Skip to content

Hide Navigation Hide TOC

Backdoor Trojan: Symbol / Emoticon Trigger (POT Attack) - ATR-2026-01756 (e3b5fc38-5a60-5a9c-ba62-499acbc47a63)

Detects Prompt-Operated Trojan (POT) attacks that use minimalist symbol or emoticon sequences as backdoor activation triggers. Unlike linguistic-phrase triggers (ATR-2026-01755), these use short character sequences — emoticons, punctuation clusters, or uncommon symbol combinations — appended to or embedded in normal task requests. Canonical examples from the ASB backdoor-pot corpus (2026-06): ":)" and "@_@". These appear as innocent suffix tokens but signal backdoor activation to a poisoned model. Detection requires distinguishing isolated trigger usage (appended to task requests) from organic conversational emoticon use.

Cluster A Galaxy A Cluster B Galaxy B Level
Backdoor Trojan: Symbol / Emoticon Trigger (POT Attack) - ATR-2026-01756 (e3b5fc38-5a60-5a9c-ba62-499acbc47a63) Agent Threat Rules LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 1
Backdoor Trojan: Symbol / Emoticon Trigger (POT Attack) - ATR-2026-01756 (e3b5fc38-5a60-5a9c-ba62-499acbc47a63) Agent Threat Rules Poison ML Model (e0eb2b64-aebd-4412-80f3-b71d7805a65f) MITRE ATLAS Attack Pattern 1
Backdoor ML Model (c704a49c-abf0-4258-9919-a862b1865469) MITRE ATLAS Attack Pattern Poison ML Model (e0eb2b64-aebd-4412-80f3-b71d7805a65f) MITRE ATLAS Attack Pattern 2