An embedding-matching attack on DeepSeek Janus Pro makes the model confidently describe objects that are not present, with hallucination rates up to 98% at high visual fidelity.
Intriguing Equivalence Structures of the Embedding Space of Vision Transformers
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Pre-trained large foundation models play a central role in the recent surge of artificial intelligence, resulting in fine-tuned models with remarkable abilities when measured on benchmark datasets, standard exams, and applications. Due to their inherent complexity, these models are not well understood. While small adversarial inputs to such models are well known, the structures of the representation space are not well characterized despite their fundamental importance. In this paper, using the vision transformers as an example due to the continuous nature of their input space, we show via analyses and systematic experiments that the representation space consists of large piecewise linear subspaces where there exist very different inputs sharing the same representations, and at the same time, local normal spaces where there are visually indistinguishable inputs having very different representations. The empirical results are further verified using the local directional estimations of the Lipschitz constants of the underlying models. Consequently, the resulting representations change the results of downstream models, and such models are subject to overgeneralization and with limited semantically meaningful generalization capability.
fields
cs.CV 1years
2025 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
DeepSeek on a Trip: Inducing Targeted Visual Hallucinations via Representation Vulnerabilities
An embedding-matching attack on DeepSeek Janus Pro makes the model confidently describe objects that are not present, with hallucination rates up to 98% at high visual fidelity.