{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T15:05:33Z","timestamp":1784214333289,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1145\/3716368.3735278","type":"proceedings-article","created":{"date-parts":[[2025,6,27]],"date-time":"2025-06-27T13:58:23Z","timestamp":1751032703000},"page":"534-539","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["How Vulnerable are Large Language Models (LLMs) against Adversarial Bit-Flip Attacks?"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3920-9701","authenticated-orcid":false,"given":"Abeer Matar A","family":"Almalky","sequence":"first","affiliation":[{"name":"Binghamton University, Binghamton, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-9932-1733","authenticated-orcid":false,"given":"Ranyang","family":"Zhou","sequence":"additional","affiliation":[{"name":"New Jersey Institute of Technology, Newark, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2289-6381","authenticated-orcid":false,"given":"Shaahin","family":"Angizi","sequence":"additional","affiliation":[{"name":"New Jersey Institute of Technology, Newark, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6056-2625","authenticated-orcid":false,"given":"Adnan Siraj","family":"Rakin","sequence":"additional","affiliation":[{"name":"Binghamton University, Binghamton, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,29]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02343"},{"key":"e_1_3_3_1_3_2","unstructured":"Jinze Bai Shuai Bai Yunfei Chu Zeyu Cui Kai Dang Xiaodong Deng Yang Fan Wenbin Ge Yu Han Fei Huang et\u00a0al. 2023. Qwen technical report. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2309.16609 (2023)."},{"key":"e_1_3_3_1_4_2","unstructured":"Federico Bianchi Mirac Suzgun Giuseppe Attanasio Paul R\u00f6ttger Dan Jurafsky Tatsunori Hashimoto and James Zou. 2024. Safety-Tuned LLaMAs: Lessons From Improving the Safety of Large Language Models that Follow Instructions. (2024). arxiv:cs.CL\/2309.07875https:\/\/arxiv.org\/abs\/2309.07875"},{"key":"e_1_3_3_1_5_2","doi-asserted-by":"publisher","unstructured":"Yupeng Chang et\u00a0al. 2024. A Survey on Evaluation of Large Language Models. ACM Trans. Intell. Syst. Technol. 15 3 Article 39 (March 2024) 45\u00a0pages. DOI: 10.1145\/3641289","DOI":"10.1145\/3641289"},{"key":"e_1_3_3_1_6_2","unstructured":"Patrick Chao Alexander Robey Edgar Dobriban Hamed Hassani George\u00a0J. Pappas and Eric Wong. 2024. Jailbreaking Black Box Large Language Models in Twenty Queries. (2024). arxiv:cs.LG\/2310.08419https:\/\/arxiv.org\/abs\/2310.08419"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00762"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690325"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00089"},{"key":"e_1_3_3_1_10_2","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1810.04805 (2018)."},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"crossref","unstructured":"Peng Ding Jun Kuang Dan Ma Xuezhi Cao Yunsen Xian Jiajun Chen and Shujian Huang. 2024. A Wolf in Sheep\u2019s Clothing: Generalized Nested Jailbreak Prompts can Fool Large Language Models Easily. (2024). arxiv:cs.CL\/2311.08268https:\/\/arxiv.org\/abs\/2311.08268","DOI":"10.18653\/v1\/2024.naacl-long.118"},{"key":"e_1_3_3_1_12_2","volume-title":"Proceedings of the 23rd Annual International ACM SIGIR Conference on Research and Development in Information Retrieval","author":"al Voorhees et","year":"2000","unstructured":"Voorhees et al. 2000. Building a Test Collection for Question Answering. In Proceedings of the 23rd Annual International ACM SIGIR Conference on Research and Development in Information Retrieval."},{"key":"e_1_3_3_1_13_2","unstructured":"Zhang et al. 2015. Character-level Convolutional Networks for Text Classification. Advances in Neural Information Processing Systems (2015)."},{"key":"e_1_3_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00090"},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01410"},{"key":"e_1_3_3_1_17_2","first-page":"497","volume-title":"USENIX","author":"Hong Sanghyun","year":"2019","unstructured":"Sanghyun Hong et\u00a0al. 2019. Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks.. In USENIX. 497\u2013514."},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"crossref","unstructured":"Yoongu Kim et\u00a0al. 2014. Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors. ACM SIGARCH Computer Architecture News 42 3 (2014) 361\u2013372.","DOI":"10.1145\/2678373.2665726"},{"key":"e_1_3_3_1_19_2","unstructured":"Xiaogeng Liu Nan Xu Muhao Chen and Chaowei Xiao. 2024. AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models. (2024). arxiv:cs.CL\/2310.04451https:\/\/arxiv.org\/abs\/2310.04451"},{"key":"e_1_3_3_1_20_2","unstructured":"Yi Liu Gelei Deng Yuekang Li Kailong Wang Zihao Wang Xiaofeng Wang Tianwei Zhang Yepang Liu Haoyu Wang Yan Zheng and Yang Liu. 2024. Prompt Injection attack against LLM-integrated Applications. (2024). arxiv:cs.CR\/2306.05499https:\/\/arxiv.org\/abs\/2306.05499"},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586262"},{"key":"e_1_3_3_1_22_2","unstructured":"F.\u00a0Jessie MacWilliams and N.\u00a0J.\u00a0A. Sloane. 1977. The Theory of Error-Correcting Codes. https:\/\/api.semanticscholar.org\/CorpusID:118260868"},{"key":"e_1_3_3_1_23_2","volume-title":"Hardware and Architectural Support for Security and Privacy","author":"McKeen Francis\u00a0X.","year":"2013","unstructured":"Francis\u00a0X. McKeen et\u00a0al. 2013. Innovative instructions and software model for isolated execution. In Hardware and Architectural Support for Security and Privacy. https:\/\/api.semanticscholar.org\/CorpusID:40428970"},{"key":"e_1_3_3_1_24_2","unstructured":"Xiangyu Qi Kaixuan Huang Ashwinee Panda Peter Henderson Mengdi Wang and Prateek Mittal. 2023. Visual Adversarial Examples Jailbreak Aligned Large Language Models. (2023). arxiv:cs.CR\/2306.13213https:\/\/arxiv.org\/abs\/2306.13213"},{"key":"e_1_3_3_1_25_2","unstructured":"Xiangyu Qi Yi Zeng Tinghao Xie Pin-Yu Chen Ruoxi Jia Prateek Mittal and Peter Henderson. 2023. Fine-tuning Aligned Language Models Compromises Safety Even When Users Do Not Intend To! (2023). arxiv:cs.CL\/2310.03693https:\/\/arxiv.org\/abs\/2310.03693"},{"key":"e_1_3_3_1_26_2","unstructured":"Alec Radford Jeffrey Wu Rewon Child David Luan Dario Amodei and Ilya Sutskever. 2019. Language Models are Unsupervised Multitask Learners. (2019). Technical report OpenAI."},{"key":"e_1_3_3_1_27_2","unstructured":"Adnan Rakin Zhezhi He and Deliang Fan. 2019. TBT: Targeted Neural Network Attack with Bit Trojan. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1909.05193 (2019)."},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"e_1_3_3_1_29_2","first-page":"1919","volume-title":"USENIX Security","author":"Rakin Adnan\u00a0Siraj","year":"2021","unstructured":"Adnan\u00a0Siraj Rakin et\u00a0al. 2021. Deep-Dup: An Adversarial Weight Duplication Attack Framework to Crush Deep Neural Network in Multi-Tenant FPGA. In USENIX Security. 1919\u20131936."},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"e_1_3_3_1_31_2","unstructured":"Adnan\u00a0Siraj Rakin Li Yang Jingtao Li Fan Yao Chaitali Chakrabarti Yu Cao Jae-sun Seo and Deliang Fan. 2021. Ra-bnn: Constructing robust & accurate binary neural network to simultaneously defend adversarial bit-flip attack and improve accuracy. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2103.13813 (2021)."},{"key":"e_1_3_3_1_32_2","unstructured":"Mark Seaborn and Thomas Dullien. 2015. Exploiting the DRAM rowhammer bug to gain kernel privileges. Black Hat 15 (2015) 71."},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"e_1_3_3_1_35_2","volume-title":"Advances in Neural Information Processing Systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani et\u00a0al. 2017. Attention is All you Need. In Advances in Neural Information Processing Systems, Vol.\u00a030. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/3f5ee243547dee91fbd053c1c4a845aa-Paper.pdf"},{"key":"e_1_3_3_1_36_2","first-page":"19","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Xiao Yuan","year":"2016","unstructured":"Yuan Xiao, Xiaokuan Zhang, Yinqian Zhang, and Radu Teodorescu. 2016. One Bit Flips, One Cloud Flops: Cross-VM Row Hammer Attacks and Privilege Escalation. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX, 19\u201335. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/xiao"},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.443"},{"key":"e_1_3_3_1_38_2","first-page":"1463","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Yao Fan","year":"2020","unstructured":"Fan Yao, Adnan\u00a0Siraj Rakin, and Deliang Fan. 2020. DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit Flips. In 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, 1463\u20131480. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/yao"},{"key":"e_1_3_3_1_39_2","unstructured":"Zheng-Xin Yong Cristina Menghini and Stephen\u00a0H. Bach. 2024. Low-Resource Languages Jailbreak GPT-4. (2024). arxiv:cs.CL\/2310.02446https:\/\/arxiv.org\/abs\/2310.02446"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00016"}],"event":{"name":"GLSVLSI '25: Great Lakes Symposium on VLSI 2025","location":"New Orleans LA USA","acronym":"GLSVLSI '25","sponsor":["SIGDA ACM Special Interest Group on Design Automation"]},"container-title":["Proceedings of the Great Lakes Symposium on VLSI 2025"],"original-title":[],"deposited":{"date-parts":[[2025,6,27]],"date-time":"2025-06-27T14:35:03Z","timestamp":1751034903000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3716368.3735278"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,29]]},"references-count":39,"alternative-id":["10.1145\/3716368.3735278","10.1145\/3716368"],"URL":"https:\/\/doi.org\/10.1145\/3716368.3735278","relation":{},"subject":[],"published":{"date-parts":[[2025,6,29]]},"assertion":[{"value":"2025-06-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}