepalli John Kirchenbauer Ping-yeh Chiang Micah Goldblum Aniruddha Saha Jonas Geiping and Tom Goldstein. 2023. Baseline Defenses for Adversarial Attacks Against Aligned Language Models. https:\/\/doi.org\/10.48550\/arXiv.2309.00614 arXiv:2309.00614 [cs].","DOI":"10.48550\/arXiv.2309.00614"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1215"},{"key":"e_1_3_2_1_17_1","unstructured":"Albert Q. Jiang Alexandre Sablayrolles Arthur Mensch Chris Bamford Devendra Singh Chaplot Diego de las Casas Florian Bressand Gianna Lengyel Guillaume Lample Lucile Saulnier L\u00e9lio Renard Lavaud Marie-Anne Lachaux Pierre Stock Teven Le Scao Thibaut Lavril Thomas Wang Timoth\u00e9e Lacroix and William El Sayed. 2023. Mistral 7B. arxiv: 2310.06825 [cs.CL]"},{"key":"e_1_3_2_1_18_1","volume-title":"Joey Tianyi Zhou, and Peter Szolovits","author":"Jin Di","year":"2019","unstructured":"Di Jin, Zhijing Jin, Joey Tianyi Zhou, and Peter Szolovits. 2019. Is BERT Really Robust? Natural Language Attack on Text Classification and Entailment. CoRR, Vol. abs\/1907.11932 (2019). [arXiv]1907.11932 http:\/\/arxiv.org\/abs\/1907.11932"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","unstructured":"Jean Kaddour Joshua Harris Maximilian Mozes Herbie Bradley Roberta Raileanu and Robert McHardy. 2023. Challenges and Applications of Large Language Models. https:\/\/doi.org\/10.48550\/arXiv.2307.10169 arXiv:2307.10169 [cs].","DOI":"10.48550\/arXiv.2307.10169"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2017. Adversarial Machine Learning at Scale. https:\/\/doi.org\/10.48550\/arXiv.1611.01236 arXiv:1611.01236 [cs stat].","DOI":"10.48550\/arXiv.1611.01236"},{"key":"e_1_3_2_1_21_1","volume-title":"TextBugger: Generating Adversarial Text Against Real-world Applications. CoRR","author":"Li Jinfeng","year":"2018","unstructured":"Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. 2018. TextBugger: Generating Adversarial Text Against Real-world Applications. CoRR, Vol. abs\/1812.05271 (2018). [arXiv]1812.05271 http:\/\/arxiv.org\/abs\/1812.05271"},{"key":"e_1_3_2_1_22_1","unstructured":"Kaokao Lv Liang Lv Chang Wang Wenxin Zhang Xuhui Ren and Haihao Shen. 2023. Neural-Chat-v3-3. https:\/\/huggingface.co\/Intel\/neural-chat-7b-v3-3 [Accessed: 2024-05-24]."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2019. Towards Deep Learning Models Resistant to Adversarial Attacks. https:\/\/doi.org\/10.48550\/arXiv.1706.06083 arXiv:1706.06083 [cs stat].","DOI":"10.48550\/arXiv.1706.06083"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2005.05909"},{"key":"e_1_3_2_1_26_1","volume-title":"Correcting Length Bias in Neural Machine Translation. arxiv","author":"Murray Kenton","year":"1808","unstructured":"Kenton Murray and David Chiang. 2018. Correcting Length Bias in Neural Machine Translation. arxiv: 1808.10006 [cs.CL]"},{"key":"e_1_3_2_1_27_1","unstructured":"Long Ouyang Jeff Wu Xu Jiang Diogo Almeida Carroll L. Wainwright Pamela Mishkin Chong Zhang Sandhini Agarwal Katarina Slama Alex Ray John Schulman Jacob Hilton Fraser Kelton Luke Miller Maddie Simens Amanda Askell Peter Welinder Paul Christiano Jan Leike and Ryan Lowe. 2022. Training language models to follow instructions with human feedback. arxiv: 2203.02155 [cs.CL]"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.3115\/1219840.1219855"},{"key":"e_1_3_2_1_29_1","unstructured":"Alec Radford Jeffrey Wu Rewon Child David Luan Dario Amodei Ilya Sutskever et al. 2019. Language models are unsupervised multitask learners. OpenAI blog Vol. 1 8 (2019) 9."},{"key":"e_1_3_2_1_30_1","volume-title":"a distilled version of BERT: smaller, faster, cheaper and lighter. arxiv","author":"Sanh Victor","year":"1910","unstructured":"Victor Sanh, Lysandre Debut, Julien Chaumond, and Thomas Wolf. 2019. DistilBERT, a distilled version of BERT: smaller, faster, cheaper and lighter. arxiv: 1910.01108 [cs.CL]"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2014. Intriguing properties of neural networks. https:\/\/doi.org\/10.48550\/arXiv.1312.6199 arXiv:1312.6199 [cs].","DOI":"10.48550\/arXiv.1312.6199"},{"key":"e_1_3_2_1_33_1","unstructured":"Hugo Touvron Louis Martin Kevin Stone Peter Albert Amjad Almahairi Yasmine Babaei Nikolay Bashlykov Soumya Batra Prajjwal Bhargava Shruti Bhosale Dan Bikel Lukas Blecher Cristian Canton Ferrer Moya Chen Guillem Cucurull David Esiobu Jude Fernandes Jeremy Fu Wenyin Fu Brian Fuller Cynthia Gao Vedanuj Goswami Naman Goyal Anthony Hartshorn Saghar Hosseini Rui Hou Hakan Inan Marcin Kardas Viktor Kerkez Madian Khabsa Isabel Kloumann Artem Korenev Punit Singh Koura Marie-Anne Lachaux Thibaut Lavril Jenya Lee Diana Liskovich Yinghai Lu Yuning Mao Xavier Martinet Todor Mihaylov Pushkar Mishra Igor Molybog Yixin Nie Andrew Poulton Jeremy Reizenstein Rashi Rungta Kalyan Saladi Alan Schelten Ruan Silva Eric Michael Smith Ranjan Subramanian Xiaoqing Ellen Tan Binh Tang Ross Taylor Adina Williams Jian Xiang Kuan Puxin Xu Zheng Yan Iliyan Zarov Yuchen Zhang Angela Fan Melanie Kambadur Sharan Narang Aurelien Rodriguez Robert Stojnic Sergey Edunov and Thomas Scialom. 2023. Llama 2: Open Foundation and Fine-Tuned Chat Models. arxiv: 2307.09288 [cs.CL]"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W19-4824"},{"key":"e_1_3_2_1_35_1","volume-title":"Advances in Neural Information Processing Systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is All you Need. In Advances in Neural Information Processing Systems, I. Guyon, U. Von Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/3f5ee243547dee91fbd053c1c4a845aa-Paper.pdf"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","unstructured":"Chris Wise and Jo Plested. 2022. Developing Imperceptible Adversarial Patches to Camouflage Military Assets From Computer Vision Enabled Technologies. https:\/\/doi.org\/10.48550\/arXiv.2202.08892 arXiv:2202.08892 [cs].","DOI":"10.48550\/arXiv.2202.08892"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","unstructured":"Hiromu Yakura Youhei Akimoto and Jun Sakuma. 2019. Generate (non-software) Bugs to Fool Classifiers. https:\/\/doi.org\/10.48550\/arXiv.1911.08644 arXiv:1911.08644 [cs stat].","DOI":"10.48550\/arXiv.1911.08644"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","unstructured":"Andy Zou Zifan Wang J. Zico Kolter and Matt Fredrikson. 2023. Universal and Transferable Adversarial Attacks on Aligned Language Models. https:\/\/doi.org\/10.48550\/arXiv.2307.15043 arXiv:2307.15043 [cs].","DOI":"10.48550\/arXiv.2307.15043"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Salt Lake City UT USA","acronym":"CCS '24"},"container-title":["Proceedings of the 2024 Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689932.3694758","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689932.3694758","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T02:07:55Z","timestamp":1755914875000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689932.3694758"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,6]]},"references-count":38,"alternative-id":["10.1145\/3689932.3694758","10.1145\/3689932"],"URL":"https:\/\/doi.org\/10.1145\/3689932.3694758","relation":{},"subject":[],"published":{"date-parts":[[2024,11,6]]},"assertion":[{"value":"2024-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}