paper-with-me

Papers

VISOR: Visual Input-based Steering for Output Redirection in Vision-Language Models

2025-08-11 · Mansi Phute, Ravikumar Balakrishnan arxiv

Vision Language Models (VLMs) are increasingly being used in a broad range of applications, bringing their security and behavioral control to the forefront. While existing approaches for behavioral control or output redirection, like system prompting in VLMs, are easily detectable and often ineffective, activation-based steering vectors require invasive runtime access to model internals--incompatible with API-based services and closed-source deployments. We introduce VISOR (Visual Input-based Steering for Output Redirection), a novel method that achieves sophisticated behavioral control through optimized visual inputs alone. By crafting universal steering images that induce target activation patterns, VISOR enables practical deployment across all VLM serving modalities while remaining imperceptible compared to explicit textual instructions. We validate VISOR on LLaVA-1.5-7B across three critical alignment tasks: refusal, sycophancy and survival instinct. A single 150KB steering image matches steering vector performance within 1-2% for positive behavioral shifts while dramatically exceeding it for negative steering--achieving up to 25% shifts from baseline compared to steering vectors' modest changes. Unlike system prompting (3-4% shifts), VISOR provides robust bidirectional control while maintaining 99.9% performance on 14,000 unrelated MMLU tasks. Beyond eliminating runtime overhead and model access requirements, VISOR exposes a critical security vulnerability: adversaries can achieve sophisticated behavioral manipulation through visual channels alone, bypassing text-based defenses. Our work fundamentally re-imagines multimodal model control and highlights the urgent need for defenses against visual steering attacks.

📄 PDF Abstract BibTeX arXiv:2508.08521

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

VISOR++: Universal Visual Inputs based Steering for Large Vision Language Models

2025-09-29 · Ravikumar Balakrishnan, Mansi Phute arxiv

As Vision Language Models (VLMs) are deployed across safety-critical applications, understanding and controlling their behavioral patterns has become increasingly important. Existing behavioral control methods face signi…

Behavior Uncloning: Distilling Mode Redirection into Policy Weights without Inference-Time Steering

2026-06-28 · Hao Wang, Jiuzhou Lei, Dayou Li, Bangya Liu 외 arxiv

Behavior-cloned policies often learn multiple behavior modes from demonstration datasets, including modes that are unsafe or otherwise undesired at deployment. For example, a policy trained on diverse handover demonstrat…

Generalized two-point visual control model of human steering for accurate state estimation

2024-06-05 · Rene Mai, Katherine Sears, Grace Roessling, Agung Julius 외

We derive and validate a generalization of the two-point visual control model, an accepted cognitive science model for human steering behavior. The generalized model is needed as current steering models are either insuff…

State Estimation

Inference-Time Machine Unlearning via Gated Activation Redirection

2026-05-12 · Vinícius Conte Turani, Otávio Parraga, João Vitor Boer Abitante, Kristen K. Arguello 외 arxiv

Large Language Models memorize vast amounts of training data, raising concerns regarding privacy, copyright infringement, and safety. Machine unlearning seeks to remove the influence of a targeted forget set while preser…

GazeDirector: Fully Articulated Eye Gaze Redirection in Video

2017-04-27 · Erroll Wood, Tadas Baltrusaitis, Louis-Philippe Morency, Peter Robinson 외

We present GazeDirector, a new approach for eye gaze redirection that uses model-fitting. Our method first tracks the eyes by fitting a multi-part eye region model to video frames using analysis-by-synthesis, thereby rec…

Gaze Estimationgaze redirection