{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T16:06:05Z","timestamp":1780675565843,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":16,"publisher":"ACM","funder":[{"name":"National Natural Science Foundation of China","award":["62372268"],"award-info":[{"award-number":["62372268"]}]},{"name":"Key R&D Program of Shandong Province, China","award":["2024CXGC010114"],"award-info":[{"award-number":["2024CXGC010114"]}]},{"name":"Key R&D Program of Shandong Province, China","award":["2025CXPT085"],"award-info":[{"award-number":["2025CXPT085"]}]},{"name":"National Natural Science Foundation of China","award":["62302473"],"award-info":[{"award-number":["62302473"]}]},{"name":"CCF-Huawei Populus Grove Fund","award":["CCF-HuaweiTC202416"],"award-info":[{"award-number":["CCF-HuaweiTC202416"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3774904.3792344","type":"proceedings-article","created":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T21:54:34Z","timestamp":1775771674000},"page":"2881-2892","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["ICL-Evader: Zero-Query Black-Box Evasion Attacks on In-Context Learning and Their Defenses"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-0648-0290","authenticated-orcid":false,"given":"Ningyuan","family":"He","sequence":"first","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-5696-272X","authenticated-orcid":false,"given":"Ronghong","family":"Huang","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-6990-2653","authenticated-orcid":false,"given":"Qianqian","family":"Tang","sequence":"additional","affiliation":[{"name":"Shandong University, Qingdao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-4145-2104","authenticated-orcid":false,"given":"Hongyu","family":"Wang","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8747-5601","authenticated-orcid":false,"given":"Xianghang","family":"Mi","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China and Monash University, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3367-0951","authenticated-orcid":false,"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[{"name":"Shandong University, Qingdao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Rishabh Agarwal Avi Singh Lei M. Zhang Bernd Bohnet Luis Rosias Stephanie Chan Biao Zhang Ankesh Anand Zaheer Abbas Azade Nova John D. Co-Reyes Eric Chu Feryal Behbahani Aleksandra Faust and Hugo Larochelle. 2024. Many-Shot In-Context Learning. arXiv:2404.11018 [cs.LG] https:\/\/arxiv.org\/abs\/2404.11018"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Amanda Bertsch Maor Ivgi Emily Xiao Uri Alon Jonathan Berant Matthew R. Gormley and Graham Neubig. 2025. In-Context Learning with Long-Context Models: An In-Depth Exploration. arXiv:2405.00200 [cs.CL] https:\/\/arxiv.org\/abs\/2405.00200","DOI":"10.18653\/v1\/2025.naacl-long.605"},{"key":"e_1_3_2_1_3_1","volume-title":"Bad Characters: Imperceptible NLP Attacks. In IEEE Symposium on Security and Privacy (SP). https:\/\/github.com\/nickboucher\/imperceptible","author":"Boucher Nicholas","year":"2022","unstructured":"Nicholas Boucher, Ilia Shumailov, Ross Anderson, and Nicolas Papernot. 2022. Bad Characters: Imperceptible NLP Attacks. In IEEE Symposium on Security and Privacy (SP). https:\/\/github.com\/nickboucher\/imperceptible"},{"key":"e_1_3_2_1_4_1","first-page":"4171","volume-title":"Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies","volume":"1","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Bert: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). 4171-4186."},{"key":"e_1_3_2_1_5_1","volume-title":"Hotflip: White-box adversarial examples for text classification. arXiv preprint arXiv:1712.06751","author":"Ebrahimi Javid","year":"2017","unstructured":"Javid Ebrahimi, Anyi Rao, Daniel Lowd, and Dejing Dou. 2017. Hotflip: White-box adversarial examples for text classification. arXiv preprint arXiv:1712.06751 (2017)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_3_2_1_7_1","unstructured":"Jigsaw (Google). 2018. Toxic Comment Classification Challenge Dataset. Kaggle Competition Dataset. https:\/\/www.kaggle.com\/c\/jigsaw-toxic-comment-classification-challenge Dataset for classifying toxic online comments into multiple categories.."},{"key":"e_1_3_2_1_8_1","volume-title":"Muhammad Ahmed Chaudhry, Jonathan H. Chen, and Andrew Y. Ng.","author":"Jiang Yixing","year":"2024","unstructured":"Yixing Jiang, Jeremy Irvin, Ji Hun Wang, Muhammad Ahmed Chaudhry, Jonathan H. Chen, and Andrew Y. Ng. 2024. Many-Shot In-Context Learning in Multimodal Foundation Models. arXiv:2405.09798 [cs.LG] https:\/\/arxiv.org\/abs\/2405.09798"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6311"},{"key":"e_1_3_2_1_10_1","volume-title":"TEXTBUGGER: Generating Adversarial Text Against Real-world Applications. In Network and Distributed System Security Symposium (NDSS). https:\/\/github.com\/QData\/TextAttack","author":"Li Jinfeng","year":"2018","unstructured":"Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. 2018. TEXTBUGGER: Generating Adversarial Text Against Real-world Applications. In Network and Distributed System Security Symposium (NDSS). https:\/\/github.com\/QData\/TextAttack"},{"key":"e_1_3_2_1_11_1","unstructured":"Aixin Liu Bei Feng Bing Xue Bingxuan Wang Bochao Wu Chengda Lu Chenggang Zhao Chengqi Deng Chenyu Zhang Chong Ruan et al. 2024. Deepseek-v3 technical report. arXiv preprint arXiv:2412.19437 (2024)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"e_1_3_2_1_13_1","unstructured":"Hongyu Wang Ying Li Ronghong Huang and Xianghang Mi. 2024. Illicit Promotion on Twitter. arXiv:2404.07797 [cs.CR]"},{"key":"e_1_3_2_1_14_1","unstructured":"Sangyi Wu Jialong Xue Shaoxuan Zhou and Xianghang Mi. 2024. Reflected Search Poisoning for Illicit Promotion. arXiv:2404.05320 [cs.CR] https:\/\/arxiv.org\/abs\/2404.05320"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-023-00765-8"},{"key":"e_1_3_2_1_16_1","volume-title":"Pan","author":"Yu Simon","year":"2024","unstructured":"Simon Yu, Jie He, Pasquale Minervini, and Jeff Z. Pan. 2024. Evaluating and Safeguarding the Adversarial Robustness of Retrieval-Based In-Context Learning. arXiv:2405.15984 [cs.CL] https:\/\/arxiv.org\/abs\/2405.15984"}],"event":{"name":"WWW '26: The ACM Web Conference 2026","location":"Dubai United Arab Emirates","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2026"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3774904.3792344","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T15:36:06Z","timestamp":1780673766000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3774904.3792344"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":16,"alternative-id":["10.1145\/3774904.3792344","10.1145\/3774904"],"URL":"https:\/\/doi.org\/10.1145\/3774904.3792344","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}