Lune

ICSE2026Top-tier venue

Training on Clean Data but Getting Backdoored Models! A Poisoning Attack on Code Encoders

Yiran Xiao, Xiangyue Liu, Zhou Yang, Lili Bo, Xiaobing Sun

2026Year

Abstract

Transformer-based code encoders like CodeBERT learn general knowledge from vast amounts of unlabeled source code. These encoders can convert input code into meaningful representations (i.e., code embeddings) and support a series of downstream tasks. Specifically, users can fine-tune a code encoder on certain datasets and obtain strong model performance on corresponding tasks. Recent studies have exposed critical security vulnerabilities in this widely-adopted paradigm: attackers can inject backdoors into models by poisoning the fine-tuning datasets with carefully crafted triggers (e.g., dead code snippets), causing the model to produce attacker-specified outputs when these triggers are present.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines