REVIEW 1 cited by
On the Adversarial Robustness of Multi-Modal Foundation Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Multi-modal foundation models combining vision and language models such as Flamingo or GPT-4 have recently gained enormous interest. Alignment of foundation models is used to prevent models from providing toxic or harmful output. While malicious users have successfully tried to jailbreak foundation models, an equally important question is if honest users could be harmed by malicious third-party content. In this paper we show that imperceivable attacks on images in order to change the caption output of a multi-modal foundation model can be used by malicious content providers to harm honest users e.g. by guiding them to malicious websites or broadcast fake information. This indicates that countermeasures to adversarial attacks should be used by any deployed multi-modal foundation model.
Forward citations
Cited by 1 Pith paper
-
Activation Steering Meets Preference Optimization: Defense Against Jailbreaks in Vision Language Models
A proposed VLM defense, SPO-VLM, combines activation steering with sequence-level preference optimization and claims lower jailbreak ASR and toxicity than ASTRA while retaining visual understanding.
Discussion (0). Continue with ORCID to comment.