Shadowcast: Stealthy Data Poisoning Attacks Against Vision-Language Models

计算机安全 计算机科学 自然语言处理 人工智能
作者
Yuancheng Xu,Jiarui Yao,Manli Shu,Yanchao Sun,Zichu Wu,Ning Yu,Tom Goldstein,Furong Huang
出处
期刊:Cornell University - arXiv 被引量:3
标识
DOI:10.48550/arxiv.2402.06659
摘要

Vision-Language Models (VLMs) excel in generating textual responses from visual inputs, but their versatility raises security concerns. This study takes the first step in exposing VLMs' susceptibility to data poisoning attacks that can manipulate responses to innocuous, everyday prompts. We introduce Shadowcast, a stealthy data poisoning attack where poison samples are visually indistinguishable from benign images with matching texts. Shadowcast demonstrates effectiveness in two attack types. The first is a traditional Label Attack, tricking VLMs into misidentifying class labels, such as confusing Donald Trump for Joe Biden. The second is a novel Persuasion Attack, leveraging VLMs' text generation capabilities to craft persuasive and seemingly rational narratives for misinformation, such as portraying junk food as healthy. We show that Shadowcast effectively achieves the attacker's intentions using as few as 50 poison samples. Crucially, the poisoned samples demonstrate transferability across different VLM architectures, posing a significant concern in black-box settings. Moreover, Shadowcast remains potent under realistic conditions involving various text prompts, training data augmentation, and image compression techniques. This work reveals how poisoned VLMs can disseminate convincing yet deceptive misinformation to everyday, benign users, emphasizing the importance of data integrity for responsible VLM deployments. Our code is available at: https://github.com/umd-huang-lab/VLM-Poisoning.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
思源应助迅速丸子采纳,获得10
1秒前
科先生发布了新的文献求助10
1秒前
1秒前
2秒前
MADKAI发布了新的文献求助20
2秒前
3秒前
丘比特应助珠123采纳,获得10
4秒前
4秒前
小蘑菇应助雷培采纳,获得10
4秒前
量子星尘发布了新的文献求助10
4秒前
5秒前
王了了发布了新的文献求助30
5秒前
woshiwuziq应助潇洒的帽子采纳,获得20
7秒前
67发布了新的文献求助10
8秒前
8秒前
务实珊完成签到,获得积分10
8秒前
xiaobu发布了新的文献求助10
9秒前
虚无完成签到,获得积分10
9秒前
11秒前
11秒前
12秒前
科研通AI6.2应助小马采纳,获得10
12秒前
美好的冰蓝完成签到 ,获得积分10
12秒前
12秒前
14秒前
15秒前
烟花应助刘星宇采纳,获得30
15秒前
67完成签到,获得积分10
16秒前
量子星尘发布了新的文献求助10
16秒前
lxl完成签到,获得积分10
16秒前
16秒前
AneyWinter66应助不吃香菜采纳,获得10
17秒前
17秒前
研友_VZG7GZ应助clio采纳,获得30
17秒前
英姑应助lalllal采纳,获得10
18秒前
结实文昊发布了新的文献求助10
18秒前
迅速丸子发布了新的文献求助10
18秒前
雷培发布了新的文献求助10
19秒前
fan发布了新的文献求助10
20秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Kinesiophobia : a new view of chronic pain behavior 2000
Cytological studies on Phanerogams in Southern Peru. I. Karyotype of Acaena ovalifolia 2000
Earth System Geophysics 1000
Bioseparations Science and Engineering Third Edition 1000
Lloyd's Register of Shipping's Approach to the Control of Incidents of Brittle Fracture in Ship Structures 1000
BRITTLE FRACTURE IN WELDED SHIPS 1000
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6122626
求助须知:如何正确求助?哪些是违规求助? 7950254
关于积分的说明 16494291
捐赠科研通 5244002
什么是DOI,文献DOI怎么找? 2801100
邀请新用户注册赠送积分活动 1782592
关于科研通互助平台的介绍 1653846