{"id":"https://openalex.org/W7147260047","doi":"https://doi.org/10.48550/arxiv.2603.27522","title":"Hidden Ads: Behavior Triggered Semantic Backdoors for Advertisement Injection in Vision Language Models","display_name":"Hidden Ads: Behavior Triggered Semantic Backdoors for Advertisement Injection in Vision Language Models","publication_year":2026,"publication_date":"2026-03-29","ids":{"openalex":"https://openalex.org/W7147260047","doi":"https://doi.org/10.48550/arxiv.2603.27522"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.27522","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.27522","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.27522","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5132611244","display_name":"Duanyi Yao","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Yao, Duanyi","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100572535","display_name":"Changyue Li","orcid":"https://orcid.org/0009-0002-0921-7014"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Changyue","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5132692332","display_name":"Zhicong Huang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Huang, Zhicong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5132542955","display_name":"Cheng Hong","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hong, Cheng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5132550937","display_name":"Songze Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Songze","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5132611244"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.49959999322891235,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.49959999322891235,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.27549999952316284,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.036400001496076584,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9180999994277954},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.694100022315979},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.5396999716758728},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.531499981880188},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.5078999996185303},{"id":"https://openalex.org/keywords/natural-language","display_name":"Natural language","score":0.4221999943256378},{"id":"https://openalex.org/keywords/false-positive-paradox","display_name":"False positive paradox","score":0.38850000500679016},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.38359999656677246},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.37689998745918274},{"id":"https://openalex.org/keywords/abstraction","display_name":"Abstraction","score":0.37459999322891235}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9180999994277954},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8284000158309937},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.694100022315979},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.5396999716758728},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.531499981880188},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.5078999996185303},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5062999725341797},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4934999942779541},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.4221999943256378},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.38850000500679016},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.38359999656677246},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.37689998745918274},{"id":"https://openalex.org/C124304363","wikidata":"https://www.wikidata.org/wiki/Q673661","display_name":"Abstraction","level":2,"score":0.37459999322891235},{"id":"https://openalex.org/C71901391","wikidata":"https://www.wikidata.org/wiki/Q7126699","display_name":"Upload","level":2,"score":0.3702999949455261},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3637000024318695},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.35010001063346863},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.34709998965263367},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.3418000042438507},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.3384000062942505},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.33250001072883606},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.33219999074935913},{"id":"https://openalex.org/C127705205","wikidata":"https://www.wikidata.org/wiki/Q5748245","display_name":"Heuristics","level":2,"score":0.32260000705718994},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.3188000023365021},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.2962999939918518},{"id":"https://openalex.org/C113174947","wikidata":"https://www.wikidata.org/wiki/Q2859736","display_name":"Tree (set theory)","level":2,"score":0.2775999903678894},{"id":"https://openalex.org/C105339364","wikidata":"https://www.wikidata.org/wiki/Q2297740","display_name":"Software deployment","level":2,"score":0.2775000035762787},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.27379998564720154},{"id":"https://openalex.org/C175154964","wikidata":"https://www.wikidata.org/wiki/Q380077","display_name":"Task analysis","level":3,"score":0.2685999870300293},{"id":"https://openalex.org/C2779356469","wikidata":"https://www.wikidata.org/wiki/Q502918","display_name":"Counterfeit","level":2,"score":0.26589998602867126},{"id":"https://openalex.org/C2776608160","wikidata":"https://www.wikidata.org/wiki/Q4785462","display_name":"Natural (archaeology)","level":2,"score":0.2612999975681305},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.25699999928474426},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.25130000710487366}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.27522","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.27522","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.27522","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.27522","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-Language":[0],"Models":[1],"(VLMs)":[2],"are":[3],"increasingly":[4],"deployed":[5],"in":[6,106],"consumer":[7],"applications":[8],"where":[9],"users":[10,61],"seek":[11],"recommendations":[12],"about":[13],"products,":[14],"dining,":[15],"and":[16,73,95,132,188,201],"services.":[17,109],"We":[18,110,195],"introduce":[19],"Hidden":[20,53,119,161],"Ads,":[21],"a":[22,112],"new":[23],"class":[24],"of":[25,67],"backdoor":[26,211],"attacks":[27],"that":[28,41,160,178,205],"exploit":[29],"this":[30],"recommendation-seeking":[31,75],"behavior":[32],"to":[33,116,145,185,190,208],"inject":[34],"unauthorized":[35],"advertisements.":[36],"Unlike":[37],"traditional":[38],"pattern-triggered":[39],"backdoors":[40],"rely":[42],"on":[43,56,155],"artificial":[44],"triggers":[45],"such":[46],"as":[47],"pixel":[48],"patches":[49],"or":[50],"special":[51],"tokens,":[52],"Ads":[54,120,162],"activates":[55],"natural":[57,147],"user":[58],"behaviors:":[59],"when":[60],"upload":[62],"images":[63],"containing":[64],"semantic":[65,152],"content":[66],"interest":[68],"(e.g.,":[69],"food,":[70],"cars,":[71],"animals)":[72],"ask":[74],"questions,":[76],"the":[77,100,179,210],"backdoored":[78],"model":[79,93],"provides":[80],"correct,":[81],"helpful":[82],"answers":[83],"while":[84,171],"seamlessly":[85],"appending":[86],"attacker-specified":[87],"promotional":[88],"slogans.":[89],"This":[90],"design":[91],"preserves":[92],"utility":[94,215],"produces":[96],"natural-sounding":[97],"injections,":[98],"making":[99],"attack":[101,180],"practical":[102],"for":[103],"real-world":[104],"deployment":[105],"consumer-facing":[107],"recommendation":[108],"propose":[111],"multi-tier":[113],"threat":[114],"framework":[115],"systematically":[117],"evaluate":[118,196],"across":[121,150],"three":[122,156],"adversary":[123],"capability":[124],"levels:":[125],"hard":[126],"prompt":[127,130],"injection,":[128],"soft":[129],"optimization,":[131],"supervised":[133],"fine-tuning.":[134],"Our":[135],"poisoned":[136],"data":[137],"generation":[138],"pipeline":[139],"uses":[140],"teacher":[141],"VLM-generated":[142],"chain-of-thought":[143],"reasoning":[144],"create":[146],"trigger--slogan":[148],"associations":[149],"multiple":[151,191],"domains.":[153],"Experiments":[154],"VLM":[157],"architectures":[158],"demonstrate":[159],"achieves":[163],"high":[164],"injection":[165],"efficacy":[166],"with":[167],"near-zero":[168],"false":[169],"positives":[170],"maintaining":[172],"task":[173],"accuracy.":[174],"Ablation":[175],"studies":[176],"confirm":[177],"is":[181],"data-efficient,":[182],"transfers":[183],"effectively":[184],"unseen":[186],"datasets,":[187],"scales":[189],"concurrent":[192],"domain-slogan":[193],"pairs.":[194],"defenses":[197],"including":[198],"instruction-based":[199],"filtering":[200],"clean":[202],"fine-tuning,":[203],"finding":[204],"both":[206],"fail":[207],"remove":[209],"without":[212],"causing":[213],"significant":[214],"degradation.":[216]},"counts_by_year":[],"updated_date":"2026-04-02T13:53:19.096889","created_date":"2026-04-02T00:00:00"}
