{"id":"https://openalex.org/W7161852430","doi":"https://doi.org/10.48550/arxiv.2605.19478","title":"Exposing Functional Fusion: A New Class of Strategic Backdoor in Dynamic Prompt Architectures","display_name":"Exposing Functional Fusion: A New Class of Strategic Backdoor in Dynamic Prompt Architectures","publication_year":2026,"publication_date":"2026-05-19","ids":{"openalex":"https://openalex.org/W7161852430","doi":"https://doi.org/10.48550/arxiv.2605.19478"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.19478","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.19478","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.19478","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5136530062","display_name":"Zeyao Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Zeyao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136609583","display_name":"Zhendong Zhao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhao, Zhendong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136518312","display_name":"Xiaojun Chen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Xiaojun","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5136593668","display_name":"Xin Zhao","orcid":"https://orcid.org/0000-0002-2337-3200"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhao, Xin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074107460","display_name":"Yuexin Xuan","orcid":"https://orcid.org/0000-0001-7887-2309"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xuan, Yuexin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5101632365","display_name":"Xiaobin Ji","orcid":"https://orcid.org/0000-0002-1067-0812"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ji, Xiaoshuang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.6814000010490417,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.6814000010490417,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.1517000049352646,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.054999999701976776,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9598000049591064},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.508899986743927},{"id":"https://openalex.org/keywords/pruning","display_name":"Pruning","score":0.5001999735832214},{"id":"https://openalex.org/keywords/generator","display_name":"Generator (circuit theory)","score":0.46639999747276306},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.4659999907016754},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.43939998745918274},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.4016000032424927}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9598000049591064},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7318000197410583},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.508899986743927},{"id":"https://openalex.org/C108010975","wikidata":"https://www.wikidata.org/wiki/Q500094","display_name":"Pruning","level":2,"score":0.5001999735832214},{"id":"https://openalex.org/C2780992000","wikidata":"https://www.wikidata.org/wiki/Q17016113","display_name":"Generator (circuit theory)","level":3,"score":0.46639999747276306},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.4659999907016754},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.45399999618530273},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.43939998745918274},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.4016000032424927},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39640000462532043},{"id":"https://openalex.org/C2776654903","wikidata":"https://www.wikidata.org/wiki/Q2601463","display_name":"SAFER","level":2,"score":0.37880000472068787},{"id":"https://openalex.org/C2780389661","wikidata":"https://www.wikidata.org/wiki/Q1528875","display_name":"VIPeR","level":3,"score":0.36959999799728394},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.3571000099182129},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.35580000281333923},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.2994000017642975},{"id":"https://openalex.org/C177284502","wikidata":"https://www.wikidata.org/wiki/Q1005390","display_name":"Adapter (computing)","level":2,"score":0.27410000562667847},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.2732999920845032},{"id":"https://openalex.org/C75732639","wikidata":"https://www.wikidata.org/wiki/Q620737","display_name":"Appeasement","level":3,"score":0.25290000438690186},{"id":"https://openalex.org/C108154423","wikidata":"https://www.wikidata.org/wiki/Q1469792","display_name":"Salience (neuroscience)","level":2,"score":0.25220000743865967}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.19478","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.19478","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.19478","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.19478","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Existing":[0],"ViT":[1],"backdoor":[2],"attacks":[3,182],"based":[4],"on":[5,97,167],"backbone-overwriting":[6],"full-tuning":[7],"are":[8,126],"computationally":[9],"expensive":[10],"and":[11,31,66,75,122],"inflict":[12],"performance":[13,166],"degradation.":[14],"This":[15,78,136],"has":[16,39],"forced":[17],"adversaries":[18],"towards":[19,64],"the":[20,43,46,60,130,145,149,158],"Visual":[21,101],"Parameter-Efficient":[22],"Fine-Tuning":[23],"(PEFT)":[24],"paradigm,":[25],"dominated":[26],"by":[27,197],"adapter-based":[28],"(e.g.,":[29,33],"LoRA)":[30],"prompt-based":[32,48],"VPT)":[34],"approaches.":[35],"While":[36],"adapter":[37],"security":[38],"seen":[40],"initial":[41],"study,":[42],"risks":[44],"of":[45,62,191],"burgeoning":[47],"ecosystem":[49],"remain":[50],"critically":[51],"unexplored.":[52],"We":[53,90],"fill":[54],"this":[55,107,110],"critical":[56],"gap,":[57],"exposing":[58],"how":[59],"evolution":[61],"VPT":[63],"dynamic":[65,84,100,111,206],"context-aware":[67],"architectures":[68],"can":[69],"facilitate":[70],"a":[71,98,139,201],"far":[72],"more":[73],"dangerous":[74],"emergent":[76,117],"threat.":[77],"vulnerability":[79],"arises":[80],"even":[81,175],"though":[82],"these":[83],"modules":[85],"unlock":[86],"superior":[87],"benign":[88,123,150],"performance.":[89,151],"propose":[91],"VIPER,":[92],"an":[93,116,187],"attack":[94,146],"framework":[95],"built":[96],"lightweight,":[99],"Prompt":[102],"Generator":[103],"(VPG)":[104],"that":[105],"demonstrates":[106],"vulnerability.":[108],"Critically,":[109],"architecture":[112],"enables":[113],"Functional":[114,198],"Fusion:":[115],"phenomenon":[118],"where":[119],"malicious":[120],"logic":[121],"task":[124],"utility":[125],"tightly":[127],"fused":[128],"into":[129],"same":[131],"sparse,":[132],"high-magnitude":[133],"parameter":[134],"core.":[135],"fusion":[137],"creates":[138],"formidable":[140],"``hostage\"":[141],"dilemma,":[142],"as":[143],"pruning":[144,179],"necessarily":[147],"destroys":[148],"Comprehensive":[152],"evaluations":[153],"show":[154],"VIPER":[155,161],"effectively":[156],"addresses":[157],"attacker's":[159],"trilemma:":[160],"not":[162],"only":[163,186],"achieves":[164],"state-of-the-art":[165],"clean":[168],"data,":[169],"but":[170],"also":[171],"maintains":[172],"near-100%":[173],"ASR":[174],"under":[176],"90%":[177],"VPG-module":[178],"(where":[180],"LoRA":[181],"collapse),":[183],"while":[184],"adding":[185],"imperceptible":[188],"0.06ms":[189],"(1.16%)":[190],"inference":[192],"latency.":[193],"VIPER's":[194],"results,":[195],"driven":[196],"Fusion,":[199],"expose":[200],"new,":[202],"paradigm-level":[203],"risk":[204],"in":[205],"prompt":[207],"architectures.":[208]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-21T00:00:00"}
