{"id":"https://openalex.org/W7160327541","doi":"https://doi.org/10.48550/arxiv.2605.02202","title":"CBV: Clean-label Backdoor Attacks on Vision Language Models via Diffusion Models","display_name":"CBV: Clean-label Backdoor Attacks on Vision Language Models via Diffusion Models","publication_year":2026,"publication_date":"2026-05-04","ids":{"openalex":"https://openalex.org/W7160327541","doi":"https://doi.org/10.48550/arxiv.2605.02202"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2605.02202","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.02202","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2605.02202","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5135315812","display_name":"Ji Guo","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Guo, Ji","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135360656","display_name":"Xiaolong Qin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Qin, Xiaolong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135357599","display_name":"Cencen Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Cencen","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043163390","display_name":"Jielei Wang","orcid":"https://orcid.org/0000-0003-2882-7053"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Jielei","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135304687","display_name":"Jierun Chen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Jierun","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5135409470","display_name":"Wenbo Jiang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jiang, Wenbo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.4537000060081482,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.4537000060081482,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.29109999537467957,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.08619999885559082,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.992900013923645},{"id":"https://openalex.org/keywords/closed-captioning","display_name":"Closed captioning","score":0.6116999983787537},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5134999752044678},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4772999882698059},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.4341999888420105},{"id":"https://openalex.org/keywords/natural-language","display_name":"Natural language","score":0.3222000002861023}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.992900013923645},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.777999997138977},{"id":"https://openalex.org/C157657479","wikidata":"https://www.wikidata.org/wiki/Q2367247","display_name":"Closed captioning","level":3,"score":0.6116999983787537},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5821999907493591},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5134999752044678},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4772999882698059},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.4341999888420105},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3292999863624573},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.3222000002861023},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.32100000977516174},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3046000003814697},{"id":"https://openalex.org/C44291984","wikidata":"https://www.wikidata.org/wiki/Q1074173","display_name":"Question answering","level":2,"score":0.2802000045776367},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.27489998936653137},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2678999900817871},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C69357855","wikidata":"https://www.wikidata.org/wiki/Q163214","display_name":"Diffusion","level":2,"score":0.2612999975681305},{"id":"https://openalex.org/C2777402240","wikidata":"https://www.wikidata.org/wiki/Q6783436","display_name":"Masking (illustration)","level":2,"score":0.2542000114917755}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2605.02202","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.02202","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2605.02202","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2605.02202","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-Language":[0],"Models":[1,79],"(VLMs)":[2],"have":[3,27],"achieved":[4],"remarkable":[5],"success":[6],"in":[7],"tasks":[8],"such":[9],"as":[10,19,136],"image":[11,117],"captioning":[12],"and":[13,50,172],"visual":[14,48],"question":[15],"answering":[16],"(VQA).":[17],"However,":[18],"their":[20],"applications":[21],"become":[22],"increasingly":[23],"widespread,":[24],"recent":[25],"studies":[26],"revealed":[28],"that":[29,114,151],"VLMs":[30,40,76],"are":[31],"vulnerable":[32],"to":[33,63,85,107,142,154],"backdoor":[34,37],"attacks.":[35],"Existing":[36],"attacks":[38],"on":[39,43,75,170],"primarily":[41],"rely":[42],"data":[44],"poisoning":[45],"by":[46],"adding":[47],"triggers":[49],"modifying":[51],"text":[52],"labels,":[53],"where":[54],"the":[55,71,96,99,104,109,122,125,129,133,156,163],"induced":[56],"image-text":[57],"mismatch":[58],"makes":[59],"poisoned":[60,88,112],"samples":[61,113],"easy":[62],"detect.":[64],"To":[65,119],"address":[66],"this":[67],"limitation,":[68],"we":[69,127,145],"propose":[70],"Clean-Label":[72],"Backdoor":[73],"Attack":[74],"via":[77,90],"Diffusion":[78],"(CBV),":[80],"which":[81],"leverages":[82],"diffusion":[83,105],"models":[84],"generate":[86],"natural":[87],"examples":[89],"score":[91,97],"matching.":[92],"Specifically,":[93],"CBV":[94],"modifies":[95],"during":[98,139],"reverse":[100],"generation":[101,110],"process":[102],"of":[103,111,124,132],"model":[106],"guide":[108],"contain":[115],"triggered":[116,134],"features.":[118],"further":[120],"enhance":[121,143],"effectiveness":[123],"attack,":[126],"incorporate":[128],"textual":[130],"information":[131],"images":[135],"multimodal":[137],"guidance":[138],"generation.":[140],"Moreover,":[141],"stealthiness,":[144],"introduce":[146],"a":[147],"GradCAM-guided":[148],"Mask":[149],"(GM)":[150],"restricts":[152],"modifications":[153],"only":[155],"most":[157],"semantically":[158],"important":[159],"regions,":[160],"rather":[161],"than":[162],"entire":[164],"image.":[165],"We":[166],"evaluate":[167],"our":[168],"method":[169],"MSCOCO":[171],"VQA":[173],"v2":[174],"with":[175],"four":[176],"representative":[177],"VLMs,":[178],"achieving":[179],"over":[180],"80%":[181],"ASR":[182],"while":[183],"preserving":[184],"normal":[185],"functionality.":[186]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-06T00:00:00"}
