{"id":"https://openalex.org/W4412376949","doi":"https://doi.org/10.1145/3726302.3730056","title":"Document Screenshot Retrievers are Vulnerable to Pixel Poisoning Attacks","display_name":"Document Screenshot Retrievers are Vulnerable to Pixel Poisoning Attacks","publication_year":2025,"publication_date":"2025-07-13","ids":{"openalex":"https://openalex.org/W4412376949","doi":"https://doi.org/10.1145/3726302.3730056"},"language":"en","primary_location":{"id":"doi:10.1145/3726302.3730056","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3726302.3730056","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3726302.3730056","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3726302.3730056","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5012958162","display_name":"Shengyao Zhuang","orcid":"https://orcid.org/0000-0002-6711-0955"},"institutions":[{"id":"https://openalex.org/I1292875679","display_name":"Commonwealth Scientific and Industrial Research Organisation","ror":"https://ror.org/03qn8fb07","country_code":"AU","type":"government","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Shengyao Zhuang","raw_affiliation_strings":["CSIRO, Brisbane, QLD, Australia"],"raw_orcid":"https://orcid.org/0000-0002-6711-0955","affiliations":[{"raw_affiliation_string":"CSIRO, Brisbane, QLD, Australia","institution_ids":["https://openalex.org/I1292875679"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102951469","display_name":"Ekaterina Khramtsova","orcid":"https://orcid.org/0000-0001-7531-4491"},"institutions":[{"id":"https://openalex.org/I165143802","display_name":"The University of Queensland","ror":"https://ror.org/00rqy9422","country_code":"AU","type":"education","lineage":["https://openalex.org/I165143802"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Ekaterina Khramtsova","raw_affiliation_strings":["The University of Queensland, Brisbane, QLD, Australia"],"raw_orcid":"https://orcid.org/0000-0001-7531-4491","affiliations":[{"raw_affiliation_string":"The University of Queensland, Brisbane, QLD, Australia","institution_ids":["https://openalex.org/I165143802"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021623012","display_name":"Xueguang Ma","orcid":"https://orcid.org/0000-0003-3430-4910"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Xueguang Ma","raw_affiliation_strings":["University of Waterloo, Waterloo, ON, Canada"],"raw_orcid":"https://orcid.org/0000-0003-3430-4910","affiliations":[{"raw_affiliation_string":"University of Waterloo, Waterloo, ON, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087733750","display_name":"Bevan Koopman","orcid":"https://orcid.org/0000-0001-5577-3391"},"institutions":[{"id":"https://openalex.org/I165143802","display_name":"The University of Queensland","ror":"https://ror.org/00rqy9422","country_code":"AU","type":"education","lineage":["https://openalex.org/I165143802"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Bevan Koopman","raw_affiliation_strings":["CSIRO, Brisbane, QLD, Australia and The University of Queensland, Brisbane, QLD, Australia"],"raw_orcid":"https://orcid.org/0000-0001-5577-3391","affiliations":[{"raw_affiliation_string":"CSIRO, Brisbane, QLD, Australia and The University of Queensland, Brisbane, QLD, Australia","institution_ids":["https://openalex.org/I165143802"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082997975","display_name":"Jimmy Lin","orcid":"https://orcid.org/0000-0002-0661-7189"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Jimmy Lin","raw_affiliation_strings":["University of Waterloo, Waterloo, ON, Canada"],"raw_orcid":"https://orcid.org/0000-0002-0661-7189","affiliations":[{"raw_affiliation_string":"University of Waterloo, Waterloo, ON, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5076031002","display_name":"Guido Zuccon","orcid":"https://orcid.org/0000-0003-0271-5563"},"institutions":[{"id":"https://openalex.org/I165143802","display_name":"The University of Queensland","ror":"https://ror.org/00rqy9422","country_code":"AU","type":"education","lineage":["https://openalex.org/I165143802"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Guido Zuccon","raw_affiliation_strings":["The University of Queensland, Brisbane, QLD, Australia"],"raw_orcid":"https://orcid.org/0000-0003-0271-5563","affiliations":[{"raw_affiliation_string":"The University of Queensland, Brisbane, QLD, Australia","institution_ids":["https://openalex.org/I165143802"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5012958162"],"corresponding_institution_ids":["https://openalex.org/I1292875679"],"apc_list":null,"apc_paid":null,"fwci":2.2665,"has_fulltext":true,"cited_by_count":2,"citation_normalized_percentile":{"value":0.8886574,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"414","last_page":"423"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9962999820709229,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9886999726295471,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.49842095375061035},{"id":"https://openalex.org/keywords/pixel","display_name":"Pixel","score":0.45034146308898926},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.23050659894943237}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.49842095375061035},{"id":"https://openalex.org/C160633673","wikidata":"https://www.wikidata.org/wiki/Q355198","display_name":"Pixel","level":2,"score":0.45034146308898926},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.23050659894943237}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3726302.3730056","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3726302.3730056","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3726302.3730056","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3726302.3730056","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3726302.3730056","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3726302.3730056","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320334593","display_name":"Natural Sciences and Engineering Research Council of Canada","ror":"https://ror.org/01h531d29"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4412376949.pdf","grobid_xml":"https://content.openalex.org/works/W4412376949.grobid-xml"},"referenced_works_count":13,"referenced_works":["https://openalex.org/W2799194071","https://openalex.org/W2912924812","https://openalex.org/W3021397474","https://openalex.org/W3157758108","https://openalex.org/W3171288285","https://openalex.org/W4281486913","https://openalex.org/W4384823501","https://openalex.org/W4389519591","https://openalex.org/W4389520346","https://openalex.org/W4389921502","https://openalex.org/W4404782721","https://openalex.org/W4405143982","https://openalex.org/W6826995673"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"Recent":[0],"advancements":[1],"in":[2,91,130,138],"dense":[3],"retrieval":[4,75],"have":[5],"introduced":[6],"vision-language":[7,139],"model":[8],"(VLM)-based":[9],"retrievers,":[10],"such":[11],"as":[12,21],"DSE":[13,95],"and":[14,27,51,59,96],"ColPali,":[15],"which":[16],"leverage":[17],"document":[18],"screenshots":[19],"embedded":[20],"vectors":[22],"to":[23,47],"enable":[24],"effective":[25],"search":[26,80],"offer":[28],"a":[29,69,116],"simplified":[30],"pipeline":[31],"over":[32],"traditional":[33],"text-only":[34,111],"methods.":[35],"In":[36],"this":[37,141],"study,":[38],"we":[39],"propose":[40],"three":[41],"pixel":[42],"poisoning":[43,82],"attack":[44,57,123],"methods":[45],"designed":[46],"compromise":[48],"VLM-based":[49],"retrievers":[50],"evaluate":[52],"their":[53,149],"effectiveness":[54],"under":[55],"various":[56],"settings":[58],"parameter":[60],"configurations.":[61],"Our":[62],"empirical":[63],"results":[64],"demonstrate":[65],"that":[66],"injecting":[67],"even":[68],"single":[70],"adversarial":[71],"screenshot":[72],"into":[73],"the":[74,83,92,122,135,144],"corpus":[76],"can":[77],"significantly":[78],"disrupt":[79],"results,":[81],"top-10":[84],"retrieved":[85],"documents":[86],"for":[87,98],"41.9%":[88],"of":[89,94,119],"queries":[90],"case":[93],"26.4%":[97],"ColPali.":[99],"These":[100],"vulnerability":[101],"rates":[102],"notably":[103],"exceed":[104],"those":[105],"observed":[106],"with":[107,148],"equivalent":[108],"attacks":[109],"on":[110],"retrievers.":[112],"Moreover,":[113],"when":[114],"targeting":[115],"small":[117],"set":[118],"known":[120],"queries,":[121],"success":[124,129],"rate":[125],"raises,":[126],"achieving":[127],"complete":[128],"certain":[131],"cases.":[132],"By":[133],"exposing":[134],"vulnerabilities":[136],"inherent":[137],"models,":[140],"work":[142],"highlights":[143],"potential":[145],"risks":[146],"associated":[147],"deployment.":[150]},"counts_by_year":[{"year":2025,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
