{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:02:07Z","timestamp":1780588927145,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":110,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["2532587"],"award-info":[{"award-number":["2532587"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["2239646"],"award-info":[{"award-number":["2239646"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3807480","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1667-1683","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["The Insider's Advantage: Exploiting Automated Privacy Policy Analyzer Tools Through Subtle Text Manipulations"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-1222-6621","authenticated-orcid":false,"given":"Tanusree Das","family":"Tithy","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Cyber Guard Research Lab, The University of Texas at Arlington, Arlington, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3744-4847","authenticated-orcid":false,"given":"Poojitha","family":"Thota","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Security and Privacy Research Lab, The University of Texas at Arlington, Arlington, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0539-3742","authenticated-orcid":false,"given":"Shirin","family":"Nilizadeh","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Security and Privacy Research Lab, The University of Texas at Arlington, Arlington, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1649-0978","authenticated-orcid":false,"given":"Faysal Hossain","family":"Shezan","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Cyber Guard Research Lab, The University of Texas at Arlington, Arlington, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Fine-grained analysis of sentence embeddings using auxiliary prediction tasks. arXiv preprint arXiv:1608.04207","author":"Adi Yossi","year":"2016","unstructured":"Yossi Adi, Einat Kermany, Yonatan Belinkov, Ofer Lavi, and Yoav Goldberg. 2016. Fine-grained analysis of sentence embeddings using auxiliary prediction tasks. arXiv preprint arXiv:1608.04207 (2016)."},{"key":"e_1_3_2_1_2_1","unstructured":"AesirX. 2023. Use AesirX Privacy Scanner for GDPR and ePrivacy Compliance. https:\/\/aesirx.io\/documentation\/scanner\/how-to\/use-aesirx-privacy-scanner-for-gdpr-and-eprivacy-compliance"},{"key":"e_1_3_2_1_3_1","unstructured":"AesirX. 2025. Ignorance or Arrogance? Why Hide Consent Outside Europe. https:\/\/aesirx.io\/blog\/aesirx\/ignorance-or-arrogance-why-hide-consent-outside-europe"},{"key":"e_1_3_2_1_4_1","volume-title":"Coull","author":"Agresti Alan","year":"1998","unstructured":"Alan Agresti and Brent A. Coull. 1998. Approximate is better than \u201cexact\u201d for interval estimation of binomial proportions. The American Statistician (1998)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.66"},{"key":"e_1_3_2_1_6_1","volume-title":"Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie.","author":"Andow Benjamin","year":"2019","unstructured":"Benjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Tao Xie. 2019. PolicyLint: Investigating Internal Privacy Policy Contradictions on Google Play. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/andow"},{"key":"e_1_3_2_1_7_1","volume-title":"29th USENIX Security Symposium (USENLX Security 20)","author":"Andow Benjamin","year":"2020","unstructured":"Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, and Serge Egelman. 2020. Actions speak louder than words:{Entity-Sensitive} privacy policy and data flow analysis with {PoliCheck}. In 29th USENIX Security Symposium (USENLX Security 20). 985\u20131002."},{"key":"e_1_3_2_1_8_1","unstructured":"Anthropic. 2023. Claude-Intro. https:\/\/www.anthropic.com\/index\/introducing-claude"},{"key":"e_1_3_2_1_9_1","unstructured":"Anthropic. 2025. Claude 4.6 Sonnet. https:\/\/www.anthropic.com\/claude\/sonnet. Accessed: 2026-03-16."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-acl.287"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-demo.2"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.3115\/1219044.1219075"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-demo.24"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833641"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","unstructured":"Duc Bui Yuan Yao Kang G. Shin Jong-Min Choi and Junbum Shin. 2021. Consistency Analysis of Data-Usage Purposes in Mobile Apps. https:\/\/doi.org\/10.1145\/3460120.3484536","DOI":"10.1145\/3460120.3484536"},{"key":"e_1_3_2_1_16_1","unstructured":"CallidusAI. 2025. AI Legal Assistant. https:\/\/callidusai.com\/solutions\/ai-legal-assistant\/. Accessed: 2025-06-04."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.821"},{"key":"e_1_3_2_1_18_1","unstructured":"Nicole Case. 2024. The Times They Are A-Changin': The Rise of Generative AI in the Legal Profession. (2024). https:\/\/www.fedbar.org\/blog\/the-times-they-are-a-changin-the-rise-of-generative-ai-in-the-legal-profession\/"},{"key":"e_1_3_2_1_19_1","unstructured":"Daniel Cer Yinfei Yang Sheng-yi Kong Nan Hua Nicole Limtiaco Rhomni St. John Noah Constant Mario Guajardo-Cespedes Steve Yuan Chris Tar Brian Strope and Ray Kurzweil. 2018. Universal Sentence Encoder for English. https:\/\/aclanthology.org\/D18-2029\/"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-5817"},{"key":"e_1_3_2_1_21_1","volume-title":"Advances in Neural Information Processing Systems","author":"Chen Liqun","year":"2018","unstructured":"Liqun Chen, Shuyang Dai, Chenyang Tao, Haichao Zhang, Zhe Gan, Dinghan Shen, Yizhe Zhang, Guoyin Wang, Ruiyi Zhang, and Lawrence Carin. 2018. Adversarial Text Generation via Feature-Mover's Distance. In Advances in Neural Information Processing Systems, S. Bengio, H. Wallach, H. Larochelle, K. Grauman, N. Cesa-Bianchi, and R. Garnett (Eds.). https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/074177d3eb6371e32c16c55a3b8f706b-Paper.pdf"},{"key":"e_1_3_2_1_22_1","unstructured":"The Conversation. 2019. Here's how tech giants profit from invading our privacy and how we can start taking it back. https:\/\/theconversation.com\/heres-how-tech-giants-profit-from-invading-our-privacy-and-how-we-can-start-taking-it-back-120078"},{"key":"e_1_3_2_1_23_1","volume-title":"32nd USENIX Security Symposium (USENLX Security 23)","author":"Cui Hao","year":"2023","unstructured":"Hao Cui, Rahmadi Trimananda, Athina Markopoulou, and Scott Jordan. 2023. PoliGraph: Automated Privacy Policy Analysis using Knowledge Graphs. In 32nd USENIX Security Symposium (USENLX Security 23). Anaheim, CA, 1037\u20131054. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/cui"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1423"},{"key":"e_1_3_2_1_25_1","volume-title":"Towards Robustness Against Natural Language Word Substitutions. In International Conference on Learning Representations.","author":"Dong Xinshuai","unstructured":"Xinshuai Dong, Anh Tuan Luu, Rongrong Ji, and Hong Liu. [n. d.]. Towards Robustness Against Natural Language Word Substitutions. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_3_2_1_27_1","unstructured":"Hugging Face. 2025. Welcome Llama 4 Maverick & Scout on Hugging Face. https:\/\/huggingface.co\/blog\/llama4-release"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Noura Farra Nadi Tomeh Alla Rozovskaya and Nizar Habash. 2014. Generalized Character-Level Spelling Error Correction.","DOI":"10.3115\/v1\/P14-2027"},{"key":"e_1_3_2_1_29_1","unstructured":"Federal Trade Commission. 2019. FTC Imposes $5 Billion Penalty and Sweeping New Privacy Restrictions on Facebook. https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2019\/07\/ftc-imposes-5-billion-penalty-sweeping-new-privacy-restrictions-facebook"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1610"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.498"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW59978.2023.00014"},{"key":"e_1_3_2_1_34_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Harkous Hamza","year":"2018","unstructured":"Hamza Harkous, Kassem Fawaz, R\u00e9mi Lebret, Florian Schaub, Kang G Shin, and Karl Aberer. 2018. Polisis: Automated analysis and presentation of privacy policies using deep learning. In 27th USENIX Security Symposium (USENIX Security 18). 531\u2013548."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.619"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1419"},{"key":"e_1_3_2_1_37_1","unstructured":"ISACA. 2023. Eliminating Deceptive Privacy Practices: Building Trust by Addressing Privacy Dark Patterns. https:\/\/www.isaca.org\/resources\/white-papers\/2023\/eliminating-deceptive-privacy-practices"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1215"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1423"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP)","author":"Jin Di","year":"2019","unstructured":"Di Jin, Zhijing Zhang, Joey Ding, and Huan Wang. 2019. TextFooler: A Black-box Attack for Text Classification Models. Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP) (2019), 1192\u20131203."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.18653\/vl\/2020.acl-main.245"},{"key":"e_1_3_2_1_42_1","volume-title":"Proceedings of the 2021 Conference on Computational Linguistics","author":"Lei Zhang","year":"2021","unstructured":"Zhang Lei and John Smith. 2021. PLAT: Phrase-level Adversarial Text Attack. Proceedings of the 2021 Conference on Computational Linguistics (2021), 789\u2013799."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-emnlp.569"},{"key":"e_1_3_2_1_44_1","unstructured":"Jiyao Li Mingze Ni Yongshun Gong and Wei Liu. 2024. Deceiving Question-Answering Models: A Hybrid Word-Level Adversarial Approach. https:\/\/arxiv.org\/abs\/2411.08248"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlpmain.500"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.17022"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.20"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.251"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.251"},{"key":"e_1_3_2_1_50_1","unstructured":"Zhicheng Lin. 2025. Hidden Prompts in Manuscripts Exploit AI-Assisted Peer Review. arXiv:2507.06185 [cs.CY] https:\/\/arxiv.org\/abs\/2507.06185"},{"key":"e_1_3_2_1_51_1","volume-title":"The Twelfth international Conference on Learning Representations.","author":"Losch Max","unstructured":"Max Losch, Mohamed Omran, David Stutz, Mario Fritz, and Bernt Schiele, [n.d.]. On Adversarial Training without Perturbing all Examples. In The Twelfth international Conference on Learning Representations."},{"key":"e_1_3_2_1_52_1","unstructured":"Luminance. [n.d.]. Legal Grade AI. https:\/\/www.luminance.com\/"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.18653\/vl\/2023.findings-emnlp.381"},{"key":"e_1_3_2_1_54_1","unstructured":"Adam Makepeace and contributors. 2021. language-tool-python: A wrapper for LanguageTool. https:\/\/github.com\/languagetool-org\/language-tool-python."},{"key":"e_1_3_2_1_55_1","volume-title":"JunJie Cheah, T Ramayah, Francis Chuah, and Tat Huei Cham.","author":"Memon Muhammad Ali","year":"2020","unstructured":"Muhammad Ali Memon, Hui Nee Ting, JunJie Cheah, T Ramayah, Francis Chuah, and Tat Huei Cham. 2020. Sample Size for Survey Research: Review and Recommendations. Journal of Applied Structural Equation Modeling (2020)."},{"key":"e_1_3_2_1_56_1","unstructured":"Microsoft Corporation. [n.d.]. Policy Analyzer. Microsoft Security Compliance Toolkit 1.0. https:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=55319"},{"key":"e_1_3_2_1_57_1","volume-title":"Virtual adversarial training: a regularization method for supervised and semi-supervised learning","author":"Miyato Takeru","year":"2018","unstructured":"Takeru Miyato, Shin-ichi Maeda, Masanori Koyama, and Shin Ishii. 2018. Virtual adversarial training: a regularization method for supervised and semi-supervised learning. IEEE transactions on pattern analysis and machine intelligence 41, 8 (2018), 1979\u20131993."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.117"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.eacl-main.13"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.eacl-main.13"},{"key":"e_1_3_2_1_61_1","volume-title":"GLEU: Automatic Evaluation of Sentence-Level Fluency. In Proceedings of the 45th Annual Meeting of the Association of Computational Linguistics, Annie Zaenen and Antal van den Bosch (Eds.)","author":"Mutton Andrew","year":"2007","unstructured":"Andrew Mutton, Mark Dras, Stephen Wan, and Robert Dale. 2007. GLEU: Automatic Evaluation of Sentence-Level Fluency. In Proceedings of the 45th Annual Meeting of the Association of Computational Linguistics, Annie Zaenen and Antal van den Bosch (Eds.). Association for Computational Linguistics, Prague, Czech Republic, 344\u2013351. https:\/\/aclanthology.org\/P07-1044"},{"key":"e_1_3_2_1_62_1","volume-title":"Proceedings of the 29th ACM international conference on information & knowledge management. 3AA1-3AAA.","author":"Zaeem Razieh Nokhbeh","year":"2020","unstructured":"Razieh Nokhbeh Zaeem, Safa Anya, Alex Issa, Jake Nimergood, Isabelle Rogers, Vinay Shah, Ayush Srivastava, and K Suzanne Barber. 2020. PrivacyCheck v2: A tool that recaps privacy policies for you. In Proceedings of the 29th ACM international conference on information & knowledge management. 3AA1-3AAA."},{"key":"e_1_3_2_1_63_1","unstructured":"OpenAI. 2022. OpenAI GPT-3.5 Models. https:\/\/platform.openai.com\/docs\/models\/gpt-3-5"},{"key":"e_1_3_2_1_64_1","unstructured":"OpenAI. 2023. GPT-4 Technical Report. arXiv:2303.08774 [cs.CL]"},{"key":"e_1_3_2_1_65_1","unstructured":"OpenAI. 2025. GPT-5 mini Model Documentation. https:\/\/developers.openai.com\/api\/docs\/models\/gpt-5-mini. OpenAI API Documentation. Accessed: 2026-03-16."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"crossref","unstructured":"Kishore Papineni Salim Roukos Todd Ward and Wei-Jing Zhu. 2002. Bleu: a Method for Automatic Evaluation of Machine Translation. https:\/\/aclanthology.org\/P02-1040\/","DOI":"10.3115\/1073083.1073135"},{"key":"e_1_3_2_1_67_1","unstructured":"Peter S. Park Simon Goldstein Aidan O'Gara Michael Chen and Dan Hendrycks. 2024. AI deception: A survey of examples risks and potential solutions. (2024). https:\/\/www.sciencedirect.com\/science\/article\/pii\/S266638992400103X"},{"key":"e_1_3_2_1_68_1","volume-title":"Prolific: Crowdsourcing Academic Online Research","author":"Peer Eyal","year":"2024","unstructured":"Eyal Peer. 2024. Prolific: Crowdsourcing Academic Online Research. Cambridge University Press, 72\u201392."},{"key":"e_1_3_2_1_69_1","unstructured":"PolicyManager. [n.d.]. Web and cloud-based platform which allows you to easily manage the way you operate your credit insurance. https:\/\/www.aonpolicymanager.com\/"},{"key":"e_1_3_2_1_70_1","unstructured":"Politiwatch Inc. 2019. PrivacySpy. https:\/\/privacyspy.org\/"},{"key":"e_1_3_2_1_71_1","unstructured":"PrivacyHawk. [n. d.]. Eliminates risk of scams fraud and identity theft. https:\/\/www.privacyhawk.com\/"},{"key":"e_1_3_2_1_72_1","volume-title":"Lipton","author":"Pruthi Danish","year":"2019","unstructured":"Danish Pruthi, Bhuwan Dhingra, and Zachary C. Lipton. 2019. Combating Adversarial Misspellings with Robust Word Recognition. https:\/\/aclanthology.org\/P19-1561\/"},{"key":"e_1_3_2_1_73_1","unstructured":"QuestionPro. 2025. QuestionPro. https:\/\/www.questionpro.com\/us\/?"},{"key":"e_1_3_2_1_74_1","volume-title":"Language models are unsupervised multitask learners. OpenAI Blog 1, 8","author":"Radford Alec","year":"2019","unstructured":"Alec Radford, Jeffrey Wu, Rewon Child, David Luan, Dario Amodei, and Ilya Sutskever. 2019. Language models are unsupervised multitask learners. OpenAI Blog 1, 8 (2019). https:\/\/cdn.openai.com\/better-language-models\/language_models_are_unsupervised_multitask_learners.pdf"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-1079"},{"key":"e_1_3_2_1_76_1","unstructured":"Advije Rizvani Giovanni Apruzzese and Pavel Laskov. 2026. Adversarial News and Lost Profits: Manipulating Headlines in LLM-Driven Algorithmic Trading. arXiv:2601.13082 [cs.CR] https:\/\/arxiv.org\/abs\/2601.13082"},{"key":"e_1_3_2_1_77_1","unstructured":"Elias Abad Rocamora Yongtao Wu Fanghui Liu Grigorios G. Chrysos and Volkan Cevher. 2024. Revisiting Character-level Adversarial Attacks for Language Models. https:\/\/arxiv.org\/abs\/2405.04346"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","unstructured":"Thomas Roelleke and Jun Wang. 2008. TF-IDF uncovered: a study of theories and probabilities. https:\/\/doi.org\/10.1145\/1390334.1390409","DOI":"10.1145\/1390334.1390409"},{"key":"e_1_3_2_1_79_1","volume-title":"Robustness Verification for Transformers. In International Conference on Learning Representations.","author":"Shi Zhouxing","year":"2020","unstructured":"Zhouxing Shi, Huan Zhang, Kai-Wei Chang, Minlie Huang, and Cho-Jui Hsieh. 2020. Robustness Verification for Transformers. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"crossref","unstructured":"Chenglei Si Zhengyan Zhang Fanchao Qi Zhiyuan Liu Yasheng Wang Qun Liu and Maosong Sun. 2021. Better Robustness by More Coverage: Adversarial and Mixup Data Augmentation for Robust Finetuning. 1569\u20131576. https:\/\/aclanthology.org\/2021.findings-acl.137\/","DOI":"10.18653\/v1\/2021.findings-acl.137"},{"key":"e_1_3_2_1_81_1","unstructured":"Spellbook. 2025. Spellbook Reviews from Legal Teams. https:\/\/www.spellbook.legal\/reviews. Accessed: 2025-06-04."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.532"},{"key":"e_1_3_2_1_83_1","unstructured":"Streamline. [n. d.]. Generative AI for Lawyers: LLMs Use Cases & Ethics [Guide in 2025]. https:\/\/www.streamline.ai\/blog\/guide-to-generative-ai-and-llms-for-lawyers"},{"key":"e_1_3_2_1_84_1","unstructured":"Survicate. 2023. How to Determine Survey Sample Size: A Short Guide. https:\/\/survicate.com\/blog\/survey-sample-size\/."},{"key":"e_1_3_2_1_85_1","volume-title":"Policygpt: Automated analysis of privacy policies with large language models. arXiv preprint arXiv:2309.10238","author":"Tang Chenhao","year":"2023","unstructured":"Chenhao Tang, Zhengliang Liu, Chong Ma, Zihao Wu, Yiwei Li, Wei Liu, Dajiang Zhu, Quanzheng Li, Xiang Li, Tianming Liu, et al. 2023. Policygpt: Automated analysis of privacy policies with large language models. arXiv preprint arXiv:2309.10238 (2023)."},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0038"},{"key":"e_1_3_2_1_87_1","unstructured":"Yiyi Tao Yixian Shen Hang Zhang Yanxin Shen Lun Wang Chuanqi Shi and Shaoshuai Du. 2024. Robustness of Large Language Models Against Adversarial Attacks. https:\/\/arxiv.org\/abs\/2412.17011"},{"key":"e_1_3_2_1_88_1","unstructured":"Thomson Reuters. 2025. Generative AI for Legal Professionals: Top Use Cases. https:\/\/legal.thomsonreuters.com\/blog\/generative-ai-for-legal-professionals-top-use-cases\/"},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.804"},{"key":"e_1_3_2_1_90_1","volume-title":"Justice Meets Algorithms: The Rise of Gen AI in Law Firms","author":"Tsipursky Gleb","year":"2025","unstructured":"Gleb Tsipursky. 2025. Justice Meets Algorithms: The Rise of Gen AI in Law Firms. New York State Bar Association (2025). https:\/\/nysba.org\/justice-meets-algorithms-the-rise-of-gen-ai-in-law-firms\/"},{"key":"e_1_3_2_1_91_1","volume-title":"Proctor","author":"Vu Kim-Phuong L.","year":"2007","unstructured":"Kim-Phuong L. Vu, Vanessa Chambers, Fredrick P. Garcia, Beth Creekmur, John Sulaitis, Deborah Nelson, Russell Pierce, and Robert W. Proctor. 2007. How Users Read and Comprehend Privacy Policies. In Human Interface and the Management of Information. Interacting in Information Environments."},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.495"},{"key":"e_1_3_2_1_93_1","unstructured":"Boxin Wang Shuohang Wang Yu Cheng Zhe Gan Ruoxi Jia Bo Li and Jingjing Liu. [n.d.]. InfoBERT: Improving Robustness of Language Models from An Information Theoretic Perspective. In ICLR."},{"key":"e_1_3_2_1_94_1","unstructured":"Haoyu Wang Guozheng Ma Cong Yu Ning Gui Linrui Zhang Zhiqi Huang Suwei Ma Yongzhe Chang Sen Zhang Li Shen Xueqian Wang Peilin Zhao and Dacheng Tao. 2023. Are Large Language Models Really Robust to Word-Level Perturbations? https:\/\/arxiv.org\/abs\/2309.11166"},{"key":"e_1_3_2_1_95_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-55393-7_28"},{"key":"e_1_3_2_1_96_1","volume-title":"Denny Zhou, et al.","author":"Wei Jason","year":"2022","unstructured":"Jason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma, Fei Xia, Ed Chi, Quoc V Le, Denny Zhou, et al. 2022. Chain-of-thought prompting elicits reasoning in large language models. Advances in neural information processing systems 35 (2022), 24824\u201324837."},{"key":"e_1_3_2_1_97_1","unstructured":"Wikipedia contributors. 2024. In re Gateway Learning Corp. \u2014 Wikipedia The Free Encyclopedia. https:\/\/en.wikipedia.org\/wiki\/In_re_Gateway_Learning_Corp."},{"key":"e_1_3_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P16-1126"},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623067"},{"key":"e_1_3_2_1_100_1","unstructured":"Zhen Xiong Yujun Cai Bryan Hooi Nanyun Peng Zhecheng Li and Yiwei Wang. 2025. Enhancing LLM Character-Level Manipulation via Divide and Conquer. https:\/\/arxiv.org\/abs\/2502.08180"},{"key":"e_1_3_2_1_101_1","volume-title":"An LLM can Fool Itself: A Prompt-Based Adversarial Attack. arXiv preprint arXiv.2310.13345","author":"Xu Xilie","year":"2023","unstructured":"Xilie Xu, Keyi Kong, Ning Liu, Lizhen Cui, Di Wang, Jingfeng Zhang, and Mohan Kankanhalli. 2023. An LLM can Fool Itself: A Prompt-Based Adversarial Attack. arXiv preprint arXiv.2310.13345 (2023)."},{"key":"e_1_3_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.18653\/vl\/2024.naacl-long.360"},{"key":"e_1_3_2_1_103_1","volume-title":"A prompt-based approach to adversarial example generation and robustness enhancement. Frontiers of Computer Science","author":"Yang Yuting","year":"2024","unstructured":"Yuting Yang, Pei Huang, Juan Cao, Jintao Li, Yun Lin, and Feifei Ma. 2024. A prompt-based approach to adversarial example generation and robustness enhancement. Frontiers of Computer Science (2024)."},{"key":"e_1_3_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.317"},{"key":"e_1_3_2_1_105_1","doi-asserted-by":"publisher","unstructured":"Xiaoyan Yu Qilei Yin Zhixin Shi and Yuru Ma. 2022. Improving the Semantic Consistency of Textual Adversarial Attacks via Prompt. In 2022 International joint Conference on Neural Networks (IJCNN). doi:10.1109\/IJCNN55064.2022. 9892715","DOI":"10.1109\/IJCNN55064.2022"},{"key":"e_1_3_2_1_106_1","volume-title":"Bertscore: Evaluating text generation with bert. arXiv preprint arXiv","author":"Zhang Tianyi","year":"2019","unstructured":"Tianyi Zhang, Varsha Kishore, Felix Wu, Kilian Q Weinberger, and Yoav Artzi. 2019. Bertscore: Evaluating text generation with bert. arXiv preprint arXiv: 1904.09675 (2019)."},{"key":"e_1_3_2_1_107_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3374217","article-title":"Adversarial attacks on deep-learning models in natural language processing: A survey","volume":"11","author":"Zhang Wei Emma","year":"2020","unstructured":"Wei Emma Zhang, Quan Z Sheng, Ahoud Alhazmi, and Chenliang Li. 2020. Adversarial attacks on deep-learning models in natural language processing: A survey. ACM Transactions on Intelligent Systems and Technology (TIST) 11,3 (2020), 1\u201341.","journal-title":"ACM Transactions on Intelligent Systems and Technology (TIST)"},{"key":"e_1_3_2_1_108_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-1496"},{"key":"e_1_3_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.426"},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24100"}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3807480","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3807480","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:24:22Z","timestamp":1780586662000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3807480"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":110,"alternative-id":["10.1145\/3779208.3807480","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3807480","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}