{"id":"https://openalex.org/W4288057740","doi":"https://doi.org/10.1109/sp46214.2022.9833579","title":"Piccolo: Exposing Complex Backdoors in NLP Transformer Models","display_name":"Piccolo: Exposing Complex Backdoors in NLP Transformer Models","publication_year":2022,"publication_date":"2022-05-01","ids":{"openalex":"https://openalex.org/W4288057740","doi":"https://doi.org/10.1109/sp46214.2022.9833579"},"language":"en","primary_location":{"id":"doi:10.1109/sp46214.2022.9833579","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833579","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5080886129","display_name":"Yingqi Liu","orcid":"https://orcid.org/0000-0002-8312-0088"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yingqi Liu","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114076473","display_name":"Guangyu Shen","orcid":"https://orcid.org/0009-0003-0701-1124"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guangyu Shen","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014842586","display_name":"Guanhong Tao","orcid":"https://orcid.org/0000-0002-4701-1327"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guanhong Tao","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030118506","display_name":"Shengwei An","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shengwei An","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101594068","display_name":"Shiqing Ma","orcid":"https://orcid.org/0000-0003-1551-8948"},"institutions":[{"id":"https://openalex.org/I4210096112","display_name":"Rutgers Sexual and Reproductive Health and Rights","ror":"https://ror.org/00rcvgx40","country_code":"NL","type":"other","lineage":["https://openalex.org/I4210096112"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Shiqing Ma","raw_affiliation_strings":["Rutgers University"],"affiliations":[{"raw_affiliation_string":"Rutgers University","institution_ids":["https://openalex.org/I4210096112"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100362465","display_name":"Xiangyu Zhang","orcid":"https://orcid.org/0000-0003-2138-4608"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiangyu Zhang","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5080886129"],"corresponding_institution_ids":["https://openalex.org/I219193219"],"apc_list":null,"apc_paid":null,"fwci":4.7813,"has_fulltext":false,"cited_by_count":46,"citation_normalized_percentile":{"value":0.96213101,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"2025","last_page":"2042"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9965000152587891,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9887999892234802,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9843999743461609,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.842066764831543},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8403134942054749},{"id":"https://openalex.org/keywords/discriminative-model","display_name":"Discriminative model","score":0.6842576265335083},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6317804455757141},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.500016450881958},{"id":"https://openalex.org/keywords/word","display_name":"Word (group theory)","score":0.4981093406677246},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.46542876958847046},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.4539378583431244},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.38829678297042847},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.34234562516212463}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.842066764831543},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8403134942054749},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.6842576265335083},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6317804455757141},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.500016450881958},{"id":"https://openalex.org/C90805587","wikidata":"https://www.wikidata.org/wiki/Q10944557","display_name":"Word (group theory)","level":2,"score":0.4981093406677246},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.46542876958847046},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.4539378583431244},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.38829678297042847},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34234562516212463},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C165801399","wikidata":"https://www.wikidata.org/wiki/Q25428","display_name":"Voltage","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46214.2022.9833579","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46214.2022.9833579","pdf_url":null,"source":{"id":"https://openalex.org/S4363606603","display_name":"2022 IEEE Symposium on Security and Privacy (SP)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Reduced inequalities","score":0.7200000286102295,"id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":146,"referenced_works":["https://openalex.org/W1828163288","https://openalex.org/W1968411139","https://openalex.org/W2022204871","https://openalex.org/W2088911157","https://openalex.org/W2113459411","https://openalex.org/W2170240176","https://openalex.org/W2251939518","https://openalex.org/W2296420526","https://openalex.org/W2547875792","https://openalex.org/W2753783305","https://openalex.org/W2774423163","https://openalex.org/W2793931959","https://openalex.org/W2805779034","https://openalex.org/W2807363941","https://openalex.org/W2810065831","https://openalex.org/W2888940765","https://openalex.org/W2896457183","https://openalex.org/W2898759955","https://openalex.org/W2899771611","https://openalex.org/W2916360674","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2947133760","https://openalex.org/W2949128310","https://openalex.org/W2952087486","https://openalex.org/W2962718684","https://openalex.org/W2962763344","https://openalex.org/W2962818281","https://openalex.org/W2962977603","https://openalex.org/W2963618920","https://openalex.org/W2963859254","https://openalex.org/W2965373594","https://openalex.org/W2965527544","https://openalex.org/W2966187620","https://openalex.org/W2966689772","https://openalex.org/W2970085549","https://openalex.org/W2971196067","https://openalex.org/W2973217491","https://openalex.org/W2978017171","https://openalex.org/W2982756474","https://openalex.org/W2982977353","https://openalex.org/W2985913519","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W2995164118","https://openalex.org/W2996458309","https://openalex.org/W2996800219","https://openalex.org/W2996851481","https://openalex.org/W3007437825","https://openalex.org/W3008901592","https://openalex.org/W3015678314","https://openalex.org/W3034258347","https://openalex.org/W3034414373","https://openalex.org/W3034457371","https://openalex.org/W3035367371","https://openalex.org/W3038046627","https://openalex.org/W3046795215","https://openalex.org/W3048715803","https://openalex.org/W3087391814","https://openalex.org/W3092005433","https://openalex.org/W3096024872","https://openalex.org/W3101449015","https://openalex.org/W3104423855","https://openalex.org/W3106047871","https://openalex.org/W3106646114","https://openalex.org/W3107337211","https://openalex.org/W3108535146","https://openalex.org/W3109409894","https://openalex.org/W3114686421","https://openalex.org/W3121478722","https://openalex.org/W3158360872","https://openalex.org/W3158487140","https://openalex.org/W3167334189","https://openalex.org/W3170465383","https://openalex.org/W3172767235","https://openalex.org/W3175052694","https://openalex.org/W3176270593","https://openalex.org/W3190013336","https://openalex.org/W3190075653","https://openalex.org/W3192036897","https://openalex.org/W3207360435","https://openalex.org/W3210951978","https://openalex.org/W3212213895","https://openalex.org/W3213508244","https://openalex.org/W4252979261","https://openalex.org/W4287281082","https://openalex.org/W4288093767","https://openalex.org/W4288094728","https://openalex.org/W4289300166","https://openalex.org/W4289549047","https://openalex.org/W4294679663","https://openalex.org/W4298140072","https://openalex.org/W4385245566","https://openalex.org/W4385727936","https://openalex.org/W6638749077","https://openalex.org/W6676984168","https://openalex.org/W6685053522","https://openalex.org/W6691459498","https://openalex.org/W6729448088","https://openalex.org/W6739901393","https://openalex.org/W6746897123","https://openalex.org/W6749755156","https://openalex.org/W6749794497","https://openalex.org/W6750462152","https://openalex.org/W6752600739","https://openalex.org/W6754279747","https://openalex.org/W6755207826","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6759424558","https://openalex.org/W6761076018","https://openalex.org/W6764288440","https://openalex.org/W6766253520","https://openalex.org/W6766336336","https://openalex.org/W6766401332","https://openalex.org/W6766673545","https://openalex.org/W6767183785","https://openalex.org/W6767184030","https://openalex.org/W6768851824","https://openalex.org/W6769209188","https://openalex.org/W6770046844","https://openalex.org/W6770634426","https://openalex.org/W6771533808","https://openalex.org/W6774126473","https://openalex.org/W6774271729","https://openalex.org/W6774277700","https://openalex.org/W6774904085","https://openalex.org/W6775678023","https://openalex.org/W6775918922","https://openalex.org/W6779690972","https://openalex.org/W6779739866","https://openalex.org/W6779945703","https://openalex.org/W6779989257","https://openalex.org/W6780640148","https://openalex.org/W6781450928","https://openalex.org/W6781614194","https://openalex.org/W6781637792","https://openalex.org/W6782308813","https://openalex.org/W6784216616","https://openalex.org/W6786651539","https://openalex.org/W6787626716","https://openalex.org/W6788876066","https://openalex.org/W6789730115","https://openalex.org/W6791576469","https://openalex.org/W6794593925","https://openalex.org/W6797364105"],"related_works":["https://openalex.org/W2395910192","https://openalex.org/W2112752961","https://openalex.org/W2113687551","https://openalex.org/W4288365749","https://openalex.org/W2936497627","https://openalex.org/W3013624417","https://openalex.org/W4287826556","https://openalex.org/W3098382480","https://openalex.org/W4287598411","https://openalex.org/W3100913109"],"abstract_inverted_index":{"Backdoors":[0],"can":[1],"be":[2],"injected":[3],"to":[4,98,108,127,199],"NLP":[5,46,147,213],"models":[6,80,148],"such":[7,23,48,68,161],"that":[8,177],"they":[9],"misbehave":[10],"when":[11,77],"the":[12,42,50,55,118,130,137,150,209],"trigger":[13,141],"words":[14,113],"or":[15],"sentences":[16],"appear":[17],"in":[18,117,188,205],"an":[19,99],"input":[20],"sample.":[21],"Detecting":[22],"backdoors":[24,64],"given":[25],"only":[26],"a":[27,31,88,95,110,122],"subject":[28,96,131],"model":[29,97,132],"and":[30,54,79,153,164,166,191],"small":[32],"number":[33],"of":[34,41,45,52,112,139,208],"benign":[35],"samples":[36],"is":[37,133,180],"very":[38],"challenging":[39],"because":[40],"unique":[43],"nature":[44],"applications,":[47],"as":[49,69,162],"discontinuity":[51],"pipeline":[53],"large":[56],"search":[57],"space.":[58],"Existing":[59],"techniques":[60],"work":[61],"well":[62],"for":[63,136,212],"with":[65,156],"simple":[66],"triggers":[67,72,78],"single":[70],"character/word":[71],"but":[73,101],"become":[74,81],"less":[75],"effective":[76],"complex":[82,159],"(e.g.,":[83],"transformer":[84],"models).":[85],"We":[86],"propose":[87],"new":[89],"backdoor":[90,214],"scanning":[91],"technique.":[92],"It":[93,104,120],"transforms":[94],"equivalent":[100],"differentiable":[102],"form.":[103],"then":[105],"uses":[106],"optimization":[107],"invert":[109],"distribution":[111],"denoting":[114],"their":[115],"likelihood":[116],"trigger.":[119],"leverages":[121],"novel":[123],"word":[124],"discriminativity":[125],"analysis":[126],"determine":[128],"if":[129],"particularly":[134],"discriminative":[135],"presence":[138],"likely":[140],"words.":[142],"Our":[143,197],"evaluation":[144],"on":[145],"3839":[146],"from":[149],"TrojAI":[151,200],"competition":[152],"existing":[154],"works":[155],"7":[157],"state-of-art":[158],"structures":[160],"BERT":[163],"GPT,":[165],"17":[167],"different":[168],"attack":[169],"types":[170],"including":[171],"two":[172,194],"latest":[173],"dynamic":[174],"attacks,":[175],"shows":[176],"our":[178],"technique":[179],"highly":[181],"effective,":[182],"achieving":[183],"over":[184],"0.9":[185],"detection":[186],"accuracy":[187],"most":[189],"scenarios":[190],"substantially":[192],"outperforming":[193],"state-of-the-art":[195],"scanners.":[196],"submissions":[198],"leaderboard":[201],"achieve":[202],"top":[203],"performance":[204],"2":[206],"out":[207],"3":[210],"rounds":[211],"scanning.":[215]},"counts_by_year":[{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":16},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
