Visual CoT Makes VLMs Smarter but More Fragile
Fuente:
arXiv
Saved in:
| Main Authors: | Xu, Chunxue, Wang, Yiwei, Cai, Yujun, Hooi, Bryan, Li, Songze |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
How does Watermarking Affect Visual Language Models in Document Understanding?
by: Xu, Chunxue, et al.
Published: (2025)
by: Xu, Chunxue, et al.
Published: (2025)
Tricking Retrievers with Influential Tokens: An Efficient Black-Box Corpus Poisoning Attack
by: Wang, Cheng, et al.
Published: (2025)
by: Wang, Cheng, et al.
Published: (2025)
Enhancing Membership Inference Attacks on Diffusion Models from a Frequency-Domain Perspective
by: Lian, Puwei, et al.
Published: (2025)
by: Lian, Puwei, et al.
Published: (2025)
Noise as a Probe: Membership Inference Attacks on Diffusion Models Leveraging Initial Noise
by: Lian, Puwei, et al.
Published: (2026)
by: Lian, Puwei, et al.
Published: (2026)
FuncPoison: Poisoning Function Library to Hijack Multi-agent Autonomous Driving Systems
by: Long, Yuzhen, et al.
Published: (2025)
by: Long, Yuzhen, et al.
Published: (2025)
DeDe: Detecting Backdoor Samples for SSL Encoders via Decoders
by: Hou, Sizai, et al.
Published: (2024)
by: Hou, Sizai, et al.
Published: (2024)
TUNI: A Textual Unimodal Detector for Identity Inference in CLIP Models
by: Li, Songze, et al.
Published: (2024)
by: Li, Songze, et al.
Published: (2024)
OmniLytics+: A Secure, Efficient, and Affordable Blockchain Data Market for Machine Learning through Off-Chain Processing
by: Li, Songze, et al.
Published: (2024)
by: Li, Songze, et al.
Published: (2024)
Noticing the Watcher: LLM Agents Can Infer CoT Monitoring from Blocking Feedback
by: Jiralerspong, Thomas, et al.
Published: (2026)
by: Jiralerspong, Thomas, et al.
Published: (2026)
Graph Neural Network Explanations are Fragile
by: Li, Jiate, et al.
Published: (2024)
by: Li, Jiate, et al.
Published: (2024)
Verification of Machine Unlearning is Fragile
by: Zhang, Binchi, et al.
Published: (2024)
by: Zhang, Binchi, et al.
Published: (2024)
TrojanDam: Detection-Free Backdoor Defense in Federated Learning through Proactive Model Robustification utilizing OOD Data
by: Dai, Yanbo, et al.
Published: (2025)
by: Dai, Yanbo, et al.
Published: (2025)
Constructing Adversarial Examples for Vertical Federated Learning: Optimal Client Corruption through Multi-Armed Bandit
by: Yao, Duanyi, et al.
Published: (2024)
by: Yao, Duanyi, et al.
Published: (2024)
Awakening the Hydra: Stabilizing Multi-Concept Backdoor Injection in Text-to-Image Diffusion Models
by: Wang, Kai, et al.
Published: (2026)
by: Wang, Kai, et al.
Published: (2026)
Knowledge-Driven Multi-Turn Jailbreaking on Large Language Models
by: Li, Songze, et al.
Published: (2026)
by: Li, Songze, et al.
Published: (2026)
Making Every Step Effective: Jailbreaking Large Vision-Language Models Through Hierarchical KV Equalization
by: Hao, Shuyang, et al.
Published: (2025)
by: Hao, Shuyang, et al.
Published: (2025)
Attack Smarter: Attention-Driven Fine-Grained Webpage Fingerprinting Attacks
by: Yuan, Yali, et al.
Published: (2025)
by: Yuan, Yali, et al.
Published: (2025)
TooBadRL: Trigger Optimization to Boost Effectiveness of Backdoor Attacks on Deep Reinforcement Learning
by: Zhang, Mingxuan, et al.
Published: (2025)
by: Zhang, Mingxuan, et al.
Published: (2025)
URVFL: Undetectable Data Reconstruction Attack on Vertical Federated Learning
by: Yao, Duanyi, et al.
Published: (2024)
by: Yao, Duanyi, et al.
Published: (2024)
Attributing and Exploiting Safety Vectors through Global Optimization in Large Language Models
by: Chu, Fengheng, et al.
Published: (2026)
by: Chu, Fengheng, et al.
Published: (2026)
VLMGuard: Defending VLMs against Malicious Prompts via Unlabeled Data
by: Du, Xuefeng, et al.
Published: (2024)
by: Du, Xuefeng, et al.
Published: (2024)
Tit-for-Tat: Safeguarding Large Vision-Language Models Against Jailbreak Attacks via Adversarial Defense
by: Hao, Shuyang, et al.
Published: (2025)
by: Hao, Shuyang, et al.
Published: (2025)
On The Fragility of Benchmark Contamination Detection in Reasoning Models
by: Wang, Han, et al.
Published: (2025)
by: Wang, Han, et al.
Published: (2025)
Turning Bias into Bugs: Bandit-Guided Style Manipulation Attacks on LLM Judges
by: Yang, Xianglin, et al.
Published: (2026)
by: Yang, Xianglin, et al.
Published: (2026)
Beauty and the Beast: Imperceptible Perturbations Against Diffusion-Based Face Swapping via Directional Attribute Editing
by: Huang, Yilong, et al.
Published: (2026)
by: Huang, Yilong, et al.
Published: (2026)
Federated Learning for Cross-Domain Data Privacy: A Distributed Approach to Secure Collaboration
by: Zhang, Yiwei, et al.
Published: (2025)
by: Zhang, Yiwei, et al.
Published: (2025)
Continuous Multi-Task Pre-training for Malicious URL Detection and Webpage Classification
by: Li, Yujie, et al.
Published: (2024)
by: Li, Yujie, et al.
Published: (2024)
Odysseus: Jailbreaking Commercial Multimodal LLM-integrated Systems via Dual Steganography
by: Li, Songze, et al.
Published: (2025)
by: Li, Songze, et al.
Published: (2025)
Hidden Ads: Behavior Triggered Semantic Backdoors for Advertisement Injection in Vision Language Models
by: Yao, Duanyi, et al.
Published: (2026)
by: Yao, Duanyi, et al.
Published: (2026)
Automated Phishing Detection Using URLs and Webpages
by: Wang, Huilin, et al.
Published: (2024)
by: Wang, Huilin, et al.
Published: (2024)
MIRAGE: Multimodal Immersive Reasoning and Guided Exploration for Red-Team Jailbreak Attacks
by: You, Wenhao, et al.
Published: (2025)
by: You, Wenhao, et al.
Published: (2025)
Is the Trigger Essential? A Feature-Based Triggerless Backdoor Attack in Vertical Federated Learning
by: Liu, Yige, et al.
Published: (2026)
by: Liu, Yige, et al.
Published: (2026)
Indiscriminate Data Poisoning Attacks on Neural Networks
by: Lu, Yiwei, et al.
Published: (2022)
by: Lu, Yiwei, et al.
Published: (2022)
Reasoning Introduces New Poisoning Attacks Yet Makes Them More Complicated
by: Foerster, Hanna, et al.
Published: (2025)
by: Foerster, Hanna, et al.
Published: (2025)
DMS: Addressing Information Loss with More Steps for Pragmatic Adversarial Attacks
by: Zhu, Zhiyu, et al.
Published: (2024)
by: Zhu, Zhiyu, et al.
Published: (2024)
Stealthy Yet Effective: Distribution-Preserving Backdoor Attacks on Graph Classification
by: Wang, Xiaobao, et al.
Published: (2025)
by: Wang, Xiaobao, et al.
Published: (2025)
Whisper Smarter, not Harder: Adversarial Attack on Partial Suppression
by: Wong, Zheng Jie, et al.
Published: (2025)
by: Wong, Zheng Jie, et al.
Published: (2025)
No More, No Less: Least-Privilege Language Models
by: Rauba, Paulius, et al.
Published: (2026)
by: Rauba, Paulius, et al.
Published: (2026)
Toward More Generalized Malicious URL Detection Models
by: Tsai, YunDa, et al.
Published: (2022)
by: Tsai, YunDa, et al.
Published: (2022)
Deferred Poisoning: Making the Model More Vulnerable via Hessian Singularization
by: He, Yuhao, et al.
Published: (2024)
by: He, Yuhao, et al.
Published: (2024)
Similar Items
-
How does Watermarking Affect Visual Language Models in Document Understanding?
by: Xu, Chunxue, et al.
Published: (2025) -
Tricking Retrievers with Influential Tokens: An Efficient Black-Box Corpus Poisoning Attack
by: Wang, Cheng, et al.
Published: (2025) -
Enhancing Membership Inference Attacks on Diffusion Models from a Frequency-Domain Perspective
by: Lian, Puwei, et al.
Published: (2025) -
Noise as a Probe: Membership Inference Attacks on Diffusion Models Leveraging Initial Noise
by: Lian, Puwei, et al.
Published: (2026) -
FuncPoison: Poisoning Function Library to Hijack Multi-agent Autonomous Driving Systems
by: Long, Yuzhen, et al.
Published: (2025)