{"id":"https://openalex.org/W4413144633","doi":"https://doi.org/10.1109/cvpr52734.2025.00885","title":"Revisiting Backdoor Attacks against Large Vision-Language Models from Domain Shift","display_name":"Revisiting Backdoor Attacks against Large Vision-Language Models from Domain Shift","publication_year":2025,"publication_date":"2025-06-10","ids":{"openalex":"https://openalex.org/W4413144633","doi":"https://doi.org/10.1109/cvpr52734.2025.00885"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr52734.2025.00885","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52734.2025.00885","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048901827","display_name":"Siyuan Liang","orcid":"https://orcid.org/0000-0002-6474-5859"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Siyuan Liang","raw_affiliation_strings":["Nanyang Technological University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Nanyang Technological University","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004005455","display_name":"Jiawei Liang","orcid":"https://orcid.org/0000-0003-0748-3183"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiawei Liang","raw_affiliation_strings":["Shenzhen Campus of Sun Yat-Sen University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shenzhen Campus of Sun Yat-Sen University","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5093836321","display_name":"Tianyu Pang","orcid":null},"institutions":[{"id":"https://openalex.org/I131787340","display_name":"Seagate (United States)","ror":"https://ror.org/04p1xtv71","country_code":"US","type":"company","lineage":["https://openalex.org/I131787340"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tianyu Pang","raw_affiliation_strings":["Sea AI Lab,Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sea AI Lab,Singapore","institution_ids":["https://openalex.org/I131787340"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111661827","display_name":"Chao Du","orcid":null},"institutions":[{"id":"https://openalex.org/I131787340","display_name":"Seagate (United States)","ror":"https://ror.org/04p1xtv71","country_code":"US","type":"company","lineage":["https://openalex.org/I131787340"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chao Du","raw_affiliation_strings":["Sea AI Lab,Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Sea AI Lab,Singapore","institution_ids":["https://openalex.org/I131787340"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014870180","display_name":"Aishan Liu","orcid":"https://orcid.org/0000-0002-4224-1318"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Aishan Liu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5120017279","display_name":"Mingli Zhu","orcid":"https://orcid.org/0000-0002-6412-1755"},"institutions":[{"id":"https://openalex.org/I4210116924","display_name":"Chinese University of Hong Kong, Shenzhen","ror":"https://ror.org/02d5ks197","country_code":"CN","type":"education","lineage":["https://openalex.org/I177725633","https://openalex.org/I180726961","https://openalex.org/I4210116924"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mingli Zhu","raw_affiliation_strings":["The Chinese University of Hong Kong,Shenzhen"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The Chinese University of Hong Kong,Shenzhen","institution_ids":["https://openalex.org/I4210116924"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068837264","display_name":"Xiaochun Cao","orcid":"https://orcid.org/0000-0001-7141-708X"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaochun Cao","raw_affiliation_strings":["Shenzhen Campus of Sun Yat-Sen University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Shenzhen Campus of Sun Yat-Sen University","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5074103823","display_name":"Dacheng Tao","orcid":"https://orcid.org/0000-0001-7225-5449"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Dacheng Tao","raw_affiliation_strings":["Nanyang Technological University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Nanyang Technological University","institution_ids":["https://openalex.org/I172675005"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":8,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":8.7939,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.97467864,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"9477","last_page":"9486"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T13702","display_name":"Machine Learning in Healthcare","score":0.8582000136375427,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T13702","display_name":"Machine Learning in Healthcare","score":0.8582000136375427,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8382999897003174,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.8197000026702881,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.986885666847229},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6223642826080322},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5057244300842285},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.4729081094264984},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3976103663444519},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.3431680202484131},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.09203273057937622}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.986885666847229},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6223642826080322},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5057244300842285},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.4729081094264984},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3976103663444519},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3431680202484131},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.09203273057937622},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cvpr52734.2025.00885","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52734.2025.00885","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320307938","display_name":"NCR","ror":"https://ror.org/00nqjkj48"},{"id":"https://openalex.org/F4320320671","display_name":"National Research Foundation","ror":"https://ror.org/05s0g1g46"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4401407399","https://openalex.org/W3204019825"],"abstract_inverted_index":{"Instruction":[0],"tuning":[1,33],"enhances":[2,100],"large":[3],"vision-language":[4],"models":[5],"(LVLMs)":[6],"but":[7],"increases":[8],"their":[9,16],"vulnerability":[10],"to":[11,15,49,97,175],"backdoor":[12,28,46,65,112,169],"attacks":[13,29],"due":[14],"open":[17],"design.":[18],"Unlike":[19],"prior":[20],"studies":[21],"in":[22,30,162],"static":[23],"settings,":[24],"this":[25],"paper":[26],"explores":[27],"LVLM":[31],"instruction":[32],"across":[34],"mismatched":[35],"training":[36],"and":[37,55,81,89,129,165],"testing":[38],"domains.":[39],"We":[40],"introduce":[41],"a":[42,109,149,154,172],"new":[43],"evaluation":[44],"dimension,":[45],"domain":[47,57],"generalization,":[48],"assess":[50],"attack":[51,101,113,137],"robustness":[52],"under":[53],"visual":[54],"text":[56],"shifts.":[58],"Our":[59,182],"findings":[60],"reveal":[61],"two":[62],"insights:":[63],"(1)":[64],"generalizability":[66,170],"improves":[67],"when":[68],"distinctive":[69],"trigger":[70,87],"patterns":[71,88],"are":[72,184],"independent":[73],"of":[74,140],"specific":[75],"data":[76,180],"domains":[77],"or":[78],"model":[79,96],"architectures,":[80],"(2)":[82],"the":[83,95,136,145],"competitive":[84],"interaction":[85],"between":[86],"clean":[90],"semantic":[91],"regions,":[92],"where":[93],"guiding":[94],"predict":[98],"triggers":[99,118],"generalizability.":[102],"Based":[103],"on":[104],"these":[105],"insights,":[106],"we":[107],"propose":[108],"multimodal":[110],"attribution":[111],"(MABA)":[114],"that":[115,132],"injects":[116],"domain-agnostic":[117],"into":[119],"critical":[120],"areas":[121],"using":[122],"attributional":[123],"interpretation.":[124],"Experiments":[125],"with":[126],"OpenFlamingo,":[127],"Blip-2,":[128],"Otter":[130],"show":[131],"MABA":[133],"significantly":[134],"boosts":[135],"success":[138,151],"rate":[139,152],"generalization":[141],"by":[142],"36.4%":[143],"over":[144],"unimodal":[146],"attack,":[147],"achieving":[148],"97%":[150],"at":[153],"0.2%":[155],"poisoning":[156],"rate.":[157],"This":[158],"study":[159],"reveals":[160],"limitations":[161],"current":[163],"evaluations":[164],"highlights":[166],"how":[167],"enhanced":[168],"poses":[171],"security":[173],"threat":[174],"LVLMs,":[176],"even":[177],"without":[178],"test":[179],"access.":[181],"codes":[183],"available":[185],"online<sup":[186],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[187],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>.":[188]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
