Pith. sign in

Paper Citation Record · LEDGER

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks

As of 13 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 0 inbound Pith citation observations for arXiv:2411.15720.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2411.15720 v1

Coverage vector

measured 57 of 57 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-12T14:04:45.533578Z

measured 57 of 57 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-12T06:34:41.77262+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

57 of 57 outbound references displayed

  • verified exact2
  • verified fuzzy25
  • unresolved30
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9465c12d-16e0-42fd-9df6-635c937d8f8d · outbound

This paper cites GPT-4 Technical Report.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks GPT-4 Technical Report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.265930Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.265930Z digest=sha256:115833db066cf59e20a55accca46c12b42ec5eb3f709185c34ff0257958da08b

Observation 278eacc9-6bb0-4c15-91c4-0d24191c39dc · outbound

This paper cites Flamingo: a visual language model for few-shot learning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Flamingo: a visual language model for few-shot learning

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.271659Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.271659Z digest=sha256:7fc17b4bca57edba96a730b95c0264e5c67c51bc00a2ae35109876737ba78b50

Observation 724168eb-2f27-4764-901e-b5c6e2853967 · outbound

This paper cites Image Hijacks: Adversarial Images can Control Generative Models at Runtime.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.276730Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.276730Z digest=sha256:4567f0dc62ecd9c348336238073749ad7fac30c4732c2e18b7af0225c73ec6d6

Observation 0f3c50c8-331c-400d-bcb1-1a28d6f2a09e · outbound

This paper cites One transformer fits all distributions in multi-modal diffu- sion at scale.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks One transformer fits all distributions in multi-modal diffu- sion at scale

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.510234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.281986Z digest=sha256:e34b56e27226c3a9bcccbf798d3ab28402edf3d4b63febdaa49a93dc918c5b13

Observation dca4f61e-f790-474d-bd4b-140f50cfccbc · outbound

This paper cites On the Opportunities and Risks of Foundation Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On the Opportunities and Risks of Foundation Models

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.286960Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.286960Z digest=sha256:0439382f6ec195513af2e75e4b70e92e78acd4f48f3b0cb9b5e74dc85e09d967

Observation 2a3d54cd-5d13-4f8c-9179-1262e0056135 · outbound

This paper cites On Evaluating Adversarial Robustness.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On Evaluating Adversarial Robustness

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.291956Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.291956Z digest=sha256:72d550a7dfce3158cbd6462bc9ff1bd0db97656202e45afdb2b8e2709b7c1c49

Observation ac2367b1-b2ed-4d99-a166-27d6df747aaf · outbound

This paper cites Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2024.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2024

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.494925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.297408Z digest=sha256:1a65b7194dea06b1ba7781578377c702e281573a985e75bd0b1d2ffe472b9676

Observation def00373-d365-4270-8781-2a5121f04642 · outbound

This paper cites Attacking Visual Language Grounding with Adversarial Examples: A Case Study on Neural Image Captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Attacking Visual Language Grounding with Adversarial Examples: A Case Study on Neural Image Captioning

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.302110Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.302110Z digest=sha256:a15890b52797c1721b39f2086d47c2126d89eb70dd7b8d2d81c3519eef9dbbc1

Observation ef3077b2-2aa8-405b-a459-109a278f3a35 · outbound

This paper cites Rethinking Model Ensemble in Transfer-based Adversarial Attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Rethinking Model Ensemble in Transfer-based Adversarial Attacks

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.307991Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.307991Z digest=sha256:b3786c688d3acf8ffb0797929712c5496926f3e0bb43789314454164b62d22b4

Observation d5b04198-9e4d-49f2-a807-185ac811989b · outbound

This paper cites Visualgpt: Data-efficient adaptation of pretrained language models for image captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Visualgpt: Data-efficient adaptation of pretrained language models for image captioning

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.479746Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.313248Z digest=sha256:d7e25697f75368ff62cc9e8cfbb58369d356fa74d4c27ac0de2b003cb38d8ace

Observation 1a00a7c4-09f5-4230-afbd-962ed25caae8 · outbound

This paper cites Microsoft COCO Captions: Data Collection and Evaluation Server.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Microsoft COCO Captions: Data Collection and Evaluation Server

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.317956Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.317956Z digest=sha256:b56beb81b1d09d25159cf64e88eb900b770204c1c094ce2a40620723d77ca528

Observation 2c4dbad5-255b-498f-b98e-6f7ea2be4121 · outbound

This paper cites Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.322630Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.322630Z digest=sha256:d25954cabc6d3e04007881c2a47c63f33e35d113be32abd5887d479fcdf58f89

Observation cb4aeab9-d8a7-4d16-8e41-98e7d221a17e · outbound

This paper cites On the robustness of large multimodal mod- els against image adversarial attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On the robustness of large multimodal mod- els against image adversarial attacks

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.453752Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.327198Z digest=sha256:7c1b4c9d8530d6bb7c64462b4fd80f7e175a942ea4b8d21989dc0646dda835d3

Observation b4684860-9ea8-47c9-85af-bd2b360debb7 · outbound

This paper cites Imagenet: A large-scale hierarchical image database.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Imagenet: A large-scale hierarchical image database

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.437420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.331657Z digest=sha256:db709d90213632ecfed70c0441f330ac36fbde1346723f7a6a1becde2e9de968

Observation 5722d0ba-873b-4a86-9fed-4a897f2f0db7 · outbound

This paper cites Boosting adversarial at- tacks with momentum.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Boosting adversarial at- tacks with momentum

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.421440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.336219Z digest=sha256:6da62ca43e8708ef6e291595c7ceedead11701580b34663aa0f49f9a2a374cd8

Observation eff8c265-d324-4f9f-888e-83c2eb789aab · outbound

This paper cites Query-efficient black-box adversarial attacks guided by a transfer-based prior.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Query-efficient black-box adversarial attacks guided by a transfer-based prior

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.406233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.340730Z digest=sha256:d703a8d24aeeb1bc3064363e9df45caabf796499588527e54aeb7e3b40297810

Observation b305d782-bd03-4cc6-9574-69ebd0f8cdd0 · outbound

This paper cites How Robust is Google's Bard to Adversarial Image Attacks?.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks How Robust is Google's Bard to Adversarial Image Attacks?

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.345445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.345445Z digest=sha256:6396c3e8f0c964e8f20ddc67bb286eb05c8bfa0766dc165685fb586e7c017bc9

Observation 2527124c-5dab-42b9-ba28-354b1739f51a · outbound

This paper cites An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.350159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.350159Z digest=sha256:31475d3fef95a32ea7607e18fbbda88850638bd6640d57bff64018ad0fef4f27

Observation 0dc6c3e0-3019-4a23-9054-092bfa50da79 · outbound

This paper cites Transferable decoding with visual entities for zero-shot image captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Transferable decoding with visual entities for zero-shot image captioning

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.389920Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.354889Z digest=sha256:49ff8190db72ea52550735ca68577731b971ef78f6d39e82e5848afcd66d7c9c

Observation d99fc87f-5a8e-416b-bb9a-3951d919900d · outbound

This paper cites Misusing Tools in Large Language Models With Visual Adversarial Examples.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Misusing Tools in Large Language Models With Visual Adversarial Examples

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.359652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.359652Z digest=sha256:72098cf4de1a106f1bf1b1d1153d7c7418d5e278df0997a4f2b69f2f751848b3

Observation 455e54ab-a27b-4814-8c6b-0ccdb3868698 · outbound

This paper cites FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.364618Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.364618Z digest=sha256:3e095f5b20a3722d61e489c69e1377b4b10f40fb0237d46460a00c25d0ac698a

Observation eb0c1066-5b28-4eb1-98e9-a7599193977c · outbound

This paper cites Explaining and Harnessing Adversarial Examples.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Explaining and Harnessing Adversarial Examples

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.369843Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.369843Z digest=sha256:ba5e99726e793839c6f6320134605d24582fa100ea22b523dfec5b8034adfa36

Observation 23b15a9f-03a8-420a-9193-10ce65785e56 · outbound

This paper cites Simple black-box adversar- ial attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Simple black-box adversar- ial attacks

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.373846Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.374370Z digest=sha256:2933b8ec583c8f3be680bd187ac50fa753a45eeeb7a213b0ba4c5e9a6025217b

Observation d9f44e4a-fcfb-46a5-837f-3629ed15c53c · outbound

This paper cites Deep residual learning for image recognition.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Deep residual learning for image recognition

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.378882Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.378882Z digest=sha256:82eb7fd4737c5ebbde7f4c9b8f804467ac08724944129fcc46a8a3212db1cdec

Observation 260eec44-4f03-47d9-829d-eff3209d306b · outbound

This paper cites Enhancing adversarial example transferability with an intermediate level attack.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Enhancing adversarial example transferability with an intermediate level attack

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.347680Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.383684Z digest=sha256:3d510c9f30743b1b9484d4ed9d8fd392c840b82bff10d07f1b31db657f981ee3

Observation 0e744330-1374-4afe-b196-5bcdd9791f62 · outbound

This paper cites Black-box adversarial attacks with limited queries and information.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Black-box adversarial attacks with limited queries and information

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.331922Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.388510Z digest=sha256:7af28c174a18000d422bec7f335a62be94790b72440febee9b80d3f982b8cc73

Observation 57ac0a62-e22f-4c7b-ae8f-71f2b98b55be · outbound

This paper cites Jailbreakzoo: Survey, landscapes, and horizons in jailbreaking large language and vision-language models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Jailbreakzoo: Survey, landscapes, and horizons in jailbreaking large language and vision-language models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.394023Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.394023Z digest=sha256:44d4f0973304a61807acfc848c4adf11d32487d89ee26f692478e01123392609

Observation 6eb0efc9-d3b0-458d-b9e8-be1d4452e1ff · outbound

This paper cites Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.399083Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.399083Z digest=sha256:51ec6f50b8b4b307ddf34efda353c97cd81e64da00a404372f5e27d5d2e45312

Observation 8809e5a4-2b83-48e4-81de-90f8229468ee · outbound

This paper cites Improved baselines with visual instruction tuning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Improved baselines with visual instruction tuning

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.306412Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.403338Z digest=sha256:033111f0bbef66ec68f1b4a06ab6908f4cb0a083558e911a086e7c19b85a5b5d

Observation ae9cf933-1803-4760-a0d3-924c70bc902d · outbound

This paper cites Visual instruction tuning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Visual instruction tuning

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.291322Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.407508Z digest=sha256:e3027b2fa079964a94bad3c452a0dd2f0210d0d064da115f6bab8dce53aff634

Observation f529ce5c-d849-4d9c-8f6b-8ede1a60fba4 · outbound

This paper cites Delving into Transferable Adversarial Examples and Black-box Attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Delving into Transferable Adversarial Examples and Black-box Attacks

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.412014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.412014Z digest=sha256:cdd61f49a7e40e0179a847cd37ed209d4360caa3b73b80af7a5c8211e22eb9ea

Observation 11626c42-057c-481f-8623-7e7c4cb46010 · outbound

This paper cites Delving into transferable adversarial examples and black- box attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Delving into transferable adversarial examples and black- box attacks

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.275318Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.416609Z digest=sha256:203405425fc20605cd2cd6718d80c5b9a845476f6cd86b79c6f703397ebb322d

Observation c9a7b32e-17ad-4556-a584-f33a14cf35f0 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.421221Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.421221Z digest=sha256:12f2c224c2d04f88a44059cbf940cb51735bdf4ae165656a9b562b2887d09bef

Observation db831ca2-61dd-425b-977f-52846b6be8fe · outbound

This paper cites ClipCap: CLIP Prefix for Image Captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks ClipCap: CLIP Prefix for Image Captioning

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.425894Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.425894Z digest=sha256:13f50f5d4033fbd9cc9e35c2951a187e9372429bd0cc5c6cfb1c98a980feed74

Observation 3a583908-46da-47a4-8df0-be3535eab082 · outbound

This paper cites Deep neural networks are easily fooled: High confidence predictions for unrecognizable images.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Deep neural networks are easily fooled: High confidence predictions for unrecognizable images

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.430441Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.430441Z digest=sha256:05cd6671f9fbd644727cc0c50a099aca452e64cb3a17d687a549606a626dcf87

Observation aabf837b-6f64-4191-ae19-f3ce9c8c758c · outbound

This paper cites Practi- cal black-box attacks against machine learning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Practi- cal black-box attacks against machine learning

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.249927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.434999Z digest=sha256:86f310da40c855867523565e9e03ff1d95a603c5916f7f8d4c0221bf306425b5

Observation 68c7a997-5a37-4ed7-a343-df167c9bab1b · outbound

This paper cites Red Teaming Language Models with Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Red Teaming Language Models with Language Models

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.439661Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.439661Z digest=sha256:01332f6eaf862656ffed5640f8620eef6281c4a3527f5cfb56919663504b5ff9

Observation 131bc890-ff1a-4462-9df5-d54cb3533721 · outbound

This paper cites Visual Adversarial Examples Jailbreak Aligned Large Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Visual Adversarial Examples Jailbreak Aligned Large Language Models

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.445238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.445238Z digest=sha256:8984b33f741a371fadc6450dba66634b28578b44a1431820fb05296781637ac1

Observation 0dffcf7f-c20d-452f-b7cc-3a0407f56fdb · outbound

This paper cites Boosting the transferability of ad- versarial attacks with reverse adversarial perturbation.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Boosting the transferability of ad- versarial attacks with reverse adversarial perturbation

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.234182Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.450171Z digest=sha256:97b63e6d31df2e588451485f92c238f1e55458973da3eb9239a8aabc892ce8df

Observation ee143442-8368-488e-ab7b-81699295b20b · outbound

This paper cites Language models are unsu- pervised multitask learners.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Language models are unsu- pervised multitask learners

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.454674Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.454674Z digest=sha256:6bacc86ecdd5bf16017ebf1a3a49dc7a79372a2d33403cbc97b5e2e892a1065e

Observation f4571ce6-ad84-41da-8b59-415926b0dbf1 · outbound

This paper cites Learning transferable visual models from natural language supervi- sion.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Learning transferable visual models from natural language supervi- sion

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.208805Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.459263Z digest=sha256:10a971babee118577c4e19a9afaa3a87d6fc15f49fb7ff89774f261068ec198c

Observation 32d7222d-9524-403b-897f-02f3b6ae6d1e · outbound

This paper cites Smallcap: lightweight image captioning prompted with retrieval augmentation.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Smallcap: lightweight image captioning prompted with retrieval augmentation

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.191362Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.463657Z digest=sha256:ac5f73c32f517252bd549859068c10539acdfef8ea0b0113c504aa0e9b9d72da

Observation e6be4645-f99b-4a08-a473-f920a359b44b · outbound

This paper cites Red-Teaming the Stable Diffusion Safety Filter.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Red-Teaming the Stable Diffusion Safety Filter

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.468299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.468299Z digest=sha256:766a92defea4b2355a35a18cd3ebf1f4f5ea0f581a68ddfaf3ff90d5047ad1ef

Observation 04091d0e-6ac4-47c8-a029-93a8bad3915a · outbound

This paper cites High-resolution image synthesis with latent diffusion models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks High-resolution image synthesis with latent diffusion models

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.175234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.472955Z digest=sha256:006f737fb619063951867439a19c0c97200f3a0543c715aa1f3dde5f08f5dac2

Observation e7ef2b3d-079c-4fc7-afe2-6f4c17489b54 · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks LLaMA: Open and Efficient Foundation Language Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.477320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.477320Z digest=sha256:a4560c23734841550931cf7c23ae4bbe32d4eaf695ecc3879cb5bcb6a34ec49e

Observation 819d6954-93ba-49d1-a469-f2e347f8677b · outbound

This paper cites Llama 2: Open Foundation and Fine-Tuned Chat Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Llama 2: Open Foundation and Fine-Tuned Chat Models

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.482107Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.482107Z digest=sha256:5bda28b0c4a5adec373a91dcb42650f062e220cbdcd3c20b031f82e393c5781b

Observation fac32d46-9ac9-47b8-86bf-1126fdaf3be9 · outbound

This paper cites How many unicorns are in this image a safety evaluation benchmark for vision llms.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks How many unicorns are in this image a safety evaluation benchmark for vision llms

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.159394Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.486582Z digest=sha256:20cefac9115878e1a92ce7c9d8e2797746ca367c277b40415dc700c405d4ef49

Observation 87f9dc7d-f8f0-4b69-aecc-f2dd709e3b53 · outbound

This paper cites Decodingtrust: A com- prehensive assessment of trustworthiness in gpt models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Decodingtrust: A com- prehensive assessment of trustworthiness in gpt models

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.143484Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.490762Z digest=sha256:02fedb399bc3b06a894a9d0155e88cceac96bde92de1b5c37d43efa61d92c39b

Observation 73c3d2fd-7404-4b75-aaf8-ce54a53d3172 · outbound

This paper cites Exact adversarial attack to image captioning via structured output learning with la- tent variables.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Exact adversarial attack to image captioning via structured output learning with la- tent variables

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.127179Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.495218Z digest=sha256:3926e598204370aeeae0ed942c0cdfd5a8d0274ab1d775fcf155df63caf920fa

Observation 9fc0d42a-727c-4fea-b7c7-6fcd83068a03 · outbound

This paper cites Adversarial Attacks of Vision Tasks in the Past 10 Years: A Survey.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Adversarial Attacks of Vision Tasks in the Past 10 Years: A Survey

Reference 50

Resolution
verified exact
local_arxiv, observed 2026-08-12T14:04:45.637508Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.499682Z digest=sha256:496dc16dc4777c0732aa1d466f1ad524d2ee9ff11fdcca95331b35e844f423ca

Observation e242e9b5-987b-4cbf-9a31-9a194fc82351 · outbound

This paper cites The unreasonable effectiveness of deep features as a perceptual metric.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks The unreasonable effectiveness of deep features as a perceptual metric

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.504498Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.504498Z digest=sha256:257c73da7203029be4a902aa1ad27000a1a1a99a76e050f02875106a238f35d3

Observation 5bd67aec-a927-4b0a-b458-4f204a7d0253 · outbound

This paper cites A Review of Adversarial Attacks in Computer Vision.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks A Review of Adversarial Attacks in Computer Vision

Reference 52

Resolution
verified exact
local_arxiv, observed 2026-08-12T14:04:45.614774Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.509333Z digest=sha256:69533d6fdd14b6e982652d615f4dcb303b4f06ac50ed93ca9a7bd9d572be5ede

Observation f62fb484-f36f-4296-a72d-05ee7d4f33ed · outbound

This paper cites A Recipe for Watermarking Diffusion Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks A Recipe for Watermarking Diffusion Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.513954Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.513954Z digest=sha256:7c30ab66f94582602d9a97f2b6bd87eb171e2da0f57c2679750456f252993a3c

Observation 44e1525b-a63d-4526-afd9-50c78ff60cc9 · outbound

This paper cites On evaluating adversarial robustness of large vision-language models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On evaluating adversarial robustness of large vision-language models

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.101716Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.519480Z digest=sha256:04af0d9e257bdaa2634ff151dd4870cfc7887f0adaa14d5912d7e25e96f0e2f8

Observation 8447102d-4c56-4706-9e50-36519ca91265 · outbound

This paper cites Transferable ad- versarial perturbations.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Transferable ad- versarial perturbations

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.084878Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.524051Z digest=sha256:9d67288ca12e6933fd571d9538e3f4377f20310a0fd4e0d6be36ce548f9d3db6

Observation cf23132f-9ad5-4d51-9356-af7bce5250f5 · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.528550Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.528550Z digest=sha256:71c97284381abbcb8f79a1a218b4c80325d1d9793d7603f8922370bdc542ff4a

Observation deaa29fd-bdcf-41e4-bd4a-0cbfb48337c2 · outbound

This paper cites How do you think of this image?.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks How do you think of this image?

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.068676Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.

source=pdf_text observed=2026-08-12T14:04:45.533578Z digest=sha256:4721907967cc70fa973cc6bb8d1c211e928d68560c8ecdc538d94048c53088b6

Pith citing papers

No inbound Pith citation observations are available.