{"id":"https://openalex.org/W4416252249","doi":"https://doi.org/10.1109/ijcnn64981.2025.11227624","title":"Weakening Prediction Confidence Makes Backdoors Strengthened: A Strong Textual Backdoor Attack on Prefix-tuning","display_name":"Weakening Prediction Confidence Makes Backdoors Strengthened: A Strong Textual Backdoor Attack on Prefix-tuning","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4416252249","doi":"https://doi.org/10.1109/ijcnn64981.2025.11227624"},"language":null,"primary_location":{"id":"doi:10.1109/ijcnn64981.2025.11227624","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11227624","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5035690502","display_name":"Yixin Tan","orcid":"https://orcid.org/0000-0001-6620-3562"},"institutions":[{"id":"https://openalex.org/I4210085920","display_name":"Shanghai Institute for Science of Science","ror":"https://ror.org/004srxn73","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210085920"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yixin Tan","raw_affiliation_strings":["Institute of Science,Tokyo"],"affiliations":[{"raw_affiliation_string":"Institute of Science,Tokyo","institution_ids":["https://openalex.org/I4210085920"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100425878","display_name":"Haoyu Zhang","orcid":"https://orcid.org/0000-0001-5070-7547"},"institutions":[{"id":"https://openalex.org/I4210160593","display_name":"Bridge Pharma (United States)","ror":"https://ror.org/05psz3234","country_code":"US","type":"company","lineage":["https://openalex.org/I4210160593"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Haoyu Zhang","raw_affiliation_strings":["Lan-Bridge Communications Ltd"],"affiliations":[{"raw_affiliation_string":"Lan-Bridge Communications Ltd","institution_ids":["https://openalex.org/I4210160593"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5063868203","display_name":"Jun Sakuma","orcid":null},"institutions":[{"id":"https://openalex.org/I4210126580","display_name":"RIKEN Center for Advanced Intelligence Project","ror":"https://ror.org/03ckxwf91","country_code":"JP","type":"facility","lineage":["https://openalex.org/I4210110652","https://openalex.org/I4210126580"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Jun Sakuma","raw_affiliation_strings":["RIKEN AIP &#x0026; Institute of Science,Tokyo"],"affiliations":[{"raw_affiliation_string":"RIKEN AIP &#x0026; Institute of Science,Tokyo","institution_ids":["https://openalex.org/I4210126580"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5035690502"],"corresponding_institution_ids":["https://openalex.org/I4210085920"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19520216,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.18330000340938568,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.18330000340938568,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12380","display_name":"Authorship Attribution and Profiling","score":0.1688999980688095,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.11249999701976776,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9904000163078308},{"id":"https://openalex.org/keywords/confidence-interval","display_name":"Confidence interval","score":0.5679000020027161},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.5543000102043152},{"id":"https://openalex.org/keywords/word","display_name":"Word (group theory)","score":0.46700000762939453},{"id":"https://openalex.org/keywords/selection","display_name":"Selection (genetic algorithm)","score":0.46230000257492065}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9904000163078308},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6740000247955322},{"id":"https://openalex.org/C44249647","wikidata":"https://www.wikidata.org/wiki/Q208498","display_name":"Confidence interval","level":2,"score":0.5679000020027161},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.5543000102043152},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.492000013589859},{"id":"https://openalex.org/C90805587","wikidata":"https://www.wikidata.org/wiki/Q10944557","display_name":"Word (group theory)","level":2,"score":0.46700000762939453},{"id":"https://openalex.org/C81917197","wikidata":"https://www.wikidata.org/wiki/Q628760","display_name":"Selection (genetic algorithm)","level":2,"score":0.46230000257492065},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3515999913215637},{"id":"https://openalex.org/C111335779","wikidata":"https://www.wikidata.org/wiki/Q3454686","display_name":"Reduction (mathematics)","level":2,"score":0.3456999957561493},{"id":"https://openalex.org/C141603448","wikidata":"https://www.wikidata.org/wiki/Q134830","display_name":"Prefix","level":2,"score":0.3077999949455261},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.303600013256073},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2815999984741211},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2678999900817871}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn64981.2025.11227624","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11227624","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":39,"referenced_works":["https://openalex.org/W1970409510","https://openalex.org/W2143017621","https://openalex.org/W2251939518","https://openalex.org/W2740168486","https://openalex.org/W2805744755","https://openalex.org/W2942091739","https://openalex.org/W2956090150","https://openalex.org/W2963323070","https://openalex.org/W2970641574","https://openalex.org/W2973217491","https://openalex.org/W3035367371","https://openalex.org/W3097595090","https://openalex.org/W3098267758","https://openalex.org/W3101449015","https://openalex.org/W3109409894","https://openalex.org/W3155431862","https://openalex.org/W3158487140","https://openalex.org/W3167002899","https://openalex.org/W3173777717","https://openalex.org/W3174770825","https://openalex.org/W3176270593","https://openalex.org/W3196832521","https://openalex.org/W3204619801","https://openalex.org/W3205191765","https://openalex.org/W3205696278","https://openalex.org/W3207360435","https://openalex.org/W3215670835","https://openalex.org/W4205991051","https://openalex.org/W4224903411","https://openalex.org/W4281902577","https://openalex.org/W4285247752","https://openalex.org/W4285603001","https://openalex.org/W4304099366","https://openalex.org/W4322760473","https://openalex.org/W4382246105","https://openalex.org/W4385570794","https://openalex.org/W4385572883","https://openalex.org/W4386187806","https://openalex.org/W4389519269"],"related_works":[],"abstract_inverted_index":{"Recent":[0],"research":[1],"on":[2,18,36,78,110,181,185],"textual":[3],"backdoor":[4,62,98,160],"attacks":[5],"(TBAs)":[6],"showed":[7],"that":[8,27,42,90],"backdoors":[9],"can":[10,172],"be":[11,173],"successfully":[12],"implanted":[13,174],"into":[14,177],"the":[15,51,57,60,74,79,93,96,101,133,158,169,178,189],"victim":[16],"model":[17],"full-parameter":[19],"fine-tuning.":[20],"In":[21,155],"this":[22,83,156],"paper,":[23],"we":[24,85],"empirically":[25],"show":[26],"existing":[28],"TBAs":[29],"cannot":[30],"achieve":[31],"high":[32],"attack":[33],"success":[34],"rates":[35],"prefix-tuning,":[37],"a":[38,44,87],"parameter-efficient":[39],"fine-tuning":[40],"paradigm":[41],"prepends":[43],"prefix":[45],"(i.e.,":[46],"deep":[47],"continuous":[48,179],"prompt)":[49],"to":[50,73,132,137,168],"input.":[52],"This":[53],"failure":[54],"is":[55],"because":[56],"invasion":[58],"of":[59,95,104,191],"inserted":[61,97,159],"and":[63,117],"general-purpose":[64],"learning":[65],"from":[66],"clean":[67],"samples":[68,127,163],"are":[69],"inherently":[70],"incompatible":[71],"due":[72],"limited":[75],"trainable":[76],"parameters":[77],"prefix.":[80],"To":[81],"address":[82],"problem,":[84],"propose":[86],"novel":[88],"TBA":[89],"indirectly":[91],"improves":[92],"effects":[94],"by":[99,148],"weakening":[100],"prediction":[102,118,130,146,166],"confidence":[103,119,131,147,167],"its":[105],"specially":[106],"embedded":[107],"sample":[108,114],"based":[109],"two":[111],"strategies:":[112],"susceptible":[113,126],"selection":[115],"(S3)":[116],"reduction":[120],"(PCR).":[121],"Specifically,":[122],"S3":[123],"consciously":[124],"selects":[125],"with":[128,164],"low":[129,165],"target":[134,170],"label":[135,171],"according":[136],"their":[138,145],"text":[139],"lengths.":[140],"Besides,":[141],"PCR":[142],"further":[143],"weakens":[144],"an":[149],"iterative":[150],"mask-and-infill":[151],"word":[152],"replacing":[153],"process.":[154],"way,":[157],"triggers":[161],"in":[162],"more":[175],"effectively":[176],"prompts":[180],"prefix-tuning.":[182],"Experiment":[183],"results":[184],"four":[186],"benchmarks":[187],"validate":[188],"superiority":[190],"our":[192],"proposed":[193],"method":[194],"<sup":[195],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[196],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>.":[197]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-14T00:00:00"}
