[2307.16888] Backdooring Instruction-Tuned Large Language Models with Virtual Prompt Injection