SceneTAP: Scene-Coherent Typographic Adversarial Planner against Vision-Language Models in Real-World Environments

对抗制 计算机科学 自然性 人工智能 人机交互 平面图(考古学) 规划师 匹配(统计) 脆弱性(计算) 自然语言 透视图(图形) 可视化 机器人 动作(物理) 自然(考古学) 计算机安全 图像编辑 工作(物理) 概率逻辑 钥匙(锁)
作者
Yue Cao,Yun Xing,Jie Zhang,Di Lin,Tianwei Zhang,Ivor W. Tsang,Yang Liu,Qing Guo
出处
期刊:Cornell University - arXiv [Cornell University]
被引量:1
标识
DOI:10.48550/arxiv.2412.00114
摘要

Large vision-language models (LVLMs) have shown remarkable capabilities in interpreting visual content. While existing works demonstrate these models' vulnerability to deliberately placed adversarial texts, such texts are often easily identifiable as anomalous. In this paper, we present the first approach to generate scene-coherent typographic adversarial attacks that mislead advanced LVLMs while maintaining visual naturalness through the capability of the LLM-based agent. Our approach addresses three critical questions: what adversarial text to generate, where to place it within the scene, and how to integrate it seamlessly. We propose a training-free, multi-modal LLM-driven scene-coherent typographic adversarial planning (SceneTAP) that employs a three-stage process: scene understanding, adversarial planning, and seamless integration. The SceneTAP utilizes chain-of-thought reasoning to comprehend the scene, formulate effective adversarial text, strategically plan its placement, and provide detailed instructions for natural integration within the image. This is followed by a scene-coherent TextDiffuser that executes the attack using a local diffusion mechanism. We extend our method to real-world scenarios by printing and placing generated patches in physical environments, demonstrating its practical implications. Extensive experiments show that our scene-coherent adversarial text successfully misleads state-of-the-art LVLMs, including ChatGPT-4o, even after capturing new images of physical setups. Our evaluations demonstrate a significant increase in attack success rates while maintaining visual naturalness and contextual appropriateness. This work highlights vulnerabilities in current vision-language models to sophisticated, scene-coherent adversarial attacks and provides insights into potential defense mechanisms.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
乙酰乙酰CoA完成签到,获得积分20
刚刚
华仔应助砂糖采纳,获得10
1秒前
1秒前
ber发布了新的文献求助10
2秒前
氕氘氚完成签到,获得积分10
2秒前
3秒前
又又完成签到,获得积分10
5秒前
Ca0cus完成签到,获得积分10
5秒前
英俊小美发布了新的文献求助10
5秒前
6秒前
7秒前
7秒前
纸皮核桃完成签到,获得积分10
8秒前
9秒前
9秒前
你你完成签到,获得积分10
10秒前
keep完成签到 ,获得积分10
11秒前
椰子发布了新的文献求助20
11秒前
11秒前
123发布了新的文献求助10
12秒前
12秒前
人群是那么像羊群完成签到,获得积分10
12秒前
13秒前
xiaoQ完成签到,获得积分10
13秒前
思源应助小懒猪采纳,获得10
13秒前
13秒前
orixero应助顺利鸵鸟采纳,获得10
14秒前
爆米花应助唠叨的伊采纳,获得10
14秒前
传奇3应助大力翠风采纳,获得10
15秒前
orixero应助shjdjhs采纳,获得10
15秒前
15秒前
15秒前
16秒前
16秒前
xlj发布了新的文献求助10
16秒前
Ryann完成签到,获得积分10
17秒前
really_1896关注了科研通微信公众号
17秒前
18秒前
yyxy完成签到,获得积分20
19秒前
胡佳庆发布了新的文献求助10
19秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Geist der Kunst und Kultur 1000
Resistance Spot Welding Dataset for Automobile Body-in-White Quality Analysis 748
日本現代怪異事典 副読本 700
悉尼大学博士学位论文,题目:Modelling and testing of one-sided stitched laminated composites. 作者:Kristopher P. Plain 650
Machine Learning for Asset Management and Pricing 600
Numerical analysis of the coupled atmosphere-ocean models (CAO II). II 600
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7398715
求助须知:如何正确求助?哪些是违规求助? 9004200
关于积分的说明 19167669
捐赠科研通 7033719
什么是DOI,文献DOI怎么找? 3230650
关于科研通互助平台的介绍 2392880
邀请新用户注册赠送积分活动 2212426