Poison Once, Control Anywhere: Clean-Text Visual Backdoors in VLM-based Mobile Agents
Fuente:
arXiv
Saved in:
| Main Authors: | Wang, Xuan, Liang, Siyuan, Liu, Zhe, Yu, Yi, Liu, Aishan, Lu, Yuliang, Gao, Xitong, Chang, Ee-Chien |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
SafeMobile: Chain-level Jailbreak Detection and Automated Evaluation for Multimodal Mobile Agents
by: Liang, Siyuan, et al.
Published: (2025)
by: Liang, Siyuan, et al.
Published: (2025)
ME: Trigger Element Combination Backdoor Attack on Copyright Infringement
by: Yang, Feiyu, et al.
Published: (2025)
by: Yang, Feiyu, et al.
Published: (2025)
TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning
by: Liang, Siyuan, et al.
Published: (2024)
by: Liang, Siyuan, et al.
Published: (2024)
ICLShield: Exploring and Mitigating In-Context Learning Backdoor Attacks
by: Ren, Zhiyao, et al.
Published: (2025)
by: Ren, Zhiyao, et al.
Published: (2025)
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026)
by: Zou, Wei, et al.
Published: (2026)
ELBA-Bench: An Efficient Learning Backdoor Attacks Benchmark for Large Language Models
by: Liu, Xuxu, et al.
Published: (2025)
by: Liu, Xuxu, et al.
Published: (2025)
FFCBA: Feature-based Full-target Clean-label Backdoor Attacks
by: Yin, Yangxu, et al.
Published: (2025)
by: Yin, Yangxu, et al.
Published: (2025)
WFCAT: Augmenting Website Fingerprinting with Channel-wise Attention on Timing Features
by: Gong, Jiajun, et al.
Published: (2024)
by: Gong, Jiajun, et al.
Published: (2024)
Compromising Embodied Agents with Contextual Backdoor Attacks
by: Liu, Aishan, et al.
Published: (2024)
by: Liu, Aishan, et al.
Published: (2024)
Acquiring Clean Language Models from Backdoor Poisoned Datasets by Downscaling Frequency Space
by: Wu, Zongru, et al.
Published: (2024)
by: Wu, Zongru, et al.
Published: (2024)
Spa-VLM: Stealthy Poisoning Attacks on RAG-based VLM
by: Yu, Lei, et al.
Published: (2025)
by: Yu, Lei, et al.
Published: (2025)
Poisoning the Pixels: Revisiting Backdoor Attacks on Semantic Segmentation
by: Zhang, Guangsheng, et al.
Published: (2026)
by: Zhang, Guangsheng, et al.
Published: (2026)
Checkerboard: A Simple, Effective, Efficient and Learning-free Clean Label Backdoor Attack with Low Poisoning Budget
by: Yang, Yi, et al.
Published: (2026)
by: Yang, Yi, et al.
Published: (2026)
Graph-Aware Stealthy Poison-Text Backdoors for Text-Attributed Graphs
by: Luo, Qi, et al.
Published: (2026)
by: Luo, Qi, et al.
Published: (2026)
VisPoison: An Effective Backdoor Attack Framework for Tabular Data Visualization Models
by: Li, Shuaimin, et al.
Published: (2024)
by: Li, Shuaimin, et al.
Published: (2024)
Activation Gradient based Poisoned Sample Detection Against Backdoor Attacks
by: Yuan, Danni, et al.
Published: (2023)
by: Yuan, Danni, et al.
Published: (2023)
From Poisoned to Aware: Fostering Backdoor Self-Awareness in LLMs
by: Shen, Guangyu, et al.
Published: (2025)
by: Shen, Guangyu, et al.
Published: (2025)
Proof-of-Authorship for Diffusion-based AI Generated Content
by: Lee, De Zhang, et al.
Published: (2026)
by: Lee, De Zhang, et al.
Published: (2026)
T2VShield: Model-Agnostic Jailbreak Defense for Text-to-Video Models
by: Liang, Siyuan, et al.
Published: (2025)
by: Liang, Siyuan, et al.
Published: (2025)
Signals and Symptoms: ICS Attack Dataset From Railway Cyber Range
by: Yusof, Anis, et al.
Published: (2025)
by: Yusof, Anis, et al.
Published: (2025)
Wicked Oddities: Selectively Poisoning for Effective Clean-Label Backdoor Attacks
by: Nguyen, Quang H., et al.
Published: (2024)
by: Nguyen, Quang H., et al.
Published: (2024)
ProtegoFed: Backdoor-Free Federated Instruction Tuning with Interspersed Poisoned Data
by: Zhao, Haodong, et al.
Published: (2026)
by: Zhao, Haodong, et al.
Published: (2026)
Poisoning-based Backdoor Attacks for Arbitrary Target Label with Positive Triggers
by: Huang, Binxiao, et al.
Published: (2024)
by: Huang, Binxiao, et al.
Published: (2024)
When Forgetting Triggers Backdoors: A Clean Unlearning Attack
by: Arazzi, Marco, et al.
Published: (2025)
by: Arazzi, Marco, et al.
Published: (2025)
AttacKG+:Boosting Attack Knowledge Graph Construction with Large Language Models
by: Zhang, Yongheng, et al.
Published: (2024)
by: Zhang, Yongheng, et al.
Published: (2024)
Targeted Bit-Flip Attacks on LLM-Based Agents
by: Wang, Jialai, et al.
Published: (2026)
by: Wang, Jialai, et al.
Published: (2026)
Removal Attack and Defense on AI-generated Content Latent-based Watermarking
by: Lee, De Zhang, et al.
Published: (2025)
by: Lee, De Zhang, et al.
Published: (2025)
A Practical and Secure Byzantine Robust Aggregator
by: Lee, De Zhang, et al.
Published: (2025)
by: Lee, De Zhang, et al.
Published: (2025)
T-Edge: Trusted Heterogeneous Edge Computing
by: Shen, Jiamin, et al.
Published: (2024)
by: Shen, Jiamin, et al.
Published: (2024)
Generalization Bound and New Algorithm for Clean-Label Backdoor Attack
by: Yu, Lijia, et al.
Published: (2024)
by: Yu, Lijia, et al.
Published: (2024)
SafeBench: A Safety Evaluation Framework for Multimodal Large Language Models
by: Ying, Zonghao, et al.
Published: (2024)
by: Ying, Zonghao, et al.
Published: (2024)
A Set of Generalized Components to Achieve Effective Poison-only Clean-label Backdoor Attacks with Collaborative Sample Selection and Triggers
by: Wu, Zhixiao, et al.
Published: (2025)
by: Wu, Zhixiao, et al.
Published: (2025)
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
by: Tie, Guiyao, et al.
Published: (2026)
by: Tie, Guiyao, et al.
Published: (2026)
SleeperNets: Universal Backdoor Poisoning Attacks Against Reinforcement Learning Agents
by: Rathbun, Ethan, et al.
Published: (2024)
by: Rathbun, Ethan, et al.
Published: (2024)
Backdoor Learning Curves: Explaining Backdoor Poisoning Beyond Influence Functions
by: Cinà, Antonio Emanuele, et al.
Published: (2021)
by: Cinà, Antonio Emanuele, et al.
Published: (2021)
Follow My Eyes: Backdoor Attacks on VLM-based Scanpath Prediction
by: Romero, Diana, et al.
Published: (2026)
by: Romero, Diana, et al.
Published: (2026)
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
by: Ying, Zonghao, et al.
Published: (2026)
by: Ying, Zonghao, et al.
Published: (2026)
ASPIRER: Bypassing System Prompts With Permutation-based Backdoors in LLMs
by: Yan, Lu, et al.
Published: (2024)
by: Yan, Lu, et al.
Published: (2024)
Mitigating Backdoor Triggered and Targeted Data Poisoning Attacks in Voice Authentication Systems
by: Mohammadi, Alireza, et al.
Published: (2025)
by: Mohammadi, Alireza, et al.
Published: (2025)
One-to-Multiple Clean-Label Image Camouflage (OmClic) based Backdoor Attack on Deep Learning
by: Wang, Guohong, et al.
Published: (2023)
by: Wang, Guohong, et al.
Published: (2023)
Similar Items
-
SafeMobile: Chain-level Jailbreak Detection and Automated Evaluation for Multimodal Mobile Agents
by: Liang, Siyuan, et al.
Published: (2025) -
ME: Trigger Element Combination Backdoor Attack on Copyright Infringement
by: Yang, Feiyu, et al.
Published: (2025) -
TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning
by: Liang, Siyuan, et al.
Published: (2024) -
ICLShield: Exploring and Mitigating In-Context Learning Backdoor Attacks
by: Ren, Zhiyao, et al.
Published: (2025) -
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026)