A Two-Stage Globally-Diverse Adversarial Attack for Vision-Language Pre-training Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Chen, Wutao, Zou, Huaqin, Wan, Chen, Huang, Lifeng
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912831613435904
author Chen, Wutao
Zou, Huaqin
Wan, Chen
Huang, Lifeng
author_facet Chen, Wutao
Zou, Huaqin
Wan, Chen
Huang, Lifeng
contents Vision-language pre-training (VLP) models are vulnerable to adversarial examples, particularly in black-box scenarios. Existing multimodal attacks often suffer from limited perturbation diversity and unstable multi-stage pipelines. To address these challenges, we propose 2S-GDA, a two-stage globally-diverse attack framework. The proposed method first introduces textual perturbations through a globally-diverse strategy by combining candidate text expansion with globally-aware replacement. To enhance visual diversity, image-level perturbations are generated using multi-scale resizing and block-shuffle rotation. Extensive experiments on VLP models demonstrate that 2S-GDA consistently improves attack success rates over state-of-the-art methods, with gains of up to 11.17\% in black-box settings. Our framework is modular and can be easily combined with existing methods to further enhance adversarial transferability.
format Preprint
id arxiv_https___arxiv_org_abs_2601_12304
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle A Two-Stage Globally-Diverse Adversarial Attack for Vision-Language Pre-training Models
Chen, Wutao
Zou, Huaqin
Wan, Chen
Huang, Lifeng
Computer Vision and Pattern Recognition
Artificial Intelligence
Vision-language pre-training (VLP) models are vulnerable to adversarial examples, particularly in black-box scenarios. Existing multimodal attacks often suffer from limited perturbation diversity and unstable multi-stage pipelines. To address these challenges, we propose 2S-GDA, a two-stage globally-diverse attack framework. The proposed method first introduces textual perturbations through a globally-diverse strategy by combining candidate text expansion with globally-aware replacement. To enhance visual diversity, image-level perturbations are generated using multi-scale resizing and block-shuffle rotation. Extensive experiments on VLP models demonstrate that 2S-GDA consistently improves attack success rates over state-of-the-art methods, with gains of up to 11.17\% in black-box settings. Our framework is modular and can be easily combined with existing methods to further enhance adversarial transferability.
title A Two-Stage Globally-Diverse Adversarial Attack for Vision-Language Pre-training Models
topic Computer Vision and Pattern Recognition
Artificial Intelligence
url https://arxiv.org/abs/2601.12304