{"id":"https://openalex.org/W4403791703","doi":"https://doi.org/10.1145/3664647.3680779","title":"Break the Visual Perception: Adversarial Attacks Targeting Encoded Visual Tokens of Large Vision-Language Models","display_name":"Break the Visual Perception: Adversarial Attacks Targeting Encoded Visual Tokens of Large Vision-Language Models","publication_year":2024,"publication_date":"2024-10-26","ids":{"openalex":"https://openalex.org/W4403791703","doi":"https://doi.org/10.1145/3664647.3680779"},"language":"en","primary_location":{"id":"doi:10.1145/3664647.3680779","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3664647.3680779","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 32nd ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5107959424","display_name":"Yubo Wang","orcid":"https://orcid.org/0009-0000-7454-1019"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yubo Wang","raw_affiliation_strings":["State Key Laboratory of Cognitive Intelligence, University of Science and Technology of China, Hefei, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Cognitive Intelligence, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061846588","display_name":"Chaohu Liu","orcid":"https://orcid.org/0009-0001-7588-4264"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chaohu Liu","raw_affiliation_strings":["State Key Laboratory of Cognitive Intelligence, University of Science and Technology of China, Hefei, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Cognitive Intelligence, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051368188","display_name":"Yanqiu Qu","orcid":null},"institutions":[{"id":"https://openalex.org/I2250653659","display_name":"Tencent (China)","ror":"https://ror.org/00hhjss72","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250653659"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yanqiu Qu","raw_affiliation_strings":["Tencent YouTu Lab, Hefei, China"],"affiliations":[{"raw_affiliation_string":"Tencent YouTu Lab, Hefei, China","institution_ids":["https://openalex.org/I2250653659"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024986567","display_name":"Haoyu Cao","orcid":"https://orcid.org/0000-0002-3789-9705"},"institutions":[{"id":"https://openalex.org/I2250653659","display_name":"Tencent (China)","ror":"https://ror.org/00hhjss72","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250653659"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Haoyu Cao","raw_affiliation_strings":["Tencent YouTu Lab, Hefei, China"],"affiliations":[{"raw_affiliation_string":"Tencent YouTu Lab, Hefei, China","institution_ids":["https://openalex.org/I2250653659"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5016912950","display_name":"Deqiang Jiang","orcid":null},"institutions":[{"id":"https://openalex.org/I2250653659","display_name":"Tencent (China)","ror":"https://ror.org/00hhjss72","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250653659"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Deqiang Jiang","raw_affiliation_strings":["Tencent YouTu Lab, Hefei, China"],"affiliations":[{"raw_affiliation_string":"Tencent YouTu Lab, Hefei, China","institution_ids":["https://openalex.org/I2250653659"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009732907","display_name":"Linli Xu","orcid":"https://orcid.org/0000-0003-0227-3793"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Linli Xu","raw_affiliation_strings":["State Key Laboratory of Cognitive Intelligence, University of Science and Technology of China, Hefei, China"],"affiliations":[{"raw_affiliation_string":"State Key Laboratory of Cognitive Intelligence, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5107959424"],"corresponding_institution_ids":["https://openalex.org/I126520041"],"apc_list":null,"apc_paid":null,"fwci":1.8013,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.87710211,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1072","last_page":"1081"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9314000010490417,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9002000093460083,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7984194159507751},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.780575156211853},{"id":"https://openalex.org/keywords/perception","display_name":"Perception","score":0.6596603989601135},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5583046674728394},{"id":"https://openalex.org/keywords/visual-language","display_name":"Visual language","score":0.5242643356323242},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.4755798876285553},{"id":"https://openalex.org/keywords/visual-perception","display_name":"Visual perception","score":0.4683125913143158},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.09119760990142822},{"id":"https://openalex.org/keywords/linguistics","display_name":"Linguistics","score":0.06280776858329773}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7984194159507751},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.780575156211853},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.6596603989601135},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5583046674728394},{"id":"https://openalex.org/C2780878386","wikidata":"https://www.wikidata.org/wiki/Q1659648","display_name":"Visual language","level":2,"score":0.5242643356323242},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.4755798876285553},{"id":"https://openalex.org/C178253425","wikidata":"https://www.wikidata.org/wiki/Q162668","display_name":"Visual perception","level":3,"score":0.4683125913143158},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.09119760990142822},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.06280776858329773},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C169760540","wikidata":"https://www.wikidata.org/wiki/Q207011","display_name":"Neuroscience","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3664647.3680779","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3664647.3680779","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 32nd ACM International Conference on Multimedia","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","display_name":"Reduced inequalities","score":0.550000011920929}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W398859631","https://openalex.org/W1987971958","https://openalex.org/W2150593711","https://openalex.org/W2187089797","https://openalex.org/W2560674852","https://openalex.org/W2746600820","https://openalex.org/W2747329762","https://openalex.org/W2774644650","https://openalex.org/W2963857521","https://openalex.org/W3035031253","https://openalex.org/W3106412272","https://openalex.org/W3143373604","https://openalex.org/W4212774754","https://openalex.org/W4283317927","https://openalex.org/W4366330503","https://openalex.org/W4366850747","https://openalex.org/W4367628410","https://openalex.org/W4375869762","https://openalex.org/W4376312115","https://openalex.org/W4382132560","https://openalex.org/W4385574358","https://openalex.org/W4386076522","https://openalex.org/W4386185600","https://openalex.org/W4390190425","https://openalex.org/W4390874575","https://openalex.org/W4393157467"],"related_works":["https://openalex.org/W1897960459","https://openalex.org/W2002567531","https://openalex.org/W180818492","https://openalex.org/W4212996970","https://openalex.org/W2033349420","https://openalex.org/W243736014","https://openalex.org/W4318185075","https://openalex.org/W2964529313","https://openalex.org/W1974005862","https://openalex.org/W2984197669"],"abstract_inverted_index":{"Large":[0],"vision-language":[1],"models":[2,67],"(LVLMs)":[3],"integrate":[4],"visual":[5,18,59,89,96,139,216],"information":[6],"into":[7,58],"large":[8],"language":[9,66],"models,":[10],"showcasing":[11],"remarkable":[12],"multi-modal":[13],"conversational":[14],"capabilities.":[15],"However,":[16],"the":[17,42,65,87,95,122,135,149,153,156,166,178,183,204,212,215],"modules":[19],"introduces":[20],"new":[21],"challenges":[22],"in":[23,152,191,198,209],"terms":[24,210],"of":[25,124,138,182,206,211,214],"robustness":[26,205],"for":[27,64],"LVLMs,":[28,207],"as":[29,109,132,134],"attackers":[30],"can":[31,200],"craft":[32],"adversarial":[33,116,158],"images":[34,57],"that":[35],"are":[36,62,75,91],"visually":[37],"clean":[38],"but":[39],"may":[40],"mislead":[41],"model":[43],"to":[44,55,68,108,148],"generate":[45,83],"incorrect":[46],"answers.":[47],"In":[48],"general,":[49],"LVLMs":[50,81,164,193],"rely":[51],"on":[52,203],"vision":[53],"encoders":[54],"transform":[56],"tokens,":[60],"which":[61,114,197],"crucial":[63],"perceive":[69],"image":[70,143,150,168,195],"contents":[71],"effectively.":[72],"Therefore,":[73],"we":[74,101],"curious":[76],"about":[77],"one":[78],"question:":[79],"Can":[80],"still":[82],"correct":[84],"responses":[85],"when":[86],"encoded":[88],"tokens":[90,140],"attacked":[92],"and":[93,129,170],"disrupting":[94,126],"information?":[97],"To":[98],"this":[99],"end,":[100],"propose":[102],"a":[103],"non-targeted":[104],"attack":[105,180],"method":[106],"referred":[107],"VT-Attack":[110,184],"(Visual":[111],"Tokens":[112],"Attack),":[113],"constructs":[115],"examples":[117,159],"from":[118],"multiple":[119],"perspectives,":[120],"with":[121,194],"goal":[123],"comprehensively":[125],"feature":[127,217],"representations":[128],"inherent":[130],"relationships":[131],"well":[133],"semantic":[136],"properties":[137],"output":[141],"by":[142],"encoders.":[144],"Using":[145],"only":[146],"access":[147],"encoder":[151,169],"proposed":[154],"attack,":[155],"generated":[157],"exhibit":[160],"transferability":[161],"across":[162,172],"diverse":[163],"utilizing":[165],"same":[167],"generality":[171],"different":[173],"tasks.":[174],"Extensive":[175],"experiments":[176],"validate":[177],"superior":[179],"performance":[181],"over":[185],"baseline":[186],"methods,":[187],"demonstrating":[188],"its":[189],"effectiveness":[190],"attacking":[192],"encoders,":[196],"turn":[199],"provide":[201],"guidance":[202],"particularly":[208],"stability":[213],"space.":[218]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4}],"updated_date":"2026-03-13T16:22:10.518609","created_date":"2025-10-10T00:00:00"}
