{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T14:43:23Z","timestamp":1775745803999,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,10]]},"DOI":"10.1145\/3746252.3760946","type":"proceedings-article","created":{"date-parts":[[2025,11,8]],"date-time":"2025-11-08T00:36:36Z","timestamp":1762562196000},"page":"4633-4638","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Pruning Strategies for Backdoor Defense in LLMs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1590-5917","authenticated-orcid":false,"given":"Santosh","family":"Chapagain","sequence":"first","affiliation":[{"name":"Department of Computer Science, Utah State University, Logan, UT, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9303-7835","authenticated-orcid":false,"given":"Shah Muhammad","family":"Hamdi","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Utah State University, Logan, UT, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5693-6383","authenticated-orcid":false,"given":"Soukaina Filali","family":"Boubrahimi","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Utah State University, Logan, UT, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,10]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"2255","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Azizi Ahmadreza","year":"2021","unstructured":"Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar, Jiameng Pu, Mobin Javed, Chandan K Reddy, and Bimal Viswanath. 2021. {T-Miner}: A generative approach to defend against trojan attacks on {DNN-based} text classification. In 30th USENIX Security Symposium (USENIX Security 21). 2255-2272."},{"key":"e_1_3_2_1_2_1","volume-title":"Yuanzhi Li, Scott Lundberg, et al.","author":"Bubeck S\u00e9bastien","year":"2023","unstructured":"S\u00e9bastien Bubeck, Varun Chadrasekaran, Ronen Eldan, Johannes Gehrke, Eric Horvitz, Ece Kamar, Peter Lee, Yin Tat Lee, Yuanzhi Li, Scott Lundberg, et al., 2023. Sparks of artificial general intelligence: Early experiments with gpt-4."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v18i1.31433"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData59044.2023.10386882"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/s13278-025-01521-z"},{"key":"e_1_3_2_1_6_1","volume-title":"Shah Muhammad Hamdi, and Soukaina Filali Boubrahimi","author":"Chapagain Santosh","year":"2025","unstructured":"Santosh Chapagain, Shah Muhammad Hamdi, and Soukaina Filali Boubrahimi. 2025b. Advancing Hate Speech Detection with Transformers: Insights from the MetaHate. arXiv:2508.04913 [cs.LG] https:\/\/arxiv.org\/abs\/2508.04913"},{"key":"e_1_3_2_1_7_1","volume-title":"Soukaina Filali Boubrahimi, Ryan E Flinn, Emily M Lund, Dannie Klooster, Jillian R Scheer, and Cory J Cascalheira.","author":"Chapagain Santosh","year":"2024","unstructured":"Santosh Chapagain, Yuxuan Zhao, Taylor K Rohleen, Shah Muhammad Hamdi, Soukaina Filali Boubrahimi, Ryan E Flinn, Emily M Lund, Dannie Klooster, Jillian R Scheer, and Cory J Cascalheira. 2024. Predictive Insights into LGBTQ Minority Stress: A Transductive Exploration of Social Media Discourse. arXiv preprint arXiv:2411.13534 (2024)."},{"key":"e_1_3_2_1_8_1","volume-title":"Badpre: Task-agnostic backdoor attacks to pre-trained nlp foundation models. arXiv preprint arXiv:2110.02467","author":"Chen Kangjie","year":"2021","unstructured":"Kangjie Chen, Yuxian Meng, Xiaofei Sun, Shangwei Guo, Tianwei Zhang, Jiwei Li, and Chun Fan. 2021. Badpre: Task-agnostic backdoor attacks to pre-trained nlp foundation models. arXiv preprint arXiv:2110.02467 (2021)."},{"key":"e_1_3_2_1_9_1","first-page":"4171","volume-title":"Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies","volume":"1","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Bert: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). 4171-4186."},{"key":"e_1_3_2_1_10_1","volume-title":"Stochastic activation pruning for robust adversarial defense. arXiv preprint arXiv:1803.01442","author":"Dhillon Guneet S","year":"2018","unstructured":"Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Anima Anandkumar. 2018. Stochastic activation pruning for robust adversarial defense. arXiv preprint arXiv:1803.01442 (2018)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.3847\/1538-4365\/ad7c4a"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.naacl-main.214"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3055844"},{"key":"e_1_3_2_1_14_1","volume-title":"What doesn't kill you makes you robust (er): How to adversarially train against data poisoning. arXiv preprint arXiv:2102.13624","author":"Geiping Jonas","year":"2021","unstructured":"Jonas Geiping, Liam Fowl, Gowthami Somepalli, Micah Goldblum, Michael Moeller, and Tom Goldstein. 2021. What doesn't kill you makes you robust (er): How to adversarially train against data poisoning. arXiv preprint arXiv:2102.13624 (2021)."},{"key":"e_1_3_2_1_15_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.repl4nlp-1.1"},{"key":"e_1_3_2_1_17_1","volume-title":"Universal language model fine-tuning for text classification. arXiv preprint arXiv:1801.06146","author":"Howard Jeremy","year":"2018","unstructured":"Jeremy Howard and Sebastian Ruder. 2018. Universal language model fine-tuning for text classification. arXiv preprint arXiv:1801.06146 (2018)."},{"key":"e_1_3_2_1_18_1","volume-title":"Vaccine: Perturbation-aware alignment for large language models against harmful fine-tuning attack. arXiv preprint arXiv:2402.01109","author":"Huang Tiansheng","year":"2024","unstructured":"Tiansheng Huang, Sihao Hu, and Ling Liu. 2024. Vaccine: Perturbation-aware alignment for large language models against harmful fine-tuning attack. arXiv preprint arXiv:2402.01109 (2024)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-1170"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645643"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.55"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.241"},{"key":"e_1_3_2_1_24_1","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume":"34","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021a. Anti-backdoor learning: Training clean models on poisoned data. Advances in Neural Information Processing Systems, Vol. 34 (2021), 14900-14912.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_25_1","unstructured":"Hongyi Liu Shaochen Zhong Xintong Sun Minghao Tian Mohsen Hariri Zirui Liu Ruixiang Tang Zhimeng Jiang Jiayi Yuan Yu-Neng Chuang et al. 2024. LoRATK: LoRA Once Backdoor Everywhere in the Share-and-Play Ecosystem. arXiv preprint arXiv:2403.00108 (2024)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.237"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3604237.3626891"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.naacl-main.348"},{"key":"e_1_3_2_1_31_1","volume-title":"Are sixteen heads really better than one? Advances in neural information processing systems","author":"Michel Paul","year":"2019","unstructured":"Paul Michel, Omer Levy, and Graham Neubig. 2019. Are sixteen heads really better than one? Advances in neural information processing systems, Vol. 32 (2019)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.377"},{"key":"e_1_3_2_1_36_1","volume-title":"International Conference on Machine Learning. PMLR","author":"Shen Guangyu","year":"2022","unstructured":"Guangyu Shen, Yingqi Liu, Guanhong Tao, Qiuling Xu, Zhuo Zhang, Shengwei An, Shiqing Ma, and Xiangyu Zhang. 2022. Constrained optimization with dynamic bound-scaling for effective nlp backdoor defense. In International Conference on Machine Learning. PMLR, 19879-19892."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_2_1_38_1","volume-title":"Proceedings of the 37th International Conference on Neural Information Processing Systems. 73191-73210","author":"Tang Ruixiang","year":"2023","unstructured":"Ruixiang Tang, Jiayi Yuan, Yiming Li, Zirui Liu, Rui Chen, and Xia Hu. 2023. Setting the trap: capturing and defeating backdoors in pretrained language models through honeypots. In Proceedings of the 37th International Conference on Neural Information Processing Systems. 73191-73210."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.725"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.337"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.165"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.659"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.431"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.157"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.findings-emnlp.26"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.5555\/3692070.3694597"},{"key":"e_1_3_2_1_49_1","volume-title":"A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations. arXiv preprint arXiv:2502.05224","author":"Zhou Yihe","year":"2025","unstructured":"Yihe Zhou, Tao Ni, Wei-Bin Lee, and Qingchuan Zhao. 2025. A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations. arXiv preprint arXiv:2502.05224 (2025)."},{"key":"e_1_3_2_1_50_1","volume-title":"Proceedings of the 36th International Conference on Neural Information Processing Systems. 1086-1099","author":"Zhu Biru","year":"2022","unstructured":"Biru Zhu, Yujia Qin, Ganqu Cui, Yangyi Chen, Weilin Zhao, Chong Fu, Yangdong Deng, Zhiyuan Liu, Jingang Wang, Wei Wu, et al., 2022. Moderate-fitting as a natural backdoor defender for pre-trained language models. In Proceedings of the 36th International Conference on Neural Information Processing Systems. 1086-1099."}],"event":{"name":"CIKM '25: The 34th ACM International Conference on Information and Knowledge Management","location":"Seoul Republic of Korea","acronym":"CIKM '25","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval","SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the 34th ACM International Conference on Information and Knowledge Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3746252.3760946","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T02:07:56Z","timestamp":1765505276000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3746252.3760946"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,10]]},"references-count":50,"alternative-id":["10.1145\/3746252.3760946","10.1145\/3746252"],"URL":"https:\/\/doi.org\/10.1145\/3746252.3760946","relation":{},"subject":[],"published":{"date-parts":[[2025,11,10]]},"assertion":[{"value":"2025-11-10","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}