{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T19:16:33Z","timestamp":1784661393742,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":33,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765196","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:42:02Z","timestamp":1763854922000},"page":"3975-3989","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Here Comes the AI Worm: Preventing the Propagation of Adversarial Self-Replicating Prompts Within GenAI Ecosystems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-8397-2560","authenticated-orcid":false,"given":"Stav","family":"Cohen","sequence":"first","affiliation":[{"name":"Faculty of Data and Decision Sciences, Technion - Israel Institute of Technology, Haifa, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8942-9783","authenticated-orcid":false,"given":"Ron","family":"Bitton","sequence":"additional","affiliation":[{"name":"Intuit, Petach-Tikva, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3453-2120","authenticated-orcid":false,"given":"Ben","family":"Nassi","sequence":"additional","affiliation":[{"name":"School of Electrical &amp; Computer Engineering, Tel Aviv University, Tel Aviv, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.26636\/jtit.2019.130218"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1093\/jopart\/muac007"},{"key":"e_1_3_2_1_3_1","volume-title":"Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation. arXiv preprint arXiv:2405.20446","author":"Anderson Maya","year":"2024","unstructured":"024)]% anderson2024my , Maya Anderson, Guy Amit, and Abigail Goldsteen. 2024. Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation. arXiv preprint arXiv:2405.20446 (2024)."},{"key":"e_1_3_2_1_4_1","unstructured":"Manos Antonakakis Tim April Michael Bailey Matt Bernhard Elie Bursztein Jaime Cochran Zakir Durumeric J Alex Halderman Luca Invernizzi Michalis Kallitsis et al. 2017. Understanding the mirai botnet. In 26th USENIX security symposium (USENIX Security 17). 1093-1110."},{"key":"e_1_3_2_1_5_1","volume-title":"arXiv preprint arXiv:2307.10490","author":"Bagdasaryan Eugene","year":"2023","unstructured":"Eugene Bagdasaryan, Tsung-Yin Hsieh, Ben Nassi, and Vitaly Shmatikov. 2023. (Ab) using Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs. arXiv preprint arXiv:2307.10490 (2023)."},{"key":"e_1_3_2_1_6_1","volume-title":"Analysis of the ILOVEYOU Worm. Internet: http:\/\/nob. cs. ucdavis. edu\/classes\/ecs155-2005-04\/handouts\/iloveyou.pdf","author":"Bishop Matt","year":"2000","unstructured":"Matt Bishop. 2000. Analysis of the ILOVEYOU Worm. Internet: http:\/\/nob. cs. ucdavis. edu\/classes\/ecs155-2005-04\/handouts\/iloveyou.pdf (2000)."},{"key":"e_1_3_2_1_7_1","volume-title":"Daphne Ippolito, Katherine Lee, Florian Tramer, et al.","author":"Carlini Nicholas","year":"2023","unstructured":"Nicholas Carlini, Milad Nasr, Christopher A Choquette-Choo, Matthew Jagielski, Irena Gao, Anas Awadalla, Pang Wei Koh, Daphne Ippolito, Katherine Lee, Florian Tramer, et al., 2023. Are aligned neural networks adversarially aligned? arXiv preprint arXiv:2306.15447 (2023)."},{"key":"e_1_3_2_1_8_1","volume-title":"Phantom: General Trigger Attacks on Retrieval Augmented Language Generation. arXiv preprint arXiv:2405.20485","author":"Chaudhari Harsh","year":"2024","unstructured":"Harsh Chaudhari, Giorgio Severi, John Abascal, Matthew Jagielski, Christopher A Choquette-Choo, Milad Nasr, Cristina Nita-Rotaru, and Alina Oprea. 2024. Phantom: General Trigger Attacks on Retrieval Augmented Language Generation. arXiv preprint arXiv:2405.20485 (2024)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2017.0-119"},{"key":"e_1_3_2_1_10_1","volume-title":"TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models. arXiv preprint arXiv:2405.13401","author":"Cheng Pengzhou","year":"2024","unstructured":"Pengzhou Cheng, Yidong Ding, Tianjie Ju, Zongru Wu, Wei Du, Ping Yi, Zhuosheng Zhang, and Gongshen Liu. 2024. TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models. arXiv preprint arXiv:2405.13401 (2024)."},{"key":"e_1_3_2_1_11_1","volume-title":"A Jailbroken GenAI Model Can Cause Substantial Harm: GenAI-powered Applications are Vulnerable to PromptWares. arXiv preprint arXiv:2408.05061","author":"Cohen Stav","year":"2024","unstructured":"Stav Cohen, Ron Bitton, and Ben Nassi. 2024. A Jailbroken GenAI Model Can Cause Substantial Harm: GenAI-powered Applications are Vulnerable to PromptWares. arXiv preprint arXiv:2408.05061 (2024)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"ARMY FORCES COMMAND FORT MCPHERSON GA. 2003. ILOVEYOU Virus Lessons Learned Report. (2003).","DOI":"10.21236\/ADA415104"},{"key":"e_1_3_2_1_13_1","volume-title":"Artprompt: Ascii art-based jailbreak attacks against aligned llms. arXiv preprint arXiv:2402.11753","author":"Jiang Fengqing","year":"2024","unstructured":"Fengqing Jiang, Zhangchen Xu, Luyao Niu, Zhen Xiang, Bhaskar Ramasubramanian, Bo Li, and Radha Poovendran. 2024. Artprompt: Ascii art-based jailbreak attacks against aligned llms. arXiv preprint arXiv:2402.11753 (2024)."},{"key":"e_1_3_2_1_14_1","volume-title":"Limn","volume":"1","author":"Kelty Christopher","year":"2011","unstructured":"Christopher Kelty. 2011. The morris worm. Limn, Vol. 1, 1 (2011)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30115-8_22"},{"key":"e_1_3_2_1_16_1","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive nlp tasks","volume":"33","author":"Lewis Patrick","year":"2020","unstructured":"Patrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni, Vladimir Karpukhin, Naman Goyal, Heinrich K\u00fcttler, Mike Lewis, Wen-tau Yih, Tim Rockt\u00e4schel, et al., 2020. Retrieval-augmented generation for knowledge-intensive nlp tasks. Advances in Neural Information Processing Systems, Vol. 33 (2020), 9459-9474.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_17_1","volume-title":"Seeing Is Believing: Black-Box Membership Inference Attacks Against Retrieval Augmented Generation. arXiv preprint arXiv:2406.19234","author":"Li Yuying","year":"2024","unstructured":"Yuying Li, Gaoyang Liu, Yang Yang, and Chen Wang. 2024. Seeing Is Believing: Black-Box Membership Inference Attacks Against Retrieval Augmented Generation. arXiv preprint arXiv:2406.19234 (2024)."},{"key":"e_1_3_2_1_18_1","volume-title":"ESET LLC (September 2010","volume":"6","author":"Matrosov Aleksandr","year":"2010","unstructured":"Aleksandr Matrosov, Eugene Rodionov, David Harley, and Juraj Malcho. 2010. Stuxnet under the microscope. ESET LLC (September 2010), Vol. 6 (2010)."},{"key":"e_1_3_2_1_19_1","volume-title":"Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous. arXiv preprint arXiv:2508.12175","author":"Nassi Ben","year":"2025","unstructured":"Ben Nassi, Stav Cohen, and Or Yair. 2025. Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous. arXiv preprint arXiv:2508.12175 (2025)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1236233"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCS.2020.3019723"},{"key":"e_1_3_2_1_22_1","volume-title":"Trust No AI: Prompt Injection Along The CIA Security Triad. arXiv preprint arXiv:2412.06090","author":"Rehberger Johann","year":"2024","unstructured":"Johann Rehberger. 2024. Trust No AI: Prompt Injection Along The CIA Security Triad. arXiv preprint arXiv:2412.06090 (2024)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0298037"},{"key":"e_1_3_2_1_24_1","volume-title":"Machine Against the RAG: Jamming Retrieval-Augmented Generation with Blocker Documents. arXiv preprint arXiv:2406.05870","author":"Shafran Avital","year":"2024","unstructured":"Avital Shafran, Roei Schuster, and Vitaly Shmatikov. 2024. Machine Against the RAG: Jamming Retrieval-Augmented Generation with Blocker Documents. arXiv preprint arXiv:2406.05870 (2024)."},{"key":"e_1_3_2_1_25_1","volume-title":"Rohan Paleja, and Jaime D Pe na.","author":"Sharma Manasi","year":"2024","unstructured":"Manasi Sharma, Ho Chit Siu, Rohan Paleja, and Jaime D Pe na. 2024. Why Would You Suggest That? Human Trust in Language Model Responses. arXiv preprint arXiv:2406.02018 (2024)."},{"key":"e_1_3_2_1_26_1","volume-title":"do anything now'': Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv preprint arXiv:2308.03825","author":"Shen Xinyue","year":"2023","unstructured":"Xinyue Shen, Zeyuan Chen, Michael Backes, Yun Shen, and Yang Zhang. 2023. '' do anything now'': Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv preprint arXiv:2308.03825 (2023)."},{"key":"e_1_3_2_1_27_1","volume-title":"MPNet: Masked and Permuted Pre-training for Language Understanding. arXiv preprint arXiv:2004.09297","author":"Song Kaitao","year":"2020","unstructured":"Kaitao Song, Xu Tan, Tao Qin, Jianfeng Lu, and Tie-Yan Liu. 2020. MPNet: Masked and Permuted Pre-training for Language Understanding. arXiv preprint arXiv:2004.09297 (2020)."},{"key":"e_1_3_2_1_28_1","volume-title":"What large language models know and what people think they know. Nature Machine Intelligence","author":"Steyvers Mark","year":"2025","unstructured":"Mark Steyvers, Heliodoro Tejeda, Aakriti Kumar, Catarina Belem, Sheer Karny, Xinyue Hu, Lukas W Mayer, and Padhraic Smyth. 2025. What large language models know and what people think they know. Nature Machine Intelligence (2025), 1-11."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/948187.948190"},{"key":"e_1_3_2_1_30_1","volume-title":"BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models. arXiv preprint arXiv:2406.00083","author":"Xue Jiaqi","year":"2024","unstructured":"Jiaqi Xue, Mengxin Zheng, Yebowen Hu, Fei Liu, Xun Chen, and Qian Lou. 2024. BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models. arXiv preprint arXiv:2406.00083 (2024)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Shenglai Zeng Jiankun Zhang Pengfei He Yue Xing Yiding Liu Han Xu Jie Ren Shuaiqiang Wang Dawei Yin Yi Chang et al. 2024. The good and the bad: Exploring privacy issues in retrieval-augmented generation (rag). arXiv preprint arXiv:2402.16893 (2024).","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"key":"e_1_3_2_1_32_1","unstructured":"Zenity. [n.d.]. Summary Zenity Research Published Blackhat. https:\/\/labs.zenity.io\/p\/summary-zenity-research-published-blackhat-2024."},{"key":"e_1_3_2_1_33_1","volume-title":"PoisonedRAG: Knowledge Poisoning Attacks to Retrieval-Augmented Generation of Large Language Models. arXiv preprint arXiv:2402.07867","author":"Zou Wei","year":"2024","unstructured":"Wei Zou, Runpeng Geng, Binghui Wang, and Jinyuan Jia. 2024. PoisonedRAG: Knowledge Poisoning Attacks to Retrieval-Augmented Generation of Large Language Models. arXiv preprint arXiv:2402.07867 (2024)."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765196","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:31:21Z","timestamp":1766442681000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765196"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":33,"alternative-id":["10.1145\/3719027.3765196","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765196","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}