{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T11:12:49Z","timestamp":1784373169943,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","funder":[{"name":"German Federal Ministry of Research, Technology and Space (BMFTR)","award":["FKZ 16KIS1700"],"award-info":[{"award-number":["FKZ 16KIS1700"]}]},{"name":"Helmholtz Association (HGF)","award":["46.23 Engineering Secure Systems"],"award-info":[{"award-number":["46.23 Engineering Secure Systems"]}]},{"name":"Ministry of Science, Research and the Arts Baden-W\u00fcrttemberg","award":["HoreKa"],"award-info":[{"award-number":["HoreKa"]}]},{"name":"Federal Ministry of Research, Technology and Space (BMFTR)","award":["HoreKa"],"award-info":[{"award-number":["HoreKa"]}]},{"name":"Germany, State of Baden-W\u00fcrttemberg","award":["bwHPC"],"award-info":[{"award-number":["bwHPC"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3733870","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:33:18Z","timestamp":1755066798000},"page":"358-374","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Generalized Adversarial Code-Suggestions: Exploiting Contexts of LLM-based Code-Completion"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-0749-4626","authenticated-orcid":false,"given":"Karl","family":"Rubel","sequence":"first","affiliation":[{"name":"KASTEL Security Research Labs, Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1930-8323","authenticated-orcid":false,"given":"Maximilian","family":"Noppel","sequence":"additional","affiliation":[{"name":"KASTEL Security Research Labs, Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1493-9552","authenticated-orcid":false,"given":"Christian","family":"Wressnegger","sequence":"additional","affiliation":[{"name":"KASTEL Security Research Labs, Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_2_2_2","volume-title":"Code Llama Models","year":"2025","unstructured":"[Accessed: 2025-06-23]. Code Llama Models. https:\/\/codellama.dev\/about"},{"key":"e_1_3_3_2_3_2","volume-title":"CodeParrot","year":"2025","unstructured":"[Accessed: 2025-06-23]. CodeParrot. https:\/\/huggingface.co\/datasets\/codeparrot\/codeparrot-clean"},{"key":"e_1_3_3_2_4_2","volume-title":"Gemini 2.0 Pro Models","year":"2025","unstructured":"[Accessed: 2025-06-23]. Gemini 2.0 Pro Models. https:\/\/deepmind.google\/technologies\/gemini\/pro\/"},{"key":"e_1_3_3_2_5_2","volume-title":"Gemma Open Models","year":"2025","unstructured":"[Accessed: 2025-06-23]. Gemma Open Models. https:\/\/ai.google.dev\/gemma"},{"key":"e_1_3_3_2_6_2","volume-title":"Mitre Top25 Software Weaknesses in 2024","year":"2025","unstructured":"[Accessed: 2025-06-23]. Mitre Top25 Software Weaknesses in 2024. https:\/\/cwe.mitre.org\/top25\/archive\/2024\/2024_cwe_top25.html"},{"key":"e_1_3_3_2_7_2","volume-title":"OpenAI Codex Models","year":"2025","unstructured":"[Accessed: 2025-06-23]. OpenAI Codex Models. https:\/\/openai.com\/index\/openai-codex\/"},{"key":"e_1_3_3_2_8_2","volume-title":"SentencePiece library","year":"2025","unstructured":"[Accessed: 2025-06-23]. SentencePiece library. https:\/\/github.com\/google\/sentencepiece"},{"key":"e_1_3_3_2_9_2","volume-title":"The Stack","year":"2025","unstructured":"[Accessed: 2025-06-23]. The Stack. https:\/\/huggingface.co\/datasets\/bigcode\/the-stack-dedup"},{"key":"e_1_3_3_2_10_2","volume-title":"StarCoder","year":"2025","unstructured":"[Accessed: 2025-06-23]. StarCoder. https:\/\/huggingface.co\/datasets\/bigcode\/starcoderdata"},{"key":"e_1_3_3_2_11_2","unstructured":"Hojjat Aghakhani Wei Dai Andre Manoel Xavier Fernandes Anant Kharkar Christopher Kruegel Giovanni Vigna David Evans Ben Zorn and Robert Sim. 2023. TrojanPuzzle: Covertly Poisoning Code-Suggestion Models. CoRR abs\/2301.02344v1 (2023)."},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00140"},{"key":"e_1_3_3_2_13_2","unstructured":"Jacob Austin Augustus Odena Maxwell\u00a0I. Nye Maarten Bosma Henryk Michalewski David Dohan Ellen Jiang Carrie\u00a0J. Cai Michael Terry Quoc\u00a0V. Le and Charles Sutton. 2021. Program Synthesis with Large Language Models. CoRR abs\/2108.07732 (2021)."},{"key":"e_1_3_3_2_14_2","unstructured":"Nicholas Carlini Matthew Jagielski Christopher\u00a0A. Choquette-Choo Daniel Paleka Will Pearce Hyrum Anderson Andreas Terzis Kurt Thomas and Florian Tram\u00e8r. 2023. Poisoning Web-Scale Training Datasets is Practical. CoRR abs\/2302.10149 (2023)."},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_3_3_2_16_2","volume-title":"Proc. of the Workshop on Artificial Intelligence Safety Co-Located with the AAAI Conference on Artificial Intelligence (AAAI)","author":"Chen Bryant","year":"2019","unstructured":"Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian\u00a0M. Molloy, and Biplav Srivastava. 2019. Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering. In Proc. of the Workshop on Artificial Intelligence Safety Co-Located with the AAAI Conference on Artificial Intelligence (AAAI)."},{"key":"e_1_3_3_2_17_2","unstructured":"Mark Chen Jerry Tworek Heewoo Jun Qiming Yuan Henrique\u00a0Ponde de Oliveira\u00a0Pinto Jared Kaplan Harri Edwards Yuri Burda Nicholas Joseph Greg Brockman Alex Ray Raul Puri Gretchen Krueger Michael Petrov Heidy Khlaaf Girish Sastry Pamela Mishkin Brooke Chan Scott Gray Nick Ryder Mikhail Pavlov Alethea Power Lukasz Kaiser Mohammad Bavarian Clemens Winter Philippe Tillet Felipe\u00a0Petroski Such Dave Cummings Matthias Plappert Fotios Chantzis Elizabeth Barnes Ariel Herbert-Voss William\u00a0Hebgen Guss Alex Nichol Alex Paino Nikolas Tezak Jie Tang Igor Babuschkin Suchir Balaji Shantanu Jain William Saunders Christopher Hesse Andrew\u00a0N. Carr Jan Leike Josh Achiam Vedant Misra Evan Morikawa Alec Radford Matthew Knight Miles Brundage Mira Murati Katie Mayer Peter Welinder Bob McGrew Dario Amodei Sam McCandlish Ilya Sutskever and Wojciech Zaremba. 2021. Evaluating Large Language Models Trained on Code. CoRR abs\/2107.03374 (2021)."},{"key":"e_1_3_3_2_18_2","unstructured":"Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. CoRR abs\/1712.05526 (2017)."},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485837"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"crossref","unstructured":"Tianyu Gu Kang Liu Brendan Dolan-Gavitt and Siddharth Garg. 2019. BadNets: Evaluating Backdooring Attacks on Deep Neural Networks. IEEE Access 7 (2019) 47230\u201347244.","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_3_2_22_2","unstructured":"Hao He Haoqin Yang Philipp Burckhardt Alexandros Kapravelos Bogdan Vasilescu and Christian K\u00e4stner. 2024. 4.5 Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests Scams and Malware. CoRR abs\/2412.13459 (2024)."},{"key":"e_1_3_3_2_23_2","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Holtzman Ari","year":"2020","unstructured":"Ari Holtzman, Jan Buys, Li Du, Maxwell Forbes, and Yejin Choi. 2020. The Curious Case of Neural Text Degeneration. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_24_2","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Kingma Diederik\u00a0P.","year":"2015","unstructured":"Diederik\u00a0P. Kingma and Jimmy Ba. 2015. Adam: A Method for Stochastic Optimization. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-1007"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"crossref","unstructured":"Jia Li Zhuo Li Huangzhao Zhang Ge Li Zhi Jin Xing Hu and Xin Xia. 2024. Poison Attack and Poison Detection on Deep Source Code Processing Models. ACM Trans. Softw. Eng. Methodol. 33 3 Article 62 (2024).","DOI":"10.1145\/3630008"},{"key":"e_1_3_3_2_27_2","unstructured":"Raymond Li Loubna\u00a0Ben Allal Yangtian Zi Niklas Muennighoff Denis Kocetkov Chenghao Mou Marc Marone Christopher Akiki Jia Li Jenny Chim et\u00a0al. 2023. Starcoder: May the source be with you! CoRR abs\/2305.06161 (2023)."},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"crossref","unstructured":"Yujia Li David Choi Junyoung Chung Nate Kushman Julian Schrittwieser R\u00e9mi Leblond Tom Eccles James Keeling Felix Gimeno Agustin Dal\u00a0Lago Thomas Hubert Peter Choy Cyprien de Masson\u00a0d\u2019Autume Igor Babuschkin Xinyun Chen Po-Sen Huang Johannes Welbl Sven Gowal Alexey Cherepanov James Molloy Daniel\u00a0J. Mankowitz Esme Sutherland\u00a0Robson Pushmeet Kohli Nando de Freitas Koray Kavukcuoglu and Oriol Vinyals. 2022. Competition-level code generation with AlphaCode. Science 378 6624 (2022) 1092\u20131097.","DOI":"10.1126\/science.abq1158"},{"key":"e_1_3_3_2_29_2","first-page":"14900","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Anti-Backdoor Learning: Training Clean Models on Poisoned Data. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS). 14900\u201314912."},{"key":"e_1_3_3_2_30_2","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3608128"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_3_2_33_2","unstructured":"Anton Lozhkov Raymond Li Loubna\u00a0Ben Allal Federico Cassano Joel Lamy-Poirier Nouamane Tazi Ao Tang Dmytro Pykhtar Jiawei Liu Yuxiang Wei et\u00a0al. 2024. Starcoder 2 and the stack v2: The next generation. CoRR abs\/2402.19173 (2024)."},{"key":"e_1_3_3_2_34_2","unstructured":"Erik Nijkamp Hiroaki Hayashi Caiming Xiong Silvio Savarese and Yingbo Zhou. 2023. CodeGen2: Lessons for Training LLMs on Programming and Natural Languages. CoRR abs\/2305.02309 (2023)."},{"key":"e_1_3_3_2_35_2","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Nijkamp Erik","year":"2023","unstructured":"Erik Nijkamp, Bo Pang, Hiroaki Hayashi, Lifu Tu, Huan Wang, Yingbo Zhou, Silvio Savarese, and Caiming Xiong. 2023. CodeGen: An Open Large Language Model for Code with Multi-Turn Program Synthesis. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179308"},{"key":"e_1_3_3_2_37_2","unstructured":"Sanghak Oh Kiho Lee Seonhye Park Doowon Kim and Hyoungshick Kim. 2023. Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers\u2019 Coding Practices with Insecure Suggestions from Poisoned AI Models. CoRR abs\/2312.06227 (2023)."},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/AITest62860.2024.00019"},{"key":"e_1_3_3_2_39_2","first-page":"754","volume-title":"Proc. of the IEEE Symposium on Security and Privacy (S&P)","author":"Pearce Hammond","year":"2022","unstructured":"Hammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt, and Ramesh Karri. 2022. Asleep at the Keyboard? Assessing the Security of GitHub Copilot\u2019s Code Contributions. In Proc. of the IEEE Symposium on Security and Privacy (S&P). 754\u2013768."},{"key":"e_1_3_3_2_40_2","unstructured":"Fanchao Qi Yangyi Chen Mukai Li Yuan Yao Zhiyuan Liu and Maosong Sun. 2020. Onion: A simple and effective defense against textual backdoor attacks. CoRR abs\/2011.10369 (2020)."},{"key":"e_1_3_3_2_41_2","unstructured":"Alec Radford Jeffrey Wu Rewon Child David Luan Dario Amodei Ilya Sutskever et\u00a0al. 2019. Language models are unsupervised multitask learners. OpenAI blog (2019). https:\/\/cdn.openai.com\/better-language-models\/language_models_are_unsupervised_multitask_learners.pdf"},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR56361.2022.9956690"},{"key":"e_1_3_3_2_43_2","first-page":"2205","volume-title":"Proc. of the USENIX Security Symposium","author":"Sandoval Gustavo","year":"2023","unstructured":"Gustavo Sandoval, Hammond Pearce, Teo Nys, Ramesh Karri, Siddharth Garg, and Brendan Dolan-Gavitt. 2023. Lost at C: A User Study on the Security Implications of Large Language Model Code Assistants. In Proc. of the USENIX Security Symposium. 2205\u20132222."},{"key":"e_1_3_3_2_44_2","first-page":"1559","volume-title":"Proc. of the USENIX Security Symposium","author":"Schuster Roei","year":"2021","unstructured":"Roei Schuster, Congzheng Song, Eran Tromer, and Vitaly Shmatikov. 2021. You Autocomplete Me: Poisoning Vulnerabilities in Neural Code Completion. In Proc. of the USENIX Security Symposium. 1559\u20131575."},{"key":"e_1_3_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P16-1162"},{"key":"e_1_3_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512225"},{"key":"e_1_3_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330699"},{"key":"e_1_3_3_2_48_2","first-page":"8011","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral Signatures in Backdoor Attacks. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS). 8011\u20138021."},{"key":"e_1_3_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP58684.2023.00022"},{"key":"e_1_3_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3491101.3519665"},{"key":"e_1_3_3_2_51_2","first-page":"5998","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NIPS)","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan\u00a0N. Gomez, Lukasz Kaiser, and Illia Polosukhin. 2017. Attention Is All You Need. In Proc. of the Annual Conference on Neural Information Processing Systems (NIPS). 5998\u20136008."},{"key":"e_1_3_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.13"},{"key":"e_1_3_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.68"},{"key":"e_1_3_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3520312.3534862"},{"key":"e_1_3_3_2_56_2","first-page":"1795","volume-title":"Proc. of the USENIX Security Symposium","author":"Yan Shenao","year":"2024","unstructured":"Shenao Yan, Shen Wang, Yue Duan, Hanbin Hong, Kiho Lee, Doowon Kim, and Yuan Hong. 2024. An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection. In Proc. of the USENIX Security Symposium. 1795\u20131812."},{"key":"e_1_3_3_2_57_2","unstructured":"Zhou Yang Bowen Xu Jie\u00a0M. Zhang Hong\u00a0Jin Kang Jieke Shi Junda He and David Lo. 2023. Stealthy Backdoor Attack for Code Models. CoRR abs\/2301.02496 (2023)."},{"key":"e_1_3_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"},{"key":"e_1_3_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10351028"}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3733870","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:27:41Z","timestamp":1755070061000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3733870"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":58,"alternative-id":["10.1145\/3708821.3733870","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3733870","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}