paper-with-me

Papers

Image-based Multimodal Models as Intruders: Transferable Multimodal Attacks on Video-based MLLMs

2025-01-02 · Linhao Huang, Xue Jiang, Zhiqiang Wang, Wentao Mo, Xi Xiao, Bo Han, Yongjie Yin, Feng Zheng

Video-based multimodal large language models (V-MLLMs) have shown vulnerability to adversarial examples in video-text multimodal tasks. However, the transferability of adversarial videos to unseen models--a common and practical real world scenario--remains unexplored. In this paper, we pioneer an investigation into the transferability of adversarial video samples across V-MLLMs. We find that existing adversarial attack methods face significant limitations when applied in black-box settings for V-MLLMs, which we attribute to the following shortcomings: (1) lacking generalization in perturbing video features, (2) focusing only on sparse key-frames, and (3) failing to integrate multimodal information. To address these limitations and deepen the understanding of V-MLLM vulnerabilities in black-box scenarios, we introduce the Image-to-Video MLLM (I2V-MLLM) attack. In I2V-MLLM, we utilize an image-based multimodal model (IMM) as a surrogate model to craft adversarial video samples. Multimodal interactions and temporal information are integrated to disrupt video representations within the latent space, improving adversarial transferability. In addition, a perturbation propagation technique is introduced to handle different unknown frame sampling strategies. Experimental results demonstrate that our method can generate adversarial examples that exhibit strong transferability across different V-MLLMs on multiple video-text multimodal tasks. Compared to white-box attacks on these models, our black-box attacks (using BLIP-2 as surrogate model) achieve competitive performance, with average attack success rates of 55.48% on MSVD-QA and 58.26% on MSRVTT-QA for VideoQA tasks, respectively. Our code will be released upon acceptance.

📄 PDF Abstract BibTeX arXiv:2501.01042

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial AttackAttribute

Similar Papers 제목 키워드 기반

When Background Matters: Breaking Medical Vision Language Models by Transferable Attack

2026-04-19 · Akash Ghosh, Subhadip Baidya, Sriparna Saha, Xiuying Chen arxiv

Vision-Language Models (VLMs) are increasingly used in clinical diagnostics, yet their robustness to adversarial attacks remains largely unexplored, posing serious risks. Existing medical attacks focus on secondary objec…

Challenging Vision-Language Models with Physically Deployable Multimodal Semantic Lighting Attacks

2026-04-14 · Yingying Zhao, Chengyin Hu, Qike Zhang, Xin Li 외 arxiv

Vision-Language Models (VLMs) have shown remarkable performance, yet their security remains insufficiently understood. Existing adversarial studies focus almost exclusively on the digital setting, leaving physical-world …

Visual Question AnsweringMultimodal ReasoningAdversarial AttackImage Captioning

Every Picture Tells a Dangerous Story: Memory-Augmented Multi-Agent Jailbreak Attacks on VLMs

2026-04-14 · Jianhao Chen, Haoyang Chen, Hanjie Zhao, Haozhe Liang 외 arxiv

Vision-Language Models (VLMs) expand the attack surface of safety-aligned systems by coupling visual perception with text generation. Existing multimodal jailbreak attacks primarily rely on crafted visual content, advers…

Adversarial Attack

On the Adversarial Robustness of Multimodal LLM Judges

2026-06-14 · Zihan Wang, Guansong Pang, Zelin Liu, Wenjun Miao 외 arxiv

Multimodal Large Language Models (MLLMs) are increasingly used as automated judges, e.g., for image quality and safety assessment. However, their adversarial robustness remains largely unexplored, threatening the fairnes…

Adversarial Robustness

Modeling False Data Injection Attacks in Integrated Electricity-Gas Systems

2023-12-01 · Rong-Peng Liu, Xiaozhe Wang, Zuyi Li, Rawad Zgheib

This work studies the modeling of false data injection attacks (FDIAs) in integrated electricity-gas systems (IEGSs). First, we introduce a static state estimation model and bad data detection method for IEGSs. Then, we …

State Estimation