Effective and Efficient Adversarial Detection for Vision-Language Models via A Single Vector

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Huang, Youcheng, Zhu, Fengbin, Tang, Jingkun, Zhou, Pan, Lei, Wenqiang, Lv, Jiancheng, Chua, Tat-Seng
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909372092776448
author Huang, Youcheng
Zhu, Fengbin
Tang, Jingkun
Zhou, Pan
Lei, Wenqiang
Lv, Jiancheng
Chua, Tat-Seng
author_facet Huang, Youcheng
Zhu, Fengbin
Tang, Jingkun
Zhou, Pan
Lei, Wenqiang
Lv, Jiancheng
Chua, Tat-Seng
contents Visual Language Models (VLMs) are vulnerable to adversarial attacks, especially those from adversarial images, which is however under-explored in literature. To facilitate research on this critical safety problem, we first construct a new laRge-scale Adervsarial images dataset with Diverse hArmful Responses (RADAR), given that existing datasets are either small-scale or only contain limited types of harmful responses. With the new RADAR dataset, we further develop a novel and effective iN-time Embedding-based AdveRSarial Image DEtection (NEARSIDE) method, which exploits a single vector that distilled from the hidden states of VLMs, which we call the attacking direction, to achieve the detection of adversarial images against benign ones in the input. Extensive experiments with two victim VLMs, LLaVA and MiniGPT-4, well demonstrate the effectiveness, efficiency, and cross-model transferrability of our proposed method. Our code is available at https://github.com/mob-scu/RADAR-NEARSIDE
format Preprint
id arxiv_https___arxiv_org_abs_2410_22888
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Effective and Efficient Adversarial Detection for Vision-Language Models via A Single Vector
Huang, Youcheng
Zhu, Fengbin
Tang, Jingkun
Zhou, Pan
Lei, Wenqiang
Lv, Jiancheng
Chua, Tat-Seng
Computer Vision and Pattern Recognition
Computation and Language
Cryptography and Security
Visual Language Models (VLMs) are vulnerable to adversarial attacks, especially those from adversarial images, which is however under-explored in literature. To facilitate research on this critical safety problem, we first construct a new laRge-scale Adervsarial images dataset with Diverse hArmful Responses (RADAR), given that existing datasets are either small-scale or only contain limited types of harmful responses. With the new RADAR dataset, we further develop a novel and effective iN-time Embedding-based AdveRSarial Image DEtection (NEARSIDE) method, which exploits a single vector that distilled from the hidden states of VLMs, which we call the attacking direction, to achieve the detection of adversarial images against benign ones in the input. Extensive experiments with two victim VLMs, LLaVA and MiniGPT-4, well demonstrate the effectiveness, efficiency, and cross-model transferrability of our proposed method. Our code is available at https://github.com/mob-scu/RADAR-NEARSIDE
title Effective and Efficient Adversarial Detection for Vision-Language Models via A Single Vector
topic Computer Vision and Pattern Recognition
Computation and Language
Cryptography and Security
url https://arxiv.org/abs/2410.22888