Vision-LLMs Can Fool Themselves with Self-Generated Typographic Attacks
Fuente:
arXiv
Saved in:
| Main Authors: | Qraitem, Maan, Tasnim, Nazia, Teterwak, Piotr, Saenko, Kate, Plummer, Bryan A. |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Web Artifact Attacks Disrupt Vision Language Models
by: Qraitem, Maan, et al.
Published: (2025)
by: Qraitem, Maan, et al.
Published: (2025)
SLANT: Spurious Logo ANalysis Toolkit
by: Qraitem, Maan, et al.
Published: (2024)
by: Qraitem, Maan, et al.
Published: (2024)
From Fake to Real: Pretraining on Balanced Synthetic Images to Prevent Spurious Correlations in Image Recognition
by: Qraitem, Maan, et al.
Published: (2023)
by: Qraitem, Maan, et al.
Published: (2023)
ERM++: An Improved Baseline for Domain Generalization
by: Teterwak, Piotr, et al.
Published: (2023)
by: Teterwak, Piotr, et al.
Published: (2023)
Is Large-Scale Pretraining the Secret to Good Domain Generalization?
by: Teterwak, Piotr, et al.
Published: (2024)
by: Teterwak, Piotr, et al.
Published: (2024)
OP-LoRA: The Blessing of Dimensionality
by: Teterwak, Piotr, et al.
Published: (2024)
by: Teterwak, Piotr, et al.
Published: (2024)
Transparency Attacks: How Imperceptible Image Layers Can Fool AI Perception
by: McKee, Forrest, et al.
Published: (2024)
by: McKee, Forrest, et al.
Published: (2024)
Can a Teenager Fool an AI? Evaluating Low-Cost Cosmetic Attacks on Age Estimation Systems
by: Shen, Xingyu, et al.
Published: (2026)
by: Shen, Xingyu, et al.
Published: (2026)
RECAST: Reparameterized, Compact weight Adaptation for Sequential Tasks
by: Tasnim, Nazia, et al.
Published: (2024)
by: Tasnim, Nazia, et al.
Published: (2024)
Certified but Fooled! Breaking Certified Defences with Ghost Certificates
by: Vo, Quoc Viet, et al.
Published: (2025)
by: Vo, Quoc Viet, et al.
Published: (2025)
StyleFool: Fooling Video Classification Systems via Style Transfer
by: Cao, Yuxin, et al.
Published: (2022)
by: Cao, Yuxin, et al.
Published: (2022)
CLAMP: Contrastive LAnguage Model Prompt-tuning
by: Teterwak, Piotr, et al.
Published: (2023)
by: Teterwak, Piotr, et al.
Published: (2023)
Technical Report for ICML 2024 TiFA Workshop MLLM Attack Challenge: Suffix Injection and Projected Gradient Descent Can Easily Fool An MLLM
by: Guo, Yangyang, et al.
Published: (2024)
by: Guo, Yangyang, et al.
Published: (2024)
QuantAttack: Exploiting Dynamic Quantization to Attack Vision Transformers
by: Baras, Amit, et al.
Published: (2023)
by: Baras, Amit, et al.
Published: (2023)
Fooling the Watchers: Breaking AIGC Detectors via Semantic Prompt Attacks
by: Hao, Run, et al.
Published: (2025)
by: Hao, Run, et al.
Published: (2025)
Perturbing Attention Gives You More Bang for the Buck: Subtle Imaging Perturbations That Efficiently Fool Customized Diffusion Models
by: Xu, Jingyao, et al.
Published: (2024)
by: Xu, Jingyao, et al.
Published: (2024)
Consistent Attack: Universal Adversarial Perturbation on Embodied Vision Navigation
by: Ying, Chengyang, et al.
Published: (2022)
by: Ying, Chengyang, et al.
Published: (2022)
Image Can Bring Your Memory Back: A Novel Multi-Modal Guided Attack against Image Generation Model Unlearning
by: Liu, Renyang, et al.
Published: (2025)
by: Liu, Renyang, et al.
Published: (2025)
DeSparsify: Adversarial Attack Against Token Sparsification Mechanisms in Vision Transformers
by: Yehezkel, Oryan, et al.
Published: (2024)
by: Yehezkel, Oryan, et al.
Published: (2024)
The Impact of Uniform Inputs on Activation Sparsity and Energy-Latency Attacks in Computer Vision
by: Müller, Andreas, et al.
Published: (2024)
by: Müller, Andreas, et al.
Published: (2024)
LogoStyleFool: Vitiating Video Recognition Systems via Logo Style Transfer
by: Cao, Yuxin, et al.
Published: (2023)
by: Cao, Yuxin, et al.
Published: (2023)
FoolSDEdit: Deceptively Steering Your Edits Towards Targeted Attribute-aware Distribution
by: Zhou, Qi, et al.
Published: (2024)
by: Zhou, Qi, et al.
Published: (2024)
Not All Prompts Are Secure: A Switchable Backdoor Attack Against Pre-trained Vision Transformers
by: Yang, Sheng, et al.
Published: (2024)
by: Yang, Sheng, et al.
Published: (2024)
Goal-oriented Backdoor Attack against Vision-Language-Action Models via Physical Objects
by: Zhou, Zirun, et al.
Published: (2025)
by: Zhou, Zirun, et al.
Published: (2025)
Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion Attacks
by: Struppek, Lukas, et al.
Published: (2023)
by: Struppek, Lukas, et al.
Published: (2023)
A Note on Implementation Errors in Recent Adaptive Attacks Against Multi-Resolution Self-Ensembles
by: Fort, Stanislav
Published: (2025)
by: Fort, Stanislav
Published: (2025)
Breaking the Assistant Mold: Modeling Behavioral Variation in LLM Based Procedural Character Generation
by: Qraitem, Maan, et al.
Published: (2026)
by: Qraitem, Maan, et al.
Published: (2026)
AttackBench: Evaluating Gradient-based Attacks for Adversarial Examples
by: Cinà, Antonio Emanuele, et al.
Published: (2024)
by: Cinà, Antonio Emanuele, et al.
Published: (2024)
Advancing Generalized Transfer Attack with Initialization Derived Bilevel Optimization and Dynamic Sequence Truncation
by: Liu, Yaohua, et al.
Published: (2024)
by: Liu, Yaohua, et al.
Published: (2024)
Can LLMs be Fooled? Investigating Vulnerabilities in LLMs
by: Abdali, Sara, et al.
Published: (2024)
by: Abdali, Sara, et al.
Published: (2024)
Boosting Generative Adversarial Transferability with Self-supervised Vision Transformer Features
by: Wu, Shangbo, et al.
Published: (2025)
by: Wu, Shangbo, et al.
Published: (2025)
Attack Anything: Blind DNNs via Universal Background Adversarial Attack
by: Lian, Jiawei, et al.
Published: (2024)
by: Lian, Jiawei, et al.
Published: (2024)
Universal Backdoor Attacks
by: Schneider, Benjamin, et al.
Published: (2023)
by: Schneider, Benjamin, et al.
Published: (2023)
Backdoor Attack on Vision Language Models with Stealthy Semantic Manipulation
by: Zhong, Zhiyuan, et al.
Published: (2025)
by: Zhong, Zhiyuan, et al.
Published: (2025)
Task-Agnostic Attacks Against Vision Foundation Models
by: Pulfer, Brian, et al.
Published: (2025)
by: Pulfer, Brian, et al.
Published: (2025)
Backdoor Attack with Sparse and Invisible Trigger
by: Gao, Yinghua, et al.
Published: (2023)
by: Gao, Yinghua, et al.
Published: (2023)
Memory Backdoor Attacks on Neural Networks
by: Luzon, Eden, et al.
Published: (2024)
by: Luzon, Eden, et al.
Published: (2024)
IU: Imperceptible Universal Backdoor Attack
by: Lin, Hsin, et al.
Published: (2026)
by: Lin, Hsin, et al.
Published: (2026)
Invisible Backdoor Attacks on Diffusion Models
by: Li, Sen, et al.
Published: (2024)
by: Li, Sen, et al.
Published: (2024)
Megatron: Evasive Clean-Label Backdoor Attacks against Vision Transformer
by: Gong, Xueluan, et al.
Published: (2024)
by: Gong, Xueluan, et al.
Published: (2024)
Similar Items
-
Web Artifact Attacks Disrupt Vision Language Models
by: Qraitem, Maan, et al.
Published: (2025) -
SLANT: Spurious Logo ANalysis Toolkit
by: Qraitem, Maan, et al.
Published: (2024) -
From Fake to Real: Pretraining on Balanced Synthetic Images to Prevent Spurious Correlations in Image Recognition
by: Qraitem, Maan, et al.
Published: (2023) -
ERM++: An Improved Baseline for Domain Generalization
by: Teterwak, Piotr, et al.
Published: (2023) -
Is Large-Scale Pretraining the Secret to Good Domain Generalization?
by: Teterwak, Piotr, et al.
Published: (2024)