PulseAugur
EN
LIVE 08:25:38

New VLM backdoor allows arbitrary, programmable control

Researchers have developed a novel method for implanting programmable backdoors into Vision-Language Models (VLMs). Unlike previous static backdoor attacks, this new technique allows attackers to dynamically control target captions and generate corresponding triggers at inference time, even for unseen semantics. The attack involves a heuristic poisoning strategy to teach the model a general trigger-as-instruction rule, followed by a feature-space steganography method to map any target caption to a stealthy visual trigger. This approach maintains the model's clean utility and demonstrates effectiveness against common backdoor defenses. AI

IMPACT Introduces a new class of sophisticated attacks against VLMs, potentially impacting model security and deployment.

RANK_REASON Academic paper detailing a new method for implanting programmable backdoors in VLMs. [lever_c_demoted from research: ic=1 ai=1.0]

Read on arXiv cs.CV →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

New VLM backdoor allows arbitrary, programmable control

COVERAGE [1]

  1. arXiv cs.CV TIER_1 English(EN) · Tao Lin, Gaojie Jin, Zongxin Liu, Peng Wu, Lijia Yu ·

    Once Poisoned, Arbitrarily Controlled: A Programmable Backdoor in VLMs

    arXiv:2608.10959v1 Announce Type: new Abstract: Existing vision-language model (VLM) backdoors are usually treated as static vulnerabilities: one-to-one and N-to-N attacks bind one or more triggers to a finite set of targets before victim training. This assumption substantially u…