{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:00:38Z","timestamp":1781283638058,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":59,"publisher":"ACM","funder":[{"name":"United Arab Emirates","award":["12R316"],"award-info":[{"award-number":["12R316"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"DOI":"10.1145\/3806007.3810962","type":"proceedings-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:29:17Z","timestamp":1781281757000},"page":"51-58","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Measuring the Security of LLM Applications: A Taxonomy and Empirical Evaluation of Attacks and Defense Tools"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7215-1666","authenticated-orcid":false,"given":"Aymen Dia Eddine","family":"Berini","sequence":"first","affiliation":[{"name":"UAE University, Alain, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7363-1466","authenticated-orcid":false,"given":"Norziana","family":"Jamil","sequence":"additional","affiliation":[{"name":"UAE University, Alain, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4725-8634","authenticated-orcid":false,"given":"Abderrahmane","family":"Lakas","sequence":"additional","affiliation":[{"name":"UAE University, Alain, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5197-8437","authenticated-orcid":false,"given":"Leila","family":"Ismail","sequence":"additional","affiliation":[{"name":"UAE University, Alain, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0632-3172","authenticated-orcid":false,"given":"Mohamed Amine","family":"Ferrag","sequence":"additional","affiliation":[{"name":"UAE University, Alain, United Arab Emirates"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7479-7970","authenticated-orcid":false,"given":"Kwok-Yan","family":"Lam","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"2024 IEEE Symposium on Security and Privacy (SP). IEEE, 1122-1140","author":"Aghakhani Hojjat","year":"2024","unstructured":"Hojjat Aghakhani, Wei Dai, Andre Manoel, Xavier Fernandes, Anant Kharkar, Christopher Kruegel, Giovanni Vigna, David Evans, Ben Zorn, and Robert Sim. 2024. Trojanpuzzle: Covertly poisoning code-suggestion models. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE, 1122-1140."},{"key":"e_1_3_2_1_2_1","unstructured":"Wenqian Cai et al. 2023. BadPrompt: Backdoor Attacks in Continuous Prompts. arXiv preprint arXiv:2302.12173 (2023)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML64287.2025.00010"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.52202\/079017-4136"},{"key":"e_1_3_2_1_6_1","volume-title":"Masterkey: Automated jailbreak across multiple large language model chatbots. arXiv preprint arXiv:2307.08715","author":"Deng Gelei","year":"2023","unstructured":"Gelei Deng, Yi Liu, Yuekang Li, Kailong Wang, Ying Zhang, Zefeng Li, Haoyu Wang, Tianwei Zhang, and Yang Liu. 2023. Masterkey: Automated jailbreak across multiple large language model chatbots. arXiv preprint arXiv:2307.08715 (2023)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671470"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_9_1","volume-title":"Denial-of-Service Poisoning Attacks on Large Language Models. arXiv preprint arXiv:2410.10760","author":"Gao Kuofeng","year":"2024","unstructured":"Kuofeng Gao, Tianyu Pang, Chao Du, Yong Yang, Shu-Tao Xia, and Min Lin. 2024. Denial-of-Service Poisoning Attacks on Large Language Models. arXiv preprint arXiv:2410.10760 (2024)."},{"key":"e_1_3_2_1_10_1","first-page":"16937","article-title":"Inverting gradients-How easy is it to break privacy in federated learning?","volume":"33","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting gradients-How easy is it to break privacy in federated learning?. In Advances in Neural Information Processing Systems, Vol. 33. 16937-16947.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_11_1","volume-title":"Scaling Responsible Generative AI: Automating Red Teaming of LLM Applications. In 2025 IEEE Conference on Artificial Intelligence (CAI). IEEE, 902-905","author":"Goh Adison","year":"2025","unstructured":"Adison Goh, Benjamin Chee, Matteo Vagnoli, Luca Baldassarre, and Akshay Narayan. 2025. Scaling Responsible Generative AI: Automating Red Teaming of LLM Applications. In 2025 IEEE Conference on Artificial Intelligence (CAI). IEEE, 902-905."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623175"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583348"},{"key":"e_1_3_2_1_15_1","first-page":"611","volume-title":"Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society","volume":"7","author":"Iqbal Umar","year":"2024","unstructured":"Umar Iqbal, Tadayoshi Kohno, and Franziska Roesner. 2024. Llm platform security: applying a systematic evaluation framework to openai's chatgpt plugins. In Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society, Vol. 7. 611-623."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW63631.2024.00018"},{"key":"e_1_3_2_1_17_1","volume-title":"Multi-step jailbreaking privacy attacks on chatgpt. arXiv preprint arXiv:2304.05197","author":"Li Haoran","year":"2023","unstructured":"Haoran Li, Dadi Guo, Wei Fan, Mingshi Xu, Jie Huang, Fanpu Meng, and Yangqiu Song. 2023a. Multi-step jailbreaking privacy attacks on chatgpt. arXiv preprint arXiv:2304.05197 (2023)."},{"key":"e_1_3_2_1_18_1","volume-title":"Chatgpt as an attack tool: Stealthy textual backdoor attack via blackbox generative model trigger. arXiv preprint arXiv:2304.14475","author":"Li Jiazhao","year":"2023","unstructured":"Jiazhao Li, Yijin Yang, Zhuofeng Wu, VG Vydiswaran, and Chaowei Xiao. 2023b. Chatgpt as an attack tool: Stealthy textual backdoor attack via blackbox generative model trigger. arXiv preprint arXiv:2304.14475 (2023)."},{"key":"e_1_3_2_1_19_1","volume-title":"Backdoorllm: A comprehensive benchmark for backdoor attacks on large language models. arXiv preprint arXiv:2408.12798","author":"Li Yige","year":"2024","unstructured":"Yige Li, Hanxun Huang, Yunhan Zhao, Xingjun Ma, and Jun Sun. 2024a. Backdoorllm: A comprehensive benchmark for backdoor attacks on large language models. arXiv preprint arXiv:2408.12798 (2024)."},{"key":"e_1_3_2_1_20_1","volume-title":"Badedit: Backdooring large language models by model editing. arXiv preprint arXiv:2403.13355","author":"Li Yanzhou","year":"2024","unstructured":"Yanzhou Li, Tianlin Li, Kangjie Chen, Jian Zhang, Shangqing Liu, Wenhan Wang, Tianwei Zhang, and Yang Liu. 2024b. Badedit: Backdooring large language models by model editing. arXiv preprint arXiv:2403.13355 (2024)."},{"key":"e_1_3_2_1_21_1","first-page":"4711","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu Tong","year":"2024","unstructured":"Tong Liu, Yingjie Zhang, Zhe Zhao, Yinpeng Dong, Guozhu Meng, and Kai Chen. 2024c. Making them ask and answer: Jailbreaking large language models in few queries via disguise and reconstruction. In 33rd USENIX Security Symposium (USENIX Security 24). 4711-4728."},{"key":"e_1_3_2_1_22_1","volume-title":"Autodan: Generating stealthy jailbreak prompts on aligned large language models. arXiv preprint arXiv:2310.04451","author":"Liu Xiaogeng","year":"2023","unstructured":"Xiaogeng Liu, Nan Xu, Muhao Chen, and Chaowei Xiao. 2023b. Autodan: Generating stealthy jailbreak prompts on aligned large language models. arXiv preprint arXiv:2310.04451 (2023)."},{"key":"e_1_3_2_1_23_1","volume-title":"Automatic and universal prompt injection attacks against large language models. arXiv preprint arXiv:2403.04957","author":"Liu Xiaogeng","year":"2024","unstructured":"Xiaogeng Liu, Zhiyuan Yu, Yizhe Zhang, Ning Zhang, and Chaowei Xiao. 2024b. Automatic and universal prompt injection attacks against large language models. arXiv preprint arXiv:2403.04957 (2024)."},{"key":"e_1_3_2_1_24_1","unstructured":"Yi Liu Gelei Deng Yuekang Li Kailong Wang Zihao Wang Xiaofeng Wang Tianwei Zhang Yepang Liu Haoyu Wang Yan Zheng et al. 2023a. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:2306.05499 (2023)."},{"key":"e_1_3_2_1_25_1","volume-title":"Flipattack: Jailbreak llms via flipping. arXiv preprint arXiv:2410.02832","author":"Liu Yue","year":"2024","unstructured":"Yue Liu, Xiaoxin He, Miao Xiong, Jinlan Fu, Shumin Deng, and Bryan Hooi. 2024a. Flipattack: Jailbreak llms via flipping. arXiv preprint arXiv:2410.02832 (2024)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC61394.2024.10718747"},{"key":"e_1_3_2_1_27_1","first-page":"1","article-title":"Exploiting machine learning to subvert your spam filter","volume":"8","author":"Nelson Blaine","year":"2008","unstructured":"Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles Sutton, J Doug Tygar, and Kai Xia. 2008. Exploiting machine learning to subvert your spam filter. LEET, Vol. 8, 1-9 (2008), 16-17.","journal-title":"LEET"},{"key":"e_1_3_2_1_28_1","volume-title":"Nathaniel D Bastian, Wenbo Guo, and Dawn Song.","author":"Nie Yuzhou","year":"2024","unstructured":"Yuzhou Nie, Yanting Wang, Jinyuan Jia, Michael J De Lucia, Nathaniel D Bastian, Wenbo Guo, and Dawn Song. 2024. TrojFM: Resource-efficient backdoor attacks against very large foundation models. arXiv preprint arXiv:2405.16783 (2024)."},{"key":"e_1_3_2_1_29_1","unstructured":"owasap. 2023. OWASP Top 10 for Large Language Model Applications. https:\/\/owasp.org\/www-project-top-10-for-large-language-modelapplications\/. Accessed: 2025-09-30."},{"key":"e_1_3_2_1_30_1","volume-title":"OWASP Top 10 for LLM Applications","year":"2025","unstructured":"Owasp. 2025. OWASP Top 10 for LLM Applications 2025. https:\/\/genai.owasp.org\/resource\/owasp-top-10-for-llm-applications-2025\/. Accessed: 2025-09-30."},{"key":"e_1_3_2_1_31_1","volume-title":"Are you copying my model? protecting the copyright of large language models for eaas via backdoor watermark. arXiv preprint arXiv:2305.10036","author":"Peng Wenjun","year":"2023","unstructured":"Wenjun Peng, Jingwei Yi, Fangzhao Wu, Shangxi Wu, Bin Zhu, Lingjuan Lyu, Binxing Jiao, Tong Xu, Guangzhong Sun, and Xing Xie. 2023. Are you copying my model? protecting the copyright of large language models for eaas via backdoor watermark. arXiv preprint arXiv:2305.10036 (2023)."},{"key":"e_1_3_2_1_32_1","volume-title":"Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527","author":"Perez F\u00e1bio","year":"2022","unstructured":"F\u00e1bio Perez and Ian Ribeiro. 2022. Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527 (2022)."},{"key":"e_1_3_2_1_33_1","volume-title":"Tricking llms into disobedience: Formalizing, analyzing, and detecting jailbreaks. arXiv preprint arXiv:2305.14965","author":"Rao Abhinav","year":"2023","unstructured":"Abhinav Rao, Sachin Vashistha, Atharva Naik, Somak Aditya, and Monojit Choudhury. 2023. Tricking llms into disobedience: Formalizing, analyzing, and detecting jailbreaks. arXiv preprint arXiv:2305.14965 (2023)."},{"key":"e_1_3_2_1_34_1","unstructured":"Siladitya Ray. 2023. Samsung bans chatgpt among employees after sensitive code leak. https:\/\/www.forbes.com\/sites\/siladityaray\/2023\/05\/02\/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak. Accessed: 2025-11-05."},{"key":"e_1_3_2_1_35_1","unstructured":"Schiffer. 2023. Amazon's Q has ''severe hallucinations'' and leaks confidential data in public preview employees warn. https:\/\/www.platformer.news\/amazons-q-has-severe-hallucinations\/. Accessed: 2025-11-05."},{"key":"e_1_3_2_1_36_1","first-page":"1559","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Schuster Roei","year":"2021","unstructured":"Roei Schuster, Congzheng Song, Eran Tromer, and Vitaly Shmatikov. 2021. You autocomplete me: Poisoning vulnerabilities in neural code completion. In 30th USENIX Security Symposium (USENIX Security 21). 1559-1575."},{"key":"e_1_3_2_1_37_1","volume-title":"2024 IEEE Symposium on Security and Privacy (SP). IEEE, 807-825","author":"Shan Shawn","year":"2024","unstructured":"Shawn Shan, Wenxin Ding, Josephine Passananti, Stanley Wu, Haitao Zheng, and Ben Y Zhao. 2024. Nightshade: Prompt-specific poisoning attacks on text-to-image generative models. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE, 807-825."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670388"},{"key":"e_1_3_2_1_39_1","volume-title":"Badgpt: Exploring security vulnerabilities of chatgpt via backdoor attacks to instructgpt. arXiv preprint arXiv:2304.12298","author":"Shi Jiawen","year":"2023","unstructured":"Jiawen Shi, Yixin Liu, Pan Zhou, and Lichao Sun. 2023. Badgpt: Exploring security vulnerabilities of chatgpt via backdoor attacks to instructgpt. arXiv preprint arXiv:2304.12298 (2023)."},{"key":"e_1_3_2_1_40_1","first-page":"61836","article-title":"On the exploitability of instruction tuning","volume":"36","author":"Shu Manli","year":"2023","unstructured":"Manli Shu, Jiongxiao Wang, Chen Zhu, Jonas Geiping, Chaowei Xiao, and Tom Goldstein. 2023. On the exploitability of instruction tuning. Advances in Neural Information Processing Systems, Vol. 36 (2023), 61836-61856.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00024"},{"key":"e_1_3_2_1_42_1","volume-title":"Mondrian: Prompt abstraction attack against large language models for cheaper api pricing. arXiv preprint arXiv:2308.03558","author":"Si Wai Man","year":"2023","unstructured":"Wai Man Si, Michael Backes, and Yang Zhang. 2023. Mondrian: Prompt abstraction attack against large language models for cheaper api pricing. arXiv preprint arXiv:2308.03558 (2023)."},{"key":"e_1_3_2_1_43_1","volume-title":"25th USENIX security symposium (USENIX Security 16). 601-618.","author":"Tram\u00e8r Florian","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction . In 25th USENIX security symposium (USENIX Security 16). 601-618."},{"key":"e_1_3_2_1_44_1","volume-title":"Imitation attacks and defenses for black-box machine translation systems. arXiv preprint arXiv:2004.15015","author":"Wallace Eric","year":"2020","unstructured":"Eric Wallace, Mitchell Stern, and Dawn Song. 2020. Imitation attacks and defenses for black-box machine translation systems. arXiv preprint arXiv:2004.15015 (2020)."},{"key":"e_1_3_2_1_45_1","volume-title":"International Conference on Machine Learning. PMLR, 35413-35425","author":"Wan Alexander","year":"2023","unstructured":"Alexander Wan, Eric Wallace, Sheng Shen, and Dan Klein. 2023. Poisoning language models during instruction tuning. In International Conference on Machine Learning. PMLR, 35413-35425."},{"key":"e_1_3_2_1_46_1","volume-title":"Zhuojun Jiang, Zhaoheng Zheng, Zhuofeng Wu, Muhao Chen, and Chaowei Xiao.","author":"Wang Jiongxiao","year":"2023","unstructured":"Jiongxiao Wang, Zichen Liu, Keun Hee Park, Zhuojun Jiang, Zhaoheng Zheng, Zhuofeng Wu, Muhao Chen, and Chaowei Xiao. 2023. Adversarial demonstration attacks on large language models. arXiv preprint arXiv:2305.14950 (2023)."},{"key":"e_1_3_2_1_47_1","unstructured":"Shenao Wang Yanjie Zhao Zhao Liu Quanchen Zou and Haoyu Wang. 2025. SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain. arXiv:2502.12497 [cs.CR] https:\/\/arxiv.org\/abs\/2502.12497"},{"key":"e_1_3_2_1_48_1","volume-title":"Badagent: Inserting and activating backdoor attacks in llm agents. arXiv preprint arXiv:2406.03007","author":"Wang Yifei","year":"2024","unstructured":"Yifei Wang, Dizhan Xue, Shengjie Zhang, and Shengsheng Qian. 2024. Badagent: Inserting and activating backdoor attacks in llm agents. arXiv preprint arXiv:2406.03007 (2024)."},{"key":"e_1_3_2_1_49_1","volume-title":"A Survey of Attacks on Large Language Models. arXiv (Jan","author":"Xu W","year":"2025","unstructured":"W Xu and KK Parhi. 2025. A Survey of Attacks on Large Language Models. arXiv (Jan. 2025). https:\/\/arxiv.org\/abs\/2505.12567"},{"key":"e_1_3_2_1_50_1","volume-title":"Shadowcast: Stealthy data poisoning attacks against vision-language models. arXiv preprint arXiv:2402.06659","author":"Xu Yuancheng","year":"2024","unstructured":"Yuancheng Xu, Jiarui Yao, Manli Shu, Yanchao Sun, Zichu Wu, Ning Yu, Tom Goldstein, and Furong Huang. 2024. Shadowcast: Stealthy data poisoning attacks against vision-language models. arXiv preprint arXiv:2402.06659 (2024)."},{"key":"e_1_3_2_1_51_1","volume-title":"On protecting the data privacy of large language models (llms): A survey. arXiv preprint arXiv:2403.05156","author":"Yan Biwei","year":"2024","unstructured":"Biwei Yan, Kun Li, Minghui Xu, Yueyan Dong, Yue Zhang, Zhaochun Ren, and Xiuzhen Cheng. 2024a. On protecting the data privacy of large language models (llms): A survey. arXiv preprint arXiv:2403.05156 (2024)."},{"key":"e_1_3_2_1_52_1","first-page":"1795","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Yan Shenao","year":"2024","unstructured":"Shenao Yan, Shen Wang, Yue Duan, Hanbin Hong, Kiho Lee, Doowon Kim, and Yuan Hong. 2024b. An Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection. In 33rd USENIX Security Symposium (USENIX Security 24). 1795-1812."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2024.3361661"},{"key":"e_1_3_2_1_54_1","volume-title":"Large language models are better adversaries: Exploring generative clean-label backdoor attacks against text classifiers. arXiv preprint arXiv:2310.18603","author":"You Wencong","year":"2023","unstructured":"Wencong You, Zayd Hammoudeh, and Daniel Lowd. 2023. Large language models are better adversaries: Exploring generative clean-label backdoor attacks against text classifiers. arXiv preprint arXiv:2310.18603 (2023)."},{"key":"e_1_3_2_1_55_1","volume-title":"Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts. arXiv preprint arXiv:2309.10253","author":"Yu Jiahao","year":"2023","unstructured":"Jiahao Yu, Xingwei Lin, Zheng Yu, and Xinyu Xing. 2023. Gptfuzzer: Red teaming large language models with auto-generated jailbreak prompts. arXiv preprint arXiv:2309.10253 (2023)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"},{"key":"e_1_3_2_1_57_1","volume-title":"Junbo Zhao, and Jie Fu.","author":"Zhao Shuai","year":"2023","unstructured":"Shuai Zhao, Jinming Wen, Luu Anh Tuan, Junbo Zhao, and Jie Fu. 2023. Prompt as triggers for backdoor attack: Examining the vulnerability in language models. arXiv preprint arXiv:2305.01219 (2023)."},{"key":"e_1_3_2_1_58_1","volume-title":"Retrieval augmented generation (rag) and beyond: A comprehensive survey on how to make your llms use external data more wisely. arXiv preprint arXiv:2409.14924","author":"Zhao Siyun","year":"2024","unstructured":"Siyun Zhao, Yuqing Yang, Zilong Wang, Zhiyuan He, Luna K Qiu, and Lili Qiu. 2024. Retrieval augmented generation (rag) and beyond: A comprehensive survey on how to make your llms use external data more wisely. arXiv preprint arXiv:2409.14924 (2024)."},{"key":"e_1_3_2_1_59_1","volume-title":"Advances in Neural Information Processing Systems","volume":"32","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. In Advances in Neural Information Processing Systems, Vol. 32."}],"event":{"name":"CODASPY '26: Sixteenth ACM Conference on Data and Application Security and Privacy","location":"Frankfurt am Main Germany","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 12th ACM International Workshop on Security and Privacy Analytics"],"original-title":[],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T16:30:20Z","timestamp":1781281820000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3806007.3810962"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":59,"alternative-id":["10.1145\/3806007.3810962","10.1145\/3806007"],"URL":"https:\/\/doi.org\/10.1145\/3806007.3810962","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}