Skip to main content

Research timeline

Related research and updates

Public articles linked to the same research event.

arXiv

Within an ε≤4/255 perturbation budget, targeted semantic substitution makes vision-language models name the target, confirm its presence, and deny the source, reaching 38% complete replacement on images and 35.9% on video

Under a white-box threat model, the work aligns each stream of a source image with its counterpart in a target image in the victim vision-language model's post-merger token space and evaluates under a strict success criterion requiring the model to simultaneously name the target, confirm its presence, and deny the source, finding that target semantics appear at ε=2/255 and complete replacement reaches 38% at ε=4/255 on images and 35.9% at ε=1/255 on video, while also observing semantic fusion.