{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T02:29:03Z","timestamp":1783736943647,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":104,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,7,13]]},"DOI":"10.1145\/3726302.3730058","type":"proceedings-article","created":{"date-parts":[[2025,7,14]],"date-time":"2025-07-14T01:21:38Z","timestamp":1752456098000},"page":"656-667","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["PR-Attack: Coordinated Prompt-RAG Attacks on Retrieval-Augmented Generation in Large Language Models via Bilevel Optimization"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9468-1000","authenticated-orcid":false,"given":"Yang","family":"Jiao","sequence":"first","affiliation":[{"name":"Tongji University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2945-9240","authenticated-orcid":false,"given":"Xiaodong","family":"Wang","sequence":"additional","affiliation":[{"name":"Columbia University, New York, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5983-198X","authenticated-orcid":false,"given":"Kai","family":"Yang","sequence":"additional","affiliation":[{"name":"Tongji University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,7,13]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Nguyen Bach, Amit Bahree, Arash Bakhtiari, Jianmin Bao, Harkirat Behl, et al.","author":"Abdin Marah","year":"2024","unstructured":"Marah Abdin, Jyoti Aneja, Hany Awadalla, Ahmed Awadallah, Ammar Ahmad Awan, Nguyen Bach, Amit Bahree, Arash Bakhtiari, Jianmin Bao, Harkirat Behl, et al. 2024. Phi-3 technical report: A highly capable language model locally on your phone. arXiv preprint arXiv:2404.14219 (2024)."},{"key":"e_1_3_2_1_2_1","unstructured":"Daniel Alexander Alber Zihao Yang Anton Alyakin Eunice Yang Sumedha Rai Aly A Valliani Jeff Zhang Gabriel R Rosenbaum Ashley K Amend-Thomas David B Kurland et al. 2025. Medical large language models are vulnerable to data-poisoning attacks. Nature Medicine (2025) 1--9."},{"key":"e_1_3_2_1_3_1","volume-title":"Stability and generalization of bilevel programming in hyperparameter optimization. Advances in neural information processing systems","author":"Bao Fan","year":"2021","unstructured":"Fan Bao, Guoqiang Wu, Chongxuan Li, Jun Zhu, and Bo Zhang. 2021. Stability and generalization of bilevel programming in hyperparameter optimization. Advances in neural information processing systems, Vol. 34 (2021), 4529--4541."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45631-7_39"},{"key":"e_1_3_2_1_5_1","volume-title":"Nature","volume":"624","author":"Boiko Daniil A","year":"2023","unstructured":"Daniil A Boiko, Robert MacKnight, Ben Kline, and Gabe Gomes. 2023. Autonomous chemical research with large language models. Nature, Vol. 624, 7992 (2023), 570--578."},{"key":"e_1_3_2_1_6_1","first-page":"37068","article-title":"Badprompt: Backdoor attacks on continuous prompts","volume":"35","author":"Cai Xiangrui","year":"2022","unstructured":"Xiangrui Cai, Haidong Xu, Sihan Xu, Ying Zhang, et al. 2022. Badprompt: Backdoor attacks on continuous prompts. Advances in Neural Information Processing Systems, Vol. 35 (2022), 37068--37080.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i16.29728"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591631"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531940"},{"key":"e_1_3_2_1_11_1","volume-title":"Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality. See https:\/\/vicuna. lmsys. org (accessed","author":"Chiang Wei-Lin","year":"2023","unstructured":"Wei-Lin Chiang, Zhuohan Li, Zi Lin, Ying Sheng, Zhanghao Wu, Hao Zhang, Lianmin Zheng, Siyuan Zhuang, Yonghao Zhuang, Joseph E Gonzalez, et al. 2023. Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality. See https:\/\/vicuna. lmsys. org (accessed 14 April 2023), Vol. 2, 3 (2023), 6."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1137\/0217049"},{"key":"e_1_3_2_1_13_1","volume-title":"Security and privacy challenges of large language models: A survey. arXiv preprint arXiv:2402.00888","author":"Das Badhan Chandra","year":"2024","unstructured":"Badhan Chandra Das, M Hadi Amini, and Yanzhao Wu. 2024. Security and privacy challenges of large language models: A survey. arXiv preprint arXiv:2402.00888 (2024)."},{"key":"e_1_3_2_1_14_1","volume-title":"Black-Box Prompt Learning for Pre-trained Language Models. Transactions on Machine Learning Research","author":"Diao Shizhe","year":"2022","unstructured":"Shizhe Diao, Zhichao Huang, Ruijia Xu, Xuechun Li, LIN Yong, Xiao Zhou, and Tong Zhang. 2022. Black-Box Prompt Learning for Pre-trained Language Models. Transactions on Machine Learning Research (2022)."},{"key":"e_1_3_2_1_15_1","volume-title":"PPT: Backdoor Attacks on Pre-trained Models via Poisoned Prompt Tuning.. In IJCAI. 680--686.","author":"Du Wei","year":"2022","unstructured":"Wei Du, Yichun Zhao, Boqun Li, Gongshen Liu, and Shilin Wang. 2022. PPT: Backdoor Attacks on Pre-trained Models via Poisoned Prompt Tuning.. In IJCAI. 680--686."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICWS62655.2024.00138"},{"key":"e_1_3_2_1_17_1","volume-title":"International conference on machine learning. PMLR, 1568--1577","author":"Franceschi Luca","year":"2018","unstructured":"Luca Franceschi, Paolo Frasconi, Saverio Salzo, Riccardo Grazzi, and Massimiliano Pontil. 2018. Bilevel programming for hyperparameter optimization and meta-learning. In International conference on machine learning. PMLR, 1568--1577."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM52122.2024.10621105"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671932"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583348"},{"key":"e_1_3_2_1_21_1","volume-title":"Unsupervised Dense Information Retrieval with Contrastive Learning. Transactions on Machine Learning Research","author":"Izacard Gautier","year":"2022","unstructured":"Gautier Izacard, Mathilde Caron, Lucas Hosseini, Sebastian Riedel, Piotr Bojanowski, Armand Joulin, and Edouard Grave. 2022. Unsupervised Dense Information Retrieval with Contrastive Learning. Transactions on Machine Learning Research (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"International conference on machine learning. PMLR, 4882--4892","author":"Ji Kaiyi","year":"2021","unstructured":"Kaiyi Ji, Junjie Yang, and Yingbin Liang. 2021. Bilevel optimization: Convergence analysis and enhanced design. In International conference on machine learning. PMLR, 4882--4892."},{"key":"e_1_3_2_1_23_1","volume-title":"Tri-Level Navigator: LLM-Empowered Tri-Level Learning for Time Series OOD Generalization. In The Thirty-eighth Annual Conference on Neural Information Processing Systems.","author":"Jian Chengtao","year":"2024","unstructured":"Chengtao Jian, Kai Yang, and Yang Jiao. 2024. Tri-Level Navigator: LLM-Empowered Tri-Level Learning for Time Series OOD Generalization. In The Thirty-eighth Annual Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_1_24_1","volume-title":"Unlocking TriLevel Learning with Level-Wise Zeroth Order Constraints: Distributed Algorithms and Provable Non-Asymptotic Convergence. arXiv preprint arXiv:2412.07138","author":"Jiao Yang","year":"2024","unstructured":"Yang Jiao, Kai Yang, and Chengtao Jian. 2024a. Unlocking TriLevel Learning with Level-Wise Zeroth Order Constraints: Distributed Algorithms and Provable Non-Asymptotic Convergence. arXiv preprint arXiv:2412.07138 (2024)."},{"key":"e_1_3_2_1_25_1","volume-title":"Distributed distributionally robust optimization with non-convex objectives. Advances in neural information processing systems","author":"Jiao Yang","year":"2022","unstructured":"Yang Jiao, Kai Yang, and Dongjin Song. 2022a. Distributed distributionally robust optimization with non-convex objectives. Advances in neural information processing systems, Vol. 35 (2022), 7987--7999."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2022.3148276"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i11.29190"},{"key":"e_1_3_2_1_28_1","volume-title":"Asynchronous Distributed Bilevel Optimization. In The Eleventh International Conference on Learning Representations.","author":"Jiao Yang","year":"2023","unstructured":"Yang Jiao, Kai Yang, Tiancheng Wu, Dongjin Song, and Chengtao Jian. 2023. Asynchronous Distributed Bilevel Optimization. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3652583.3658086"},{"key":"e_1_3_2_1_30_1","volume-title":"Scaling laws for neural language models. arXiv preprint arXiv:2001.08361","author":"Kaplan Jared","year":"2020","unstructured":"Jared Kaplan, Sam McCandlish, Tom Henighan, Tom B Brown, Benjamin Chess, Rewon Child, Scott Gray, Alec Radford, Jeffrey Wu, and Dario Amodei. 2020. Scaling laws for neural language models. arXiv preprint arXiv:2001.08361 (2020)."},{"key":"e_1_3_2_1_31_1","volume-title":"The social amplification of risk: A conceptual framework. Risk analysis","author":"Kasperson Roger E","year":"1988","unstructured":"Roger E Kasperson, Ortwin Renn, Paul Slovic, Halina S Brown, Jacque Emel, Robert Goble, Jeanne X Kasperson, and Samuel Ratick. 1988. The social amplification of risk: A conceptual framework. Risk analysis, Vol. 8, 2 (1988), 177--187."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00276"},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of the 29th International Conference on Computational Linguistics. 1943--1952","author":"Li Haochen","year":"2022","unstructured":"Haochen Li, Tong Mo, Hongcheng Fan, Jingkun Wang, Jiaxi Wang, Fuhao Zhang, and Weiping Li. 2022. KiPT: Knowledge-injected prompt tuning for event detection. In Proceedings of the 29th International Conference on Computational Linguistics. 1943--1952."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.33"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3532048"},{"key":"e_1_3_2_1_37_1","volume-title":"A simple first-order approach. Advances in neural information processing systems","author":"Liu Bo","year":"2022","unstructured":"Bo Liu, Mao Ye, Stephen Wright, Peter Stone, and Qiang Liu. 2022. Bome! bilevel optimization made easy: A simple first-order approach. Advances in neural information processing systems, Vol. 35 (2022), 17248--17262."},{"key":"e_1_3_2_1_38_1","volume-title":"International conference on machine learning. PMLR, 6882--6892","author":"Liu Risheng","year":"2021","unstructured":"Risheng Liu, Xuan Liu, Xiaoming Yuan, Shangzhi Zeng, and Jin Zhang. 2021a. A value-function-based interior-point method for non-convex bi-level optimization. In International conference on machine learning. PMLR, 6882--6892."},{"key":"e_1_3_2_1_39_1","first-page":"8662","article-title":"Towards gradient-based bilevel optimization with non-convex followers and beyond","volume":"34","author":"Liu Risheng","year":"2021","unstructured":"Risheng Liu, Yaohua Liu, Shangzhi Zeng, and Jin Zhang. 2021b. Towards gradient-based bilevel optimization with non-convex followers and beyond. Advances in Neural Information Processing Systems, Vol. 34 (2021), 8662--8675.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_40_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu Tong","year":"2024","unstructured":"Tong Liu, Yingjie Zhang, Zhe Zhao, Yinpeng Dong, Guozhu Meng, and Kai Chen. 2024c. Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction. In 33rd USENIX Security Symposium (USENIX Security 24). 4711--4728."},{"key":"e_1_3_2_1_41_1","unstructured":"Yi Liu Gelei Deng Yuekang Li Kailong Wang Zihao Wang Xiaofeng Wang Tianwei Zhang Yepang Liu Haoyu Wang Yan Zheng et al. 2023. Prompt Injection attack against LLM-integrated Applications. arXiv preprint arXiv:2306.05499 (2023)."},{"key":"e_1_3_2_1_42_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu Yupei","year":"2024","unstructured":"Yupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia, and Neil Zhenqiang Gong. 2024a. Formalizing and benchmarking prompt injection attacks and defenses. In 33rd USENIX Security Symposium (USENIX Security 24). 1831--1847."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657704"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i20.30232"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671956"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-024-64827-6"},{"key":"e_1_3_2_1_47_1","volume-title":"Revolutionizing edge ai and vision with open, customizable models. Meta AI","author":"Meta AI","year":"2024","unstructured":"AI Meta. 2024. Llama 3.2: Revolutionizing edge ai and vision with open, customizable models. Meta AI (2024)."},{"key":"e_1_3_2_1_48_1","unstructured":"Tri Nguyen Mir Rosenberg Xia Song Jianfeng Gao Saurabh Tiwary Rangan Majumder and Li Deng. 2016. Ms marco: A human-generated machine reading comprehension dataset. (2016)."},{"key":"e_1_3_2_1_49_1","volume-title":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 2284--2295","author":"Wang Shijie","year":"2024","unstructured":"Liang-bo Ning, Shijie Wang, Wenqi Fan, Qing Li, Xin Xu, Hao Chen, and Feiran Huang. 2024. Cheatagent: Attacking llm-empowered recommender systems via llm agent. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 2284--2295."},{"key":"e_1_3_2_1_50_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Pan Xudong","year":"2022","unstructured":"Xudong Pan, Mi Zhang, Beina Sheng, Jiaming Zhu, and Min Yang. 2022. Hidden trigger backdoor attack on {NLP} models via linguistic style manipulation. In 31st USENIX Security Symposium (USENIX Security 22). 3611--3628."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-emnlp.97"},{"key":"e_1_3_2_1_52_1","volume-title":"Ignore Previous Prompt: Attack Techniques For Language Models. In NeurIPS ML Safety Workshop.","author":"Perez F\u00e1bio","unstructured":"F\u00e1bio Perez and Ian Ribeiro. [n.,d.]. Ignore Previous Prompt: Attack Techniques For Language Models. In NeurIPS ML Safety Workshop."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01526"},{"key":"e_1_3_2_1_55_1","volume-title":"Jordan S Ellenberg, Pengming Wang, Omar Fawzi, et al.","author":"Romera-Paredes Bernardino","year":"2024","unstructured":"Bernardino Romera-Paredes, Mohammadamin Barekatain, Alexander Novikov, Matej Balog, M Pawan Kumar, Emilien Dupont, Francisco JR Ruiz, Jordan S Ellenberg, Pengming Wang, Omar Fawzi, et al. 2024. Mathematical discoveries from program search with large language models. Nature, Vol. 625, 7995 (2024), 468--475."},{"key":"e_1_3_2_1_56_1","volume-title":"The logical structure of the social amplification of risk framework (SARF): Metatheoretical foundations and policy implications. The social amplification of risk","author":"Rosa Eugene A","year":"2003","unstructured":"Eugene A Rosa. 2003. The logical structure of the social amplification of risk framework (SARF): Metatheoretical foundations and policy implications. The social amplification of risk, Vol. 47 (2003), 47--49."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657783"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657733"},{"key":"e_1_3_2_1_59_1","first-page":"7522","article-title":"A gradient method for multilevel optimization","volume":"34","author":"Sato Ryo","year":"2021","unstructured":"Ryo Sato, Mirai Tanaka, and Akiko Takeda. 2021. A gradient method for multilevel optimization. Advances in Neural Information Processing Systems, Vol. 34 (2021), 7522--7533.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.302"},{"key":"e_1_3_2_1_61_1","volume-title":"do anything now'': Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv preprint arXiv:2308.03825","author":"Shen Xinyue","year":"2023","unstructured":"Xinyue Shen, Zeyuan Chen, Michael Backes, Yun Shen, and Yang Zhang. 2023. '' do anything now'': Characterizing and evaluating in-the-wild jailbreak prompts on large language models. arXiv preprint arXiv:2308.03825 (2023)."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-emnlp.733"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3673791.3698415"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.231"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.34740\/KAGGLE\/M\/3301"},{"key":"e_1_3_2_1_66_1","series-title":"Round 2","volume-title":"Thirty-fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track","author":"Thakur Nandan","unstructured":"Nandan Thakur, Nils Reimers, Andreas R\u00fcckl\u00e9, Abhishek Srivastava, and Iryna Gurevych. [n.,d.]. BEIR: A Heterogeneous Benchmark for Zero-shot Evaluation of Information Retrieval Models. In Thirty-fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track (Round 2)."},{"key":"e_1_3_2_1_67_1","unstructured":"Hugo Touvron Louis Martin Kevin Stone Peter Albert Amjad Almahairi Yasmine Babaei Nikolay Bashlykov Soumya Batra Prajjwal Bhargava Shruti Bhosale et al. 2023. Llama 2: Open foundation and fine-tuned chat models. arXiv preprint arXiv:2307.09288 (2023)."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.13"},{"key":"e_1_3_2_1_69_1","volume-title":"International Conference on Machine Learning. PMLR, 35413--35425","author":"Wan Alexander","year":"2023","unstructured":"Alexander Wan, Eric Wallace, Sheng Shen, and Dan Klein. 2023. Poisoning language models during instruction tuning. In International Conference on Machine Learning. PMLR, 35413--35425."},{"key":"e_1_3_2_1_70_1","unstructured":"Ben Wang and Aran Komatsuzaki. 2021. GPT-J-6B: A 6 Billion Parameter Autoregressive Language Model. https:\/\/github.com\/kingoflolz\/mesh-transformer-jax."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.157"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.140"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657853"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531892"},{"key":"e_1_3_2_1_75_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Wen Yuxin","year":"2024","unstructured":"Yuxin Wen, Neel Jain, John Kirchenbauer, Micah Goldblum, Jonas Geiping, and Tom Goldstein. 2024. Hard prompts made easy: Gradient-based discrete optimization for prompt tuning and discovery. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1111\/risa.13228"},{"key":"e_1_3_2_1_77_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Xi Zhaohan","year":"2024","unstructured":"Zhaohan Xi, Tianyu Du, Changjiang Li, Ren Pang, Shouling Ji, Jinghui Chen, Fenglong Ma, and Ting Wang. 2024. Defending pre-trained language models as few-shot learners against backdoor attacks. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.908"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.443"},{"key":"e_1_3_2_1_80_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Xue Jiaqi","year":"2024","unstructured":"Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau B\u00f6l\u00f6ni, and Qian Lou. 2024. Trojllm: A black-box trojan prompt attack on large language models. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2024.3367788"},{"key":"e_1_3_2_1_82_1","first-page":"13670","article-title":"Provably faster algorithms for bilevel optimization","volume":"34","author":"Yang Junjie","year":"2021","unstructured":"Junjie Yang, Kaiyi Ji, and Yingbin Liang. 2021. Provably faster algorithms for bilevel optimization. Advances in Neural Information Processing Systems, Vol. 34 (2021), 13670--13682.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_83_1","unstructured":"Junwei Yang Hanwen Xu Srbuhi Mirzoyan Tong Chen Zixuan Liu Zequn Liu Wei Ju Luchen Liu Zhiping Xiao Ming Zhang et al. 2024b. Poisoning medical knowledge using large language models. Nature Machine Intelligence (2024) 1--13."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1259"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP48485.2024.10448041"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP48485.2024.10446267"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00209"},{"key":"e_1_3_2_1_88_1","volume-title":"A survey on large language model (llm) security and privacy: The good, the bad, and the ugly. High-Confidence Computing","author":"Yao Yifan","year":"2024","unstructured":"Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, and Yue Zhang. 2024a. A survey on large language model (llm) security and privacy: The good, the bad, and the ugly. High-Confidence Computing (2024), 100211."},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20872"},{"key":"e_1_3_2_1_90_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Yu Zhiyuan","year":"2024","unstructured":"Zhiyuan Yu, Xiaogeng Liu, Shunning Liang, Zach Cameron, Chaowei Xiao, and Ning Zhang. 2024. Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.871"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6226"},{"key":"e_1_3_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657781"},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1145\/3663529.3663786"},{"key":"e_1_3_2_1_95_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Zhang Rui","year":"2024","unstructured":"Rui Zhang, Hongwei Li, Rui Wen, Wenbo Jiang, Yuan Zhang, Michael Backes, Yun Shen, and Yang Zhang. 2024b. Instruction backdoor attacks against customized {LLMs}. In 33rd USENIX Security Symposium (USENIX Security 24). 1849--1866."},{"key":"e_1_3_2_1_96_1","volume-title":"Revisiting Zeroth-Order Optimization for Memory-Efficient LLM Fine-Tuning: A Benchmark. In Forty-first International Conference on Machine Learning.","author":"Zhang Yihua","unstructured":"Yihua Zhang, Pingzhi Li, Junyuan Hong, Jiaxiang Li, Yimeng Zhang, Wenqing Zheng, Pin-Yu Chen, Jason D Lee, Wotao Yin, Mingyi Hong, et al. [n.,d.]. Revisiting Zeroth-Order Optimization for Memory-Efficient LLM Fine-Tuning: A Benchmark. In Forty-first International Conference on Machine Learning."},{"key":"e_1_3_2_1_97_1","volume-title":"International Conference on Machine Learning. PMLR, 26693--26712","author":"Zhang Yihua","year":"2022","unstructured":"Yihua Zhang, Guanhua Zhang, Prashant Khanduri, Mingyi Hong, Shiyu Chang, and Sijia Liu. 2022. Revisiting and advancing fast adversarial training through the lens of bi-level optimization. In International Conference on Machine Learning. PMLR, 26693--26712."},{"key":"e_1_3_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591752"},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.849"},{"key":"e_1_3_2_1_100_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Zhou Wenzhuo","year":"2024","unstructured":"Wenzhuo Zhou. 2024. Bi-level offline policy optimization with limited exploration. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i17.29949"},{"key":"e_1_3_2_1_102_1","volume-title":"First Conference on Language Modeling.","author":"Zhu Sicheng","year":"2024","unstructured":"Sicheng Zhu, Ruiyi Zhang, Bang An, Gang Wu, Joe Barrow, Zichao Wang, Furong Huang, Ani Nenkova, and Tong Sun. 2024. AutoDAN: interpretable gradient-based adversarial attacks on large language models. In First Conference on Language Modeling."},{"key":"e_1_3_2_1_103_1","volume-title":"Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043","author":"Zou Andy","year":"2023","unstructured":"Andy Zou, Zifan Wang, Nicholas Carlini, Milad Nasr, J Zico Kolter, and Matt Fredrikson. 2023. Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv:2307.15043 (2023)."},{"key":"e_1_3_2_1_104_1","volume-title":"Poisonedrag: Knowledge poisoning attacks to retrieval-augmented generation of large language models. arXiv preprint arXiv:2402.07867","author":"Zou Wei","year":"2024","unstructured":"Wei Zou, Runpeng Geng, Binghui Wang, and Jinyuan Jia. 2024. Poisonedrag: Knowledge poisoning attacks to retrieval-augmented generation of large language models. arXiv preprint arXiv:2402.07867 (2024)."}],"event":{"name":"SIGIR '25: The 48th International ACM SIGIR Conference on Research and Development in Information Retrieval","location":"Padua Italy","acronym":"SIGIR '25","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval"]},"container-title":["Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3726302.3730058","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T10:01:24Z","timestamp":1755856884000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3726302.3730058"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,13]]},"references-count":104,"alternative-id":["10.1145\/3726302.3730058","10.1145\/3726302"],"URL":"https:\/\/doi.org\/10.1145\/3726302.3730058","relation":{},"subject":[],"published":{"date-parts":[[2025,7,13]]},"assertion":[{"value":"2025-07-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}