{"id":"https://openalex.org/W7155098287","doi":"https://doi.org/10.48550/arxiv.2604.17318","title":"When Background Matters: Breaking Medical Vision Language Models by Transferable Attack","display_name":"When Background Matters: Breaking Medical Vision Language Models by Transferable Attack","publication_year":2026,"publication_date":"2026-04-19","ids":{"openalex":"https://openalex.org/W7155098287","doi":"https://doi.org/10.48550/arxiv.2604.17318"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.17318","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.17318","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.17318","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5109494520","display_name":"Akash Ghosh","orcid":"https://orcid.org/0009-0001-9353-7258"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ghosh, Akash","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5123464813","display_name":"Subhadip Baidya","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Baidya, Subhadip","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5134207231","display_name":"Sriparna Saha","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Saha, Sriparna","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5134179726","display_name":"Xiuying Chen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Xiuying","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.933899998664856,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.933899998664856,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11775","display_name":"COVID-19 diagnosis using AI","score":0.019500000402331352,"subfield":{"id":"https://openalex.org/subfields/2741","display_name":"Radiology, Nuclear Medicine and Imaging"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.007899999618530273,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7889000177383423},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6021999716758728},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.5866000056266785},{"id":"https://openalex.org/keywords/medical-diagnosis","display_name":"Medical diagnosis","score":0.5095000267028809},{"id":"https://openalex.org/keywords/modalities","display_name":"Modalities","score":0.49900001287460327},{"id":"https://openalex.org/keywords/natural-language","display_name":"Natural language","score":0.4043000042438507},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.37630000710487366}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7889000177383423},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.73089998960495},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6021999716758728},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.5866000056266785},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5184999704360962},{"id":"https://openalex.org/C534262118","wikidata":"https://www.wikidata.org/wiki/Q177719","display_name":"Medical diagnosis","level":2,"score":0.5095000267028809},{"id":"https://openalex.org/C2779903281","wikidata":"https://www.wikidata.org/wiki/Q6888026","display_name":"Modalities","level":2,"score":0.49900001287460327},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.4043000042438507},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.37630000710487366},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37560001015663147},{"id":"https://openalex.org/C2776378700","wikidata":"https://www.wikidata.org/wiki/Q3030775","display_name":"Distraction","level":2,"score":0.36980000138282776},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.34470000863075256},{"id":"https://openalex.org/C31601959","wikidata":"https://www.wikidata.org/wiki/Q931309","display_name":"Medical imaging","level":2,"score":0.30979999899864197},{"id":"https://openalex.org/C89611455","wikidata":"https://www.wikidata.org/wiki/Q6804646","display_name":"Mechanism (biology)","level":2,"score":0.3075000047683716},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.29910001158714294},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.29820001125335693},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.27889999747276306},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.27720001339912415},{"id":"https://openalex.org/C3017944768","wikidata":"https://www.wikidata.org/wiki/Q1450463","display_name":"Poison control","level":2,"score":0.2646999955177307},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.2637999951839447}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.17318","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.17318","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"Preprint"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.17318","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.17318","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Preprint"},"sustainable_development_goals":[{"score":0.5285892486572266,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-Language":[0],"Models":[1],"(VLMs)":[2],"are":[3],"increasingly":[4],"used":[5],"in":[6,140],"clinical":[7,146],"diagnostics,":[8],"yet":[9,64,111],"their":[10],"robustness":[11],"to":[12,87],"adversarial":[13,33],"attacks":[14,23,37],"remains":[15],"largely":[16],"unexplored,":[17],"posing":[18],"serious":[19],"risks.":[20],"Existing":[21],"medical":[22,100],"focus":[24,91],"on":[25],"secondary":[26],"objectives":[27],"such":[28],"as":[29],"model":[30],"stealing":[31],"or":[32],"fine-tuning,":[34],"while":[35,68],"transferable":[36,57],"from":[38,93],"natural":[39],"images":[40],"introduce":[41,120],"visible":[42],"distortions":[43],"that":[44,61,104,128],"clinicians":[45],"can":[46],"easily":[47],"detect.":[48],"To":[49],"address":[50],"this,":[51],"we":[52],"propose":[53],"MedFocusLeak,":[54],"a":[55,121,137],"highly":[56],"black-box":[58],"multimodal":[59],"attack":[60,131],"induces":[62],"incorrect":[63],"clinically":[65],"plausible":[66],"diagnoses":[67],"keeping":[69],"perturbations":[70,76],"imperceptible.":[71],"The":[72],"method":[73],"injects":[74],"coordinated":[75],"into":[77],"non-diagnostic":[78],"background":[79],"regions":[80],"and":[81,133],"employs":[82],"an":[83],"attention":[84],"distraction":[85],"mechanism":[86],"shift":[88],"the":[89,141],"model's":[90],"away":[92],"pathological":[94],"areas.":[95],"Extensive":[96],"evaluations":[97],"across":[98,115],"six":[99],"imaging":[101],"modalities":[102],"show":[103],"MedFocusLeak":[105],"achieves":[106],"state-of-the-art":[107],"performance,":[108],"generating":[109],"misleading":[110],"realistic":[112],"diagnostic":[113],"outputs":[114],"diverse":[116],"VLMs.":[117,147],"We":[118],"further":[119],"unified":[122],"evaluation":[123],"framework":[124],"with":[125],"novel":[126],"metrics":[127],"jointly":[129],"capture":[130],"success":[132],"image":[134],"fidelity,":[135],"revealing":[136],"critical":[138],"weakness":[139],"reasoning":[142],"capabilities":[143],"of":[144],"modern":[145]},"counts_by_year":[],"updated_date":"2026-07-01T08:55:40.977307","created_date":"2026-04-22T00:00:00"}
