{"id":"https://openalex.org/W7147233181","doi":"https://doi.org/10.48550/arxiv.2603.27240","title":"Diagnosing and Repairing Unsafe Channels in Vision-Language Models via Causal Discovery and Dual-Modal Safety Subspace Projection","display_name":"Diagnosing and Repairing Unsafe Channels in Vision-Language Models via Causal Discovery and Dual-Modal Safety Subspace Projection","publication_year":2026,"publication_date":"2026-03-28","ids":{"openalex":"https://openalex.org/W7147233181","doi":"https://doi.org/10.48550/arxiv.2603.27240"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.27240","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.27240","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.27240","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5078503620","display_name":"Jinhu Fu","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Fu, Jinhu","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063901345","display_name":"Yihang Lou","orcid":"https://orcid.org/0000-0002-8143-389X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lou, Yihang","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5132595163","display_name":"Qingyi Si","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Si, Qingyi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5132547969","display_name":"Shudong Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Shudong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5132688345","display_name":"Yan Bai","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bai, Yan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5132547539","display_name":"Sen Su","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Su, Sen","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5078503620"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.4440999925136566,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.4440999925136566,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.3239000141620636,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.09019999951124191,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6401000022888184},{"id":"https://openalex.org/keywords/linear-subspace","display_name":"Linear subspace","score":0.6155999898910522},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.5760999917984009},{"id":"https://openalex.org/keywords/projection","display_name":"Projection (relational algebra)","score":0.4880000054836273},{"id":"https://openalex.org/keywords/modalities","display_name":"Modalities","score":0.3188000023365021},{"id":"https://openalex.org/keywords/visualization","display_name":"Visualization","score":0.31839999556541443},{"id":"https://openalex.org/keywords/modality","display_name":"Modality (human\u2013computer interaction)","score":0.31769999861717224}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7275999784469604},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6401000022888184},{"id":"https://openalex.org/C12362212","wikidata":"https://www.wikidata.org/wiki/Q728435","display_name":"Linear subspace","level":2,"score":0.6155999898910522},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.5760999917984009},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5515999794006348},{"id":"https://openalex.org/C57493831","wikidata":"https://www.wikidata.org/wiki/Q3134666","display_name":"Projection (relational algebra)","level":2,"score":0.4880000054836273},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36419999599456787},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.3188000023365021},{"id":"https://openalex.org/C36464697","wikidata":"https://www.wikidata.org/wiki/Q451553","display_name":"Visualization","level":2,"score":0.31839999556541443},{"id":"https://openalex.org/C2780226545","wikidata":"https://www.wikidata.org/wiki/Q6888030","display_name":"Modality (human\u2013computer interaction)","level":2,"score":0.31769999861717224},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3165999948978424},{"id":"https://openalex.org/C89611455","wikidata":"https://www.wikidata.org/wiki/Q6804646","display_name":"Mechanism (biology)","level":2,"score":0.30809998512268066},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.29789999127388},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.27709999680519104},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.27309998869895935},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.26019999384880066},{"id":"https://openalex.org/C33676613","wikidata":"https://www.wikidata.org/wiki/Q13415176","display_name":"Dimension (graph theory)","level":2,"score":0.2574999928474426},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.257099986076355},{"id":"https://openalex.org/C11671645","wikidata":"https://www.wikidata.org/wiki/Q5054567","display_name":"Causal model","level":2,"score":0.2535000145435333}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.27240","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.27240","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.27240","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.27240","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"score":0.5744500756263733,"display_name":"Quality Education","id":"https://metadata.un.org/sdg/4"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Large":[0],"Vision-Language":[1],"Models":[2],"(LVLMs)":[3],"have":[4],"achieved":[5],"impressive":[6],"performance":[7],"across":[8],"multimodal":[9,139],"understanding":[10],"and":[11,21,34,50,79,87,109,145],"reasoning":[12],"tasks,":[13],"yet":[14],"their":[15],"internal":[16],"safety":[17,67,74,98,124,134],"mechanisms":[18],"remain":[19],"opaque":[20],"poorly":[22],"controlled.":[23],"In":[24],"this":[25],"work,":[26],"we":[27,63],"present":[28],"a":[29,65,101],"comprehensive":[30],"framework":[31,131],"for":[32,56,76],"diagnosing":[33],"repairing":[35],"unsafe":[36,57,114],"channels":[37],"within":[38],"LVLMs":[39],"(CARE).":[40],"We":[41],"first":[42],"perform":[43],"causal":[44],"mediation":[45],"analysis":[46],"to":[47],"identify":[48],"neurons":[49],"layers":[51],"that":[52,71,105,127],"are":[53,93],"causally":[54],"responsible":[55],"behaviors.":[58],"Based":[59],"on":[60,122],"these":[61,97],"findings,":[62],"introduce":[64],"dual-modal":[66],"subspace":[68],"projection":[69],"method":[70,150],"learns":[72],"generalized":[73,83],"subspaces":[75,99],"both":[77],"visual":[78,108],"textual":[80,110],"modalities":[81],"through":[82],"eigen-decomposition":[84],"between":[85],"benign":[86],"malicious":[88],"activations.":[89],"During":[90],"inference,":[91],"activations":[92],"dynamically":[94],"projected":[95],"toward":[96],"via":[100],"hybrid":[102],"fusion":[103],"mechanism":[104],"adaptively":[106],"balances":[107],"corrections,":[111],"effectively":[112],"suppressing":[113],"features":[115],"while":[116],"preserving":[117],"semantic":[118],"fidelity.":[119],"Extensive":[120],"experiments":[121],"multiple":[123],"benchmarks":[125],"demonstrate":[126],"our":[128,149],"causal-subspace":[129],"repair":[130],"significantly":[132],"enhances":[133],"robustness":[135],"without":[136],"degrading":[137],"general":[138],"capabilities,":[140],"outperforming":[141],"prior":[142],"activation":[143],"steering":[144],"alignment-based":[146],"baselines.":[147],"Additionally,":[148],"exhibits":[151],"good":[152],"transferability,":[153],"defending":[154],"against":[155],"unseen":[156],"attacks.":[157]},"counts_by_year":[],"updated_date":"2026-04-02T13:53:19.096889","created_date":"2026-04-02T00:00:00"}
