Fetching the paper…
Reading the bibliography…
Vision Language Models (VLMs) have shown remarkable performance, but are also vulnerable to backdoor attacks whereby the adversary can manipulate the model's outputs through hidden triggers.
2017
Earlier work this paper cites.
Y. Ji, X. Zhang, and T. Wang, “Backdoor attacks against learning systems,” in Proc. 2017 IEEE Conf. Commun. Network Secur. (CNS) . IEEE, 2017, pp. 1–9
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
Y. Goyal, T. Khot, D. Summers-Stay, D. Batra, and D. Parikh, “Making the V in VQA matter: Elevating the role of image understanding in visual question answering,” in 2017 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2017, Honolulu, HI, USA, July 21-26, 2017 . IEEE Computer Society, 2017, pp. 6325–6334. [Online]. Available: https://doi.org/10.1109/CVPR.2017.670
2017
Earlier work this paper cites.
2018
Earlier work this paper cites.
2019
Earlier work this paper cites.
J. Dai, C. Chen, and Y. Li, “A backdoor attack against lstm-based text classification systems,” IEEE Access , vol. 7, pp. 138 872–138 878, 2019
2019
Earlier work this paper cites.
D. A. Hudson and C. D. Manning, “Gqa: A new dataset for real-world visual reasoning and compositional question answering,” in 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , 2019, pp. 6693–6702
2019
Earlier work this paper cites.
K. Kurita, P. Michel, and G. Neubig, “Weight poisoning attacks on pretrained models,” in Proc. 58th Annu. Meet. Assoc. Comput. Linguist. (ACL) . Association for Computational Linguistics, Jul. 2020, pp. 2793–2806. [Online]. Available: https://aclanthology.org/2020.acl-main.249
2020
Earlier work this paper cites.
X. Chen, A. Salem, D. Chen, M. Backes, S. Ma, Q. Shen, Z. Wu, and Y. Zhang, “Badnl: Backdoor attacks against NLP models with semantic-preserving improvements,” in ACSAC ’21: Annual Computer Security Applications Conference, Virtual Event, USA, December 6 - 10, 2021 . ACM, 2021, pp. 554–569. [Online]. Available: https://doi.org/10.1145/3485832.3485837
2021
Earlier work this paper cites.
2021
Earlier work this paper cites.
F. Qi, M. Li, Y. Chen, Z. Zhang, Z. Liu, Y. Wang, and M. Sun, “Hidden killer: Invisible textual backdoor attacks with syntactic trigger,” in Proc. 59th Annu. Meet. Assoc. Comput. Linguist. (ACL) and 11th Int. Joint Conf. Natural Lang. Process. Online: Association for Computational Linguistics, Aug. 2021, pp. 443–453. [Online]. Available: https://aclanthology.org/2021.acl-long.37
2021
Earlier work this paper cites.
F. Qi, Y. Chen, X. Zhang, M. Li, Z. Liu, and M. Sun, “Mind the style of text! adversarial and backdoor attacks based on text style transfer,” in Proc. 2021 Conf. Empirical Methods Nat. Lang. Process. (EMNLP) . Association for Computational Linguistics, Nov. 2021, pp. 4569–4580. [Online]. Available: https://aclanthology.org/2021.emnlp-main.374
2021
Earlier work this paper cites.
2021
Earlier work this paper cites.
L. Shen, S. Ji, X. Zhang, J. Li, J. Chen, J. Shi, C. Fang, J. Yin, and T. Wang, “Backdoor pre-trained models can transfer to all,” in Proc. 2021 ACM SIGSAC Conf. Comput. Commun. Secur. , ser. CCS ’21, 2021, p. 3141–3158. [Online]. Available: https://doi.org/10.1145/3460120.3485370
2021
Earlier work this paper cites.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in 2021 IEEE/CVF International Conference on Computer Vision, ICCV 2021, Montreal, QC, Canada, October 10-17, 2021 . IEEE, 2021, pp. 16 443–16 452. [Online]. Available: https://doi.org/10.1109/ICCV48922.2021.01615
2021
Earlier work this paper cites.
F. Qi, Y. Chen, X. Zhang, M. Li, Z. Liu, and M. Sun, “Mind the style of text! adversarial and backdoor attacks based on text style transfer,” in Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, EMNLP 2021, Virtual Event / Punta Cana, Dominican Republic, 7-11 November, 2021 , M. Moens, X. Huang, L. Specia, and S. W. Yih, Eds. Association for Computational Linguistics, 2021, pp. 4569–4580. [Online]. Available: https://doi.org/10.18653/v1/2021.emnlp-main.374
2021
Earlier work this paper cites.
N. Carlini and A. Terzis, “Poisoning and backdooring contrastive learning,” in The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April 25-29, 2022 . OpenReview.net, 2022. [Online]. Available: https://openreview.net/forum?id=iC4UHbQ01Mp
2022
Earlier work this paper cites.
G. Tao, G. Shen, Y. Liu, S. An, Q. Xu, S. Ma, P. Li, and X. Zhang, “Better trigger inversion optimization in backdoor scanning,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2022, pp. 13 368–13 378
2022
Earlier work this paper cites.
E. J. Hu, yelong shen, P. Wallis, Z. Allen-Zhu, Y. Li, S. Wang, L. Wang, and W. Chen, “Lora: Low-rank adaptation of large language models,” in International Conference on Learning Representations , 2022. [Online]. Available: https://openreview.net/forum?id=nZeVKeeFYf9
2022
Earlier work this paper cites.
2022
Earlier work this paper cites.
2023
Earlier work this paper cites.
2023
Earlier work this paper cites.
A. Wan, E. Wallace, S. Shen, and D. Klein, “Poisoning language models during instruction tuning,” in Proc. Int. Conf. Mach. Learn. (ICML) . PMLR, 2023, pp. 35 413–35 425
2023
Cited alongside, same era.
2023
Cited alongside, same era.
J. Yan, V. Yadav, S. Li, L. Chen, Z. Tang, H. Wang, V. Srinivasan, X. Ren, and H. Jin, “Backdooring instruction-tuned large language models with virtual prompt injection,” in NeurIPS 2023 Workshop on Backdoors in Deep Learning-The Good, the Bad, and the Ugly , 2023
2023
Cited alongside, same era.
H. Liu, C. Li, Y. Li, and Y. J. Lee, “Improved baselines with visual instruction tuning,” pp. 26 286–26 296, 2024. [Online]. Available: https://doi.org/10.1109/CVPR52733.2024.02484
2024
Cited alongside, same era.
2024
Later among the works it cites.
S. Liang, J. Liang, T. Pang, C. Du, A. Liu, E.-C. Chang, and X. Cao, “Revisiting backdoor attacks against large vision-language models from domain shift,” 2024. [Online]. Available: https://api.semanticscholar.org/CorpusID:270764501
2024
Later among the works it cites.
2024
Later among the works it cites.
W. Lyu, J. Yao, S. Gupta, L. Pang, T. Sun, L. Yi, L. Hu, H. Ling, and C. Chen, “Backdooring vision-language models with out-of-distribution data,” in The Thirteenth International Conference on Learning Representations , 2025. [Online]. Available: https://openreview.net/forum?id=tZozeR3VV7
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2024
Cited alongside, same era.
Meta, “Llama 3.2: Revolutionizing edge ai and vision with open, customizable models,” 2024. [Online]. Available: https://ai.meta.com/blog/llama-3-2-connect-2024-vision-edge-mobile-devices/
2024
Cited alongside, same era.
2024
Cited alongside, same era.
W. Lyu, L. Pang, T. Ma, H. Ling, and C. Chen, “Trojvlm: Backdoor attack against vision language models,” in Computer Vision - ECCV 2024 - 18th European Conference, Milan, Italy, September 29-October 4, 2024, Proceedings, Part LXV , ser. Lecture Notes in Computer Science, vol. 15123. Springer, 2024, pp. 467–483. [Online]. Available: https://doi.org/10.1007/978-3-031-73650-6_27
2024
Cited alongside, same era.
Y. Xu, J. Yao, M. Shu, Y. Sun, Z. Wu, N. Yu, T. Goldstein, and F. Huang, “Shadowcast: Stealthy data poisoning attacks against vision-language models,” in The Thirty-eighth Annual Conference on Neural Information Processing Systems , 2024. [Online]. Available: https://openreview.net/forum?id=JhqyeppMiD
2024
Cited alongside, same era.
2024
Cited alongside, same era.
R. Zhao, Q. Yuan, J. Li, Y. Fan, Y. Li, and F. Gao, “Drivellava: Human-level behavior decisions via vision language model,” Sensors , vol. 24, no. 13, 2024. [Online]. Available: https://www.mdpi.com/1424-8220/24/13/4113
2024
Cited alongside, same era.
2024
Cited alongside, same era.
2025
Closest in time.
2025
Closest in time.
G. Shen, S. Cheng, Z. Zhang, G. Tao, K. Zhang, H. Guo, L. Yan, X. Jin, S. An, S. Ma, and X. Zhang, “Bait: Large language model backdoor scanning by inverting attack target,” in Proceedings of the 46th IEEE Symposium on Security and Privacy . IEEE Computer Society, 2025
2025
Closest in time.
Google, “Gemini 2.0 flash,” 2025. [Online]. Available: https://cloud.google.com/vertex-ai/generative-ai/docs/models/gemini/2-0-flash
2025
Closest in time.
Microsoft, “azure-open-dataset,” 2025. [Online]. Available: https://azure.microsoft.com/en-us/products/open-datasets
2025
Closest in time.
H. Face, “huggingface-dataset,” 2025. [Online]. Available: https://huggingface.co/datasets
2025
Closest in time.
2025
Closest in time.
2025
Closest in time.
Y. Huang, J. Huang, Y. Liu, M. Yan, J. Lv, J. Liu, W. Xiong, H. Zhang, L. Cao, and S. Chen, “Diffusion model-based image editing: A survey,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 47, no. 6, p. 4409–4437, Jun. 2025. [Online]. Available: http://dx.doi.org/10.1109/TPAMI.2025.3541625
2025
Closest in time.
Qwen, “Qwen2.5-vl,” 2025. [Online]. Available: https://huggingface.co/Qwen/Qwen2.5-VL-7B-Instruct
2025
Closest in time.
Google, “Gemma 3-4b,” 2025. [Online]. Available: https://huggingface.co/google/gemma-3-4b-it
2025
Closest in time.
——, “Gemma 3-12b,” 2025. [Online]. Available: https://huggingface.co/google/gemma-3-12b-it
2025
Closest in time.
2025
Closest in time.
H. Liu, C. Li, Y. Li, and Y. J. Lee, “Llava-1.5,” 2025. [Online]. Available: https://huggingface.co/llava-hf/llava-1.5-7b-hf
2025
Closest in time.
Qwen, “Qwen2-vl,” 2025. [Online]. Available: https://huggingface.co/collections/Qwen/qwen2-vl-66cee7455501d7126940800d
2025
Closest in time.
Meta, “Llama 3.2-vision,” 2025. [Online]. Available: https://huggingface.co/meta-llama/Llama-3.2-11B-Vision-Instruct
2025
Closest in time.
J. Zheng, T. Hu, T. Cong, and X. He, “Cl-attack: Textual backdoor attacks via cross-lingual triggers,” in AAAI-25, Sponsored by the Association for the Advancement of Artificial Intelligence, February 25 - March 4, 2025, Philadelphia, PA, USA , T. Walsh, J. Shah, and Z. Kolter, Eds. AAAI Press, 2025, pp. 26 427–26 435. [Online]. Available: https://doi.org/10.1609/aaai.v39i25.34842
2025
Closest in time.
2025
Closest in time.
2025
Closest in time.