Shadowcast: Stealthy Data Poisoning Attacks Against Vision-Language Models

计算机安全 计算机科学 自然语言处理 人工智能
作者
Yuancheng Xu,Jiarui Yao,Manli Shu,Yanchao Sun,Zichu Wu,Ning Yu,Tom Goldstein,Furong Huang
出处
期刊:Cornell University - arXiv 被引量:3
标识
DOI:10.48550/arxiv.2402.06659
摘要

Vision-Language Models (VLMs) excel in generating textual responses from visual inputs, but their versatility raises security concerns. This study takes the first step in exposing VLMs' susceptibility to data poisoning attacks that can manipulate responses to innocuous, everyday prompts. We introduce Shadowcast, a stealthy data poisoning attack where poison samples are visually indistinguishable from benign images with matching texts. Shadowcast demonstrates effectiveness in two attack types. The first is a traditional Label Attack, tricking VLMs into misidentifying class labels, such as confusing Donald Trump for Joe Biden. The second is a novel Persuasion Attack, leveraging VLMs' text generation capabilities to craft persuasive and seemingly rational narratives for misinformation, such as portraying junk food as healthy. We show that Shadowcast effectively achieves the attacker's intentions using as few as 50 poison samples. Crucially, the poisoned samples demonstrate transferability across different VLM architectures, posing a significant concern in black-box settings. Moreover, Shadowcast remains potent under realistic conditions involving various text prompts, training data augmentation, and image compression techniques. This work reveals how poisoned VLMs can disseminate convincing yet deceptive misinformation to everyday, benign users, emphasizing the importance of data integrity for responsible VLM deployments. Our code is available at: https://github.com/umd-huang-lab/VLM-Poisoning.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
优秀的梦旋完成签到,获得积分10
1秒前
Hanayu完成签到 ,获得积分0
2秒前
2秒前
淡淡砖家发布了新的文献求助10
2秒前
11发布了新的文献求助10
3秒前
王思蒙发布了新的文献求助10
3秒前
CodeCraft应助hhh采纳,获得10
4秒前
4秒前
和仲完成签到,获得积分10
4秒前
orixero应助科研通管家采纳,获得10
4秒前
思源应助科研通管家采纳,获得10
5秒前
隐形曼青应助科研通管家采纳,获得30
5秒前
5秒前
5秒前
香蕉觅云应助高贵的沂采纳,获得10
5秒前
orixero应助科研通管家采纳,获得30
5秒前
Ava应助科研通管家采纳,获得10
5秒前
Jasper应助科研通管家采纳,获得10
5秒前
5秒前
科目三应助科研通管家采纳,获得10
5秒前
刘豆完成签到,获得积分10
5秒前
5秒前
华仔应助科研通管家采纳,获得10
5秒前
6秒前
6秒前
6秒前
6秒前
6秒前
6秒前
6秒前
6秒前
温白开发布了新的文献求助20
7秒前
7秒前
9秒前
yy发布了新的文献求助10
9秒前
WSY关闭了WSY文献求助
9秒前
jimmy_bytheway完成签到,获得积分0
9秒前
orixero应助lll采纳,获得10
10秒前
10秒前
10秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
No Good Deed Goes Unpunished 1100
Bioseparations Science and Engineering Third Edition 1000
Lloyd's Register of Shipping's Approach to the Control of Incidents of Brittle Fracture in Ship Structures 1000
BRITTLE FRACTURE IN WELDED SHIPS 1000
Entre Praga y Madrid: los contactos checoslovaco-españoles (1948-1977) 1000
Polymorphism and polytypism in crystals 1000
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6100912
求助须知:如何正确求助?哪些是违规求助? 7930606
关于积分的说明 16427236
捐赠科研通 5230309
什么是DOI,文献DOI怎么找? 2795242
邀请新用户注册赠送积分活动 1777621
关于科研通互助平台的介绍 1651127