paper-with-me

홈 › Papers

When Lighting Deceives: Exposing Vision-Language Models' Illumination Vulnerability Through Illumination Transformation Attack

2025-03-10 · Hanqing Liu, Shouwei Ruan, Yao Huang, Shiji Zhao, Xingxing Wei

Vision-Language Models (VLMs) have achieved remarkable success in various tasks, yet their robustness to real-world illumination variations remains largely unexplored. To bridge this gap, we propose \textbf{I}llumination \textbf{T}ransformation \textbf{A}ttack (\textbf{ITA}), the first framework to systematically assess VLMs' robustness against illumination changes. However, there still exist two key challenges: (1) how to model global illumination with fine-grained control to achieve diverse lighting conditions and (2) how to ensure adversarial effectiveness while maintaining naturalness. To address the first challenge, we innovatively decompose global illumination into multiple parameterized point light sources based on the illumination rendering equation. This design enables us to model more diverse lighting variations that previous methods could not capture. Then, by integrating these parameterized lighting variations with physics-based lighting reconstruction techniques, we could precisely render such light interactions in the original scenes, finally meeting the goal of fine-grained lighting control. For the second challenge, by controlling illumination through the lighting reconstrution model's latent space rather than direct pixel manipulation, we inherently preserve physical lighting priors. Furthermore, to prevent potential reconstruction artifacts, we design additional perceptual constraints for maintaining visual consistency with original images and diversity constraints for avoiding light source convergence. Extensive experiments demonstrate that our ITA could significantly reduce the performance of advanced VLMs, e.g., LLaVA-1.6, while possessing competitive naturalness, exposing VLMS' critical illuminiation vulnerabilities.

📄 PDF Abstract BibTeX arXiv:2503.06903

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Relighting as a Probe of Visual Priors via Augmented Latent Intrinsics

2026-02-01 · Xiaoyan Xing, Xiao Zhang, Sezer Karaoglu, Theo Gevers 외 arxiv

Image-to-image relighting requires representations that separate illumination from scene properties while preserving dense geometry, material, and photometric cues. We use this task as a probe of visual priors: unlike re…

Image Relighting

Challenging Vision-Language Models with Physically Deployable Multimodal Semantic Lighting Attacks

2026-04-14 · Yingying Zhao, Chengyin Hu, Qike Zhang, Xin Li 외 arxiv

Vision-Language Models (VLMs) have shown remarkable performance, yet their security remains insufficiently understood. Existing adversarial studies focus almost exclusively on the digital setting, leaving physical-world …

Visual Question AnsweringMultimodal ReasoningAdversarial AttackImage Captioning

Toward Universal and Transferable Jailbreak Attacks on Vision-Language Models

2026-02-01 · Kaiyuan Cui, Yige Li, Yutao Wu, Xingjun Ma 외 arxiv

Vision-language models (VLMs) extend large language models (LLMs) with vision encoders, enabling text generation conditioned on both images and text. However, this multimodal integration expands the attack surface by exp…

Text Generation

Effective Black-Box Multi-Faceted Attacks Breach Vision Large Language Model Guardrails

2025-02-09 · Yijun Yang, Lichao Wang, Xiao Yang, Lanqing Hong 외

Vision Large Language Models (VLLMs) integrate visual data processing, expanding their real-world applications, but also increasing the risk of generating unsafe responses. In response, leading companies have implemented…

Language ModelingLanguage ModellingLarge Language Model

Shielding Google's language toxicity model against adversarial attacks

2018-01-05 · Nestor Rodriguez, Sergio Rojas-Galeano

Lack of moderation in online communities enables participants to incur in personal aggression, harassment or cyberbullying, issues that have been accentuated by extremist radicalisation in the contemporary post-truth pol…

BIG-bench Machine LearningmodelNegation