{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T13:01:58Z","timestamp":1785502918835,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","funder":[{"name":"China Postdoctoral Science Foundation","award":["2024M751050"],"award-info":[{"award-number":["2024M751050"]}]},{"name":"Post-doctoral Fellowship Program of CPSF","award":["GZC20230922"],"award-info":[{"award-number":["GZC20230922"]}]},{"name":"Hubei Province Postdoctoral Innovation Talen Training Project","award":["2024HBBHCXB042"],"award-info":[{"award-number":["2024HBBHCXB042"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,8,9]]},"DOI":"10.1145\/3770854.3780227","type":"proceedings-article","created":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T12:07:40Z","timestamp":1785499660000},"page":"867-878","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1345-5736","authenticated-orcid":false,"given":"Hui","family":"Liu","sequence":"first","affiliation":[{"name":"Central China Normal University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-2118-1362","authenticated-orcid":false,"given":"Yibo","family":"Zhou","sequence":"additional","affiliation":[{"name":"Central China Normal University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9695-9624","authenticated-orcid":false,"given":"Liguo","family":"Dong","sequence":"additional","affiliation":[{"name":"Central China Normal University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8165-4385","authenticated-orcid":false,"given":"Weidong","family":"Li","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4485-6743","authenticated-orcid":false,"given":"Shui","family":"Yu","sequence":"additional","affiliation":[{"name":"University of Technology Sydney, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,20]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"MS MARCO: A Human Generated MAchine Reading COmprehension Dataset. arXiv:1611.09268 [cs.CL] https:\/\/arxiv.org\/abs\/1611.09268","author":"Bajaj Payal","year":"2018","unstructured":"Payal Bajaj, Daniel Campos, Nick Craswell, Li Deng, Jianfeng Gao, Xiaodong Liu, Rangan Majumder, Andrew McNamara, Bhaskar Mitra, Tri Nguyen, Mir Rosenberg, Xia Song, Alina Stoica, Saurabh Tiwary, and Tong Wang. 2018. MS MARCO: A Human Generated MAchine Reading COmprehension Dataset. arXiv:1611.09268 [cs.CL] https:\/\/arxiv.org\/abs\/1611.09268"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3532682"},{"key":"e_1_3_2_2_3_1","volume-title":"Phantom: General Trigger Attacks on Retrieval Augmented Language Generation. arXiv:2405.20485 [cs.CR] https:\/\/arxiv.org\/abs\/2405.20485","author":"Chaudhari Harsh","year":"2024","unstructured":"Harsh Chaudhari, Giorgio Severi, John Abascal, Matthew Jagielski, Christopher A. Choquette-Choo, Milad Nasr, Cristina Nita-Rotaru, and Alina Oprea. 2024. Phantom: General Trigger Attacks on Retrieval Augmented Language Generation. arXiv:2405.20485 [cs.CR] https:\/\/arxiv.org\/abs\/2405.20485"},{"key":"e_1_3_2_2_4_1","volume-title":"Proceedings of the 38th International Conference on Neural Information Processing Systems","author":"Chen Zhaorun","year":"2025","unstructured":"Zhaorun Chen, Zhen Xiang, Chaowei Xiao, Dawn Song, and Bo Li. 2025. AGENTPOISON: red-teaming LLM agents via poisoning memory or knowledge bases. In Proceedings of the 38th International Conference on Neural Information Processing Systems (Vancouver, BC, Canada) (NIPS '24). Curran Associates Inc., Red Hook, NY, USA, Article 4136, 29 pages."},{"key":"e_1_3_2_2_5_1","unstructured":"Cody Clop and Yannick Teglia. 2024. Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models. arXiv:2410.14479 [cs.CR] https:\/\/arxiv.org\/abs\/2410.14479"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2503.05037"},{"key":"e_1_3_2_2_7_1","unstructured":"Google Cloud. 2024. Gemini 2.0 Flash \u2014 Technical Documentation. https:\/\/cloud.google.com\/vertex-ai\/generative-ai\/docs\/models\/gemini\/2-0-flash. Accessed: 2025-07-18."},{"key":"e_1_3_2_2_8_1","unstructured":"Tianyu Gu Brendan Dolan-Gavitt and Siddharth Garg. 2019. BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain. arXiv:1708.06733 [cs.CR] https:\/\/arxiv.org\/abs\/1708.06733"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671932"},{"key":"e_1_3_2_2_10_1","unstructured":"Zhengmian Hu Gang Wu Saayan Mitra Ruiyi Zhang Tong Sun Heng Huang and Viswanathan Swaminathan. 2024b. Token-Level Adversarial Prompt Detection Based on Perplexity Measures and Contextual Information. arXiv:2311.11509 [cs.CL] https:\/\/arxiv.org\/abs\/2311.11509"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"crossref","unstructured":"Yang Jiao Xiaodong Wang and Kai Yang. 2025. PR-Attack: Coordinated Prompt-RAG Attacks on Retrieval-Augmented Generation in Large Language Models via Bilevel Optimization. arXiv:2504.07717 [cs.CR] https:\/\/arxiv.org\/abs\/2504.07717","DOI":"10.1145\/3726302.3730058"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.550"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00276"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.695"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/3495724.3496517"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657704"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671956"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.173"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-88717-8_18"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3677328"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671837"},{"key":"e_1_3_2_2_25_1","unstructured":"OpenAI. 2025. Introducing GPT-4.1 in the API. https:\/\/openai.com\/index\/gpt-4-1. Accessed: 2025-07-18."},{"key":"e_1_3_2_2_26_1","unstructured":"Yuefeng Peng Junda Wang Hong Yu and Amir Houmansadr. 2025. Data Extraction Attacks in Retrieval-Augmented Generation via Backdoors. arXiv:2411.01705 [cs.CR] https:\/\/arxiv.org\/abs\/2411.01705"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657957"},{"key":"e_1_3_2_2_28_1","unstructured":"Hugo Touvron Thibaut Lavril Gautier Izacard Xavier Martinet Marie-Anne Lachaux Timoth\u00e9e Lacroix Baptiste Rozi\u00e8re Naman Goyal Eric Hambro Faisal Azhar Aurelien Rodriguez Armand Joulin Edouard Grave and Guillaume Lample. 2023. LLaMA: Open and Efficient Foundation Language Models. arXiv:2302.13971 [cs.CL] https:\/\/arxiv.org\/abs\/2302.13971"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.5555\/3618408.3619882"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657853"},{"key":"e_1_3_2_2_31_1","unstructured":"Zhen Xiang Fengqing Jiang Zidi Xiong Bhaskar Ramasubramanian Radha Poovendran and Bo Li. 2024. BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models. arXiv:2401.12242 [cs.CR] https:\/\/arxiv.org\/abs\/2401.12242"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.337"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D18-1259"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657923"},{"key":"e_1_3_2_2_35_1","unstructured":"Chenggang Zhao Chengqi Deng Chong Ruan Damai Dai Huazuo Gao Jiashi Li Liyue Zhang Panpan Huang Shangyan Zhou Shirong Ma Wenfeng Liang Ying He Yuqing Wang Yuxuan Liu and Y. X. Wei. 2025. Insights into DeepSeek-V3: Scaling Challenges and Reflections on Hardware for AI Architectures. arXiv:2505.09343 [cs.DC] https:\/\/arxiv.org\/abs\/2505.09343"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.18653\/V1\/2023.EMNLP-MAIN.849"},{"key":"e_1_3_2_2_37_1","unstructured":"Wei Zou Runpeng Geng Binghui Wang and Jinyuan Jia. 2024. PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models. arXiv:2402.07867 [cs.CR] https:\/\/arxiv.org\/abs\/2402.07867"}],"event":{"name":"KDD '26: The 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Jeju Island Republic of Korea","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3770854.3780227","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T12:14:20Z","timestamp":1785500060000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3770854.3780227"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,20]]},"references-count":37,"alternative-id":["10.1145\/3770854.3780227","10.1145\/3770854"],"URL":"https:\/\/doi.org\/10.1145\/3770854.3780227","relation":{},"subject":[],"published":{"date-parts":[[2026,4,20]]},"assertion":[{"value":"2026-04-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}