{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:BMMEEQB6TNK2DWPIJZ5JXUKRT7","short_pith_number":"pith:BMMEEQB6","schema_version":"1.0","canonical_sha256":"0b1842403e9b55a1d9e84e7a9bd1519feba3f09bc1d50e7525c0e052dae91468","source":{"kind":"arxiv","id":"2403.07654","version":1},"attestation_state":"computed","paper":{"title":"Analyzing Adversarial Attacks on Sequence-to-Sequence Relevance Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.IR","authors_text":"Andrew Parry, Maik Fr\\\"obe, Martin Potthast, Matthias Hagen, Sean MacAvaney","submitted_at":"2024-03-12T13:45:20Z","abstract_excerpt":"Modern sequence-to-sequence relevance models like monoT5 can effectively capture complex textual interactions between queries and documents through cross-encoding. However, the use of natural language tokens in prompts, such as Query, Document, and Relevant for monoT5, opens an attack vector for malicious documents to manipulate their relevance score through prompt injection, e.g., by adding target words such as true. Since such possibilities have not yet been considered in retrieval evaluation, we analyze the impact of query-independent prompt injection via manually constructed templates and "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2403.07654","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.IR","submitted_at":"2024-03-12T13:45:20Z","cross_cats_sorted":[],"title_canon_sha256":"d08557eb135b7b5f8cbd1c4ae11345004b0f4a38fc5483b71ed246d4201f8e30","abstract_canon_sha256":"ab6bb3681e9dc53df8fced6adadd5612a060ee77d0021803ef56510e0c5508bc"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:55:06.430136Z","signature_b64":"IflH/MsAIc7PClYaFrW9GgtSQfp2zGNqhB9hFigvPjetYVDHk0I6VXpc6UI2+VY874KHV2RRoqADeZu+PFB5DQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0b1842403e9b55a1d9e84e7a9bd1519feba3f09bc1d50e7525c0e052dae91468","last_reissued_at":"2026-07-05T07:55:06.429644Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:55:06.429644Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Analyzing Adversarial Attacks on Sequence-to-Sequence Relevance Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.IR","authors_text":"Andrew Parry, Maik Fr\\\"obe, Martin Potthast, Matthias Hagen, Sean MacAvaney","submitted_at":"2024-03-12T13:45:20Z","abstract_excerpt":"Modern sequence-to-sequence relevance models like monoT5 can effectively capture complex textual interactions between queries and documents through cross-encoding. However, the use of natural language tokens in prompts, such as Query, Document, and Relevant for monoT5, opens an attack vector for malicious documents to manipulate their relevance score through prompt injection, e.g., by adding target words such as true. Since such possibilities have not yet been considered in retrieval evaluation, we analyze the impact of query-independent prompt injection via manually constructed templates and "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2403.07654","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2403.07654/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2403.07654","created_at":"2026-07-05T07:55:06.429704+00:00"},{"alias_kind":"arxiv_version","alias_value":"2403.07654v1","created_at":"2026-07-05T07:55:06.429704+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2403.07654","created_at":"2026-07-05T07:55:06.429704+00:00"},{"alias_kind":"pith_short_12","alias_value":"BMMEEQB6TNK2","created_at":"2026-07-05T07:55:06.429704+00:00"},{"alias_kind":"pith_short_16","alias_value":"BMMEEQB6TNK2DWPI","created_at":"2026-07-05T07:55:06.429704+00:00"},{"alias_kind":"pith_short_8","alias_value":"BMMEEQB6","created_at":"2026-07-05T07:55:06.429704+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2604.09946","citing_title":"All Eyes on the Ranker: Participatory Auditing to Surface Blind Spots in Ranked Search Results","ref_index":40,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7","json":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7.json","graph_json":"https://pith.science/api/pith-number/BMMEEQB6TNK2DWPIJZ5JXUKRT7/graph.json","events_json":"https://pith.science/api/pith-number/BMMEEQB6TNK2DWPIJZ5JXUKRT7/events.json","paper":"https://pith.science/paper/BMMEEQB6"},"agent_actions":{"view_html":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7","download_json":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7.json","view_paper":"https://pith.science/paper/BMMEEQB6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2403.07654&json=true","fetch_graph":"https://pith.science/api/pith-number/BMMEEQB6TNK2DWPIJZ5JXUKRT7/graph.json","fetch_events":"https://pith.science/api/pith-number/BMMEEQB6TNK2DWPIJZ5JXUKRT7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7/action/storage_attestation","attest_author":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7/action/author_attestation","sign_citation":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7/action/citation_signature","submit_replication":"https://pith.science/pith/BMMEEQB6TNK2DWPIJZ5JXUKRT7/action/replication_record"}},"created_at":"2026-07-05T07:55:06.429704+00:00","updated_at":"2026-07-05T07:55:06.429704+00:00"}