Pith. sign in

Paper Citation Record · LEDGER

Transferable Adversarial Attacks on Black-Box Vision-Language Models

As of 17 August 2026, this Paper Citation Record lists 83 of 83 outbound references and 9 inbound Pith citation observations for arXiv:2505.01050.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.01050 v1

Coverage vector

measured 83 of 83 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-16T04:34:34.466875Z

measured 92 of 92 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-16T06:30:59.297886+00:00

measured 9 of 9 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T17:47:19.126970Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T00:59:21.218293Z

Reference resolution

83 of 83 outbound references displayed

  • verified exact1
  • verified fuzzy25
  • unresolved57
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation ee7b22f6-444c-4832-878a-abc3ddd21edb · outbound

This paper cites write newline.

Transferable Adversarial Attacks on Black-Box Vision-Language Models write newline

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.160872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.160872Z digest=sha256:05b364a99e17856b0e253affe7da546d4bf9797927c6c2121e63a8a0605d91ae

Observation c1f9d0ad-3eae-4627-81c5-c258e9542356 · outbound

This paper cites GPT-4 Technical Report.

Transferable Adversarial Attacks on Black-Box Vision-Language Models GPT-4 Technical Report

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.165708Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.165708Z digest=sha256:ac174f20442b235f6f56cd35180674ef88bb1feb76038b9ce49d1b0ce201a978

Observation e8e6b134-43b6-48e7-b94d-596091a31889 · outbound

This paper cites Llama 3 model card.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Llama 3 model card

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.169725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.169725Z digest=sha256:2882507249578793acb0dc26bf4f0f0d82921dc8841bdfbee83fb8ffc5f17778

Observation 9130abb0-0457-4875-8965-f7b8d118eda3 · outbound

This paper cites Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.173226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.173226Z digest=sha256:1273e8fb7df9246129bb1583bcbb5d097323c466a6264491ea56138a7b3aa29f

Observation 26b926a3-bd56-4dc1-81ca-fba99ae45735 · outbound

This paper cites Model card and evaluations for claude models, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Model card and evaluations for claude models, 2023

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.177020Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.177020Z digest=sha256:d11f3f6036d2ffe073b4c5b863344e61399d1ed25a077bf9558a1bfc72015fe9

Observation e6f7accd-9ed6-4bf5-90e0-d438fec113c9 · outbound

This paper cites The claude 3 model family: Opus, sonnet, haiku.

Transferable Adversarial Attacks on Black-Box Vision-Language Models The claude 3 model family: Opus, sonnet, haiku

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.334246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.180461Z digest=sha256:775946b37ff327980ba008596092db52b64901f5d1a4eeadf055ae30126caba7

Observation 51845fca-6eda-4c25-aa77-cae82fd698f9 · outbound

This paper cites Qwen2.5-VL Technical Report.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Qwen2.5-VL Technical Report

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.183861Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.183861Z digest=sha256:7cac24cf36e07bf3bb29e2c2e6a15ae830b77a877c05c4935d1185ace15d233f

Observation 836fd2c4-9d7f-40e5-b3d4-6ada7dcd91ce · outbound

This paper cites Image Hijacks: Adversarial Images can Control Generative Models at Runtime.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.187704Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.187704Z digest=sha256:13f2990a7036ba6f3726bf5cde786a7a6fa7bd640f207452947c5bf35a863184

Observation 4e74ba98-fd9a-46b4-bb3e-5d9664275554 · outbound

This paper cites Evasion attacks against machine learning at test time.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Evasion attacks against machine learning at test time

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.323690Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.191197Z digest=sha256:a1edd3c00d83473abf599f814716ac304cfad7d71d72fb17e8bb29ecc10a209a

Observation 39791491-56bc-4bf0-8687-8010b191d4a8 · outbound

This paper cites RT-2: Vision-Language-Action Models Transfer Web Knowledge to Robotic Control.

Transferable Adversarial Attacks on Black-Box Vision-Language Models RT-2: Vision-Language-Action Models Transfer Web Knowledge to Robotic Control

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.194529Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.194529Z digest=sha256:510bd8e6843a731bae7e5dddff522a92ac19bf980c9c26f7e73f4f390d91c920

Observation 232eb64f-ff7b-4d68-9b15-2d61f3da3c31 · outbound

This paper cites Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2023

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.313026Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.198028Z digest=sha256:a8b41d373a17509596a304e77a423f2c5850c62b579ef43eca730474c4a961e7

Observation 1ca1d42d-810c-4d58-91f2-90a79f8a560d · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.201186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.201186Z digest=sha256:2059e4efb4118db7c539f315a2a4422063b6935c0d588e53118cbb522643320b

Observation 807f4dd1-4a16-4aae-ad71-fb07a707204f · outbound

This paper cites Rethinking Model Ensemble in Transfer-based Adversarial Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Rethinking Model Ensemble in Transfer-based Adversarial Attacks

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.204316Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.204316Z digest=sha256:de334e3cf3476aa6c949d1f3bb4ef02e2683530d4966bfdab73a21ac870f9a07

Observation 9426dbcb-d891-4347-82ca-93130fa736ae · outbound

This paper cites Red Teaming GPT-4V: Are GPT-4V Safe Against Uni/Multi-Modal Jailbreak Attacks?.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Red Teaming GPT-4V: Are GPT-4V Safe Against Uni/Multi-Modal Jailbreak Attacks?

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.207424Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.207424Z digest=sha256:665a5ac4859cbf3488e730523264a393e1a4a7c776ee1651d997083554316153

Observation d3ecb44a-bc7b-408e-8fa1-50e26bffde9f · outbound

This paper cites Certified adversarial robustness via randomized smoothing.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Certified adversarial robustness via randomized smoothing

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.302101Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.210767Z digest=sha256:8645980a794cb35c7c72e0a44b51e48f4ce8a7afd4e8904f3348deaa391fd582

Observation a52e39a9-b6c0-42c4-ba6e-9bbd402ddff1 · outbound

This paper cites Vision Transformers Need Registers.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Vision Transformers Need Registers

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.214741Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.214741Z digest=sha256:7534cbe268fc9e2493db5dcaab48d66bff36c3f4c66b7887bb03afb78708dd2a

Observation 50de2276-79c0-4cee-ab66-7476e8d7afae · outbound

This paper cites Paddleocr: An easy-to-use ocr tool based on paddlepaddle.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Paddleocr: An easy-to-use ocr tool based on paddlepaddle

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.194540Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.218313Z digest=sha256:768687ebd4826bf70da01e678129a395a9f31914b1fc3dbe6de9d367e94dcc3b

Observation 7ca23396-7e39-4883-8729-a54a7e1a16fe · outbound

This paper cites How Robust is Google's Bard to Adversarial Image Attacks?.

Transferable Adversarial Attacks on Black-Box Vision-Language Models How Robust is Google's Bard to Adversarial Image Attacks?

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.222225Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.222225Z digest=sha256:b40d620585c92bdc63112cc02f3949a95ef669eab060f1236fbdc727365372ba

Observation f1c10498-814c-4243-abb0-4f67ac295e5e · outbound

This paper cites Large language models in radiology: fundamentals, applications, ethical considerations, risks, and future directions.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Large language models in radiology: fundamentals, applications, ethical considerations, risks, and future directions

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.184607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.226222Z digest=sha256:10e0a06b3de856f1077f06a7b2265ab4b0b29ac313c61c5b9712d23afc47685c

Observation da38a1d0-1415-4c07-aca8-e13158d5c825 · outbound

This paper cites Robust physical-world attacks on deep learning visual classification.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Robust physical-world attacks on deep learning visual classification

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.229543Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.229543Z digest=sha256:443aca751a958c90930f5a4bbb3778a4811923166ce720aff32be13c833cd3c8

Observation c917b5d7-14cd-4058-acf7-ac06200894c6 · outbound

This paper cites Data Filtering Networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Data Filtering Networks

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.232849Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.232849Z digest=sha256:45608793c9ab587b43bbfcb1eeb0a4cf86c9a3421abfcebd8ccc5fe5fdc4c981

Observation 7048848a-7e78-4c27-bd35-59cfc9c775cf · outbound

This paper cites Sharpness-Aware Minimization for Efficiently Improving Generalization.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Sharpness-Aware Minimization for Efficiently Improving Generalization

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.236251Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.236251Z digest=sha256:f7be1b71af78347f73d82b9367f45988fc7456dcef7aff5a547b1d4986357a9f

Observation baeb416b-e12e-4682-99b0-3df4979f8d64 · outbound

This paper cites Multimodal neurons in artificial neural networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Multimodal neurons in artificial neural networks

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.239756Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.239756Z digest=sha256:776b0bfce378e6788eb542d80eb157987f7ab6f7340972355290a666b8357125

Observation edf5d497-06fc-4a0f-aa12-a64ea4280b78 · outbound

This paper cites Goodfellow, Jonathon Shlens, and Christian Szegedy.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Goodfellow, Jonathon Shlens, and Christian Szegedy

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.243186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.243186Z digest=sha256:dca428697b381848b6dfdb65c60a39439c31cab74b2e0dfb06c4ff2c4bc43e73

Observation aecff6d5-dc7e-406e-85fa-25e26479f794 · outbound

This paper cites Regulating chatgpt and other large generative ai models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Regulating chatgpt and other large generative ai models

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.156584Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.247003Z digest=sha256:d9f605aa8221b8adec4099f183d3e26a19a5a99c7469d6178f2703902fd1be40

Observation e246c911-ba7e-4294-9dd0-eac34feaeae7 · outbound

This paper cites Deep residual learning for image recognition.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Deep residual learning for image recognition

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.250782Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.250782Z digest=sha256:64e2127a38f14159043a0afd6ee2dc523e3d60a670d7819fe1bf7f4beee24c6f

Observation 9f14c6a3-d17a-479d-9f35-df75d17c215e · outbound

This paper cites Deep networks with stochastic depth.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Deep networks with stochastic depth

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.140252Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.253970Z digest=sha256:76a1eee951e0a66f02728f1bedd22495cd9b6fbf4f4ea7e701a5dc48fe2e5093

Observation cd3aeb0a-9296-4bee-a9e1-a04458abb6d5 · outbound

This paper cites Densely connected convolutional networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Densely connected convolutional networks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.257743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.257743Z digest=sha256:cfb94ece20a176041e8e5bcd5cdc13492199089f4e7575bd2f5b91328e91ce76

Observation cbe52011-36f5-4a70-9efc-7a6331ddbfb2 · outbound

This paper cites Averaging Weights Leads to Wider Optima and Better Generalization.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Averaging Weights Leads to Wider Optima and Better Generalization

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.261402Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.261402Z digest=sha256:f5e310bb615f65ab701791a57c01a1e5e34e6ff3573130d900aba96f7a5ab6b5

Observation 1b224d41-e382-4346-9245-fc29747c201a · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.264833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.264833Z digest=sha256:1b9c585a4e7096563ea154e4965a319a80ebab839293be1c563f4b14b43beb37

Observation 3655163f-0bf5-429b-8b3a-382f9c8e6832 · outbound

This paper cites Never Stop Learning: The Effectiveness of Fine-Tuning in Robotic Reinforcement Learning.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Never Stop Learning: The Effectiveness of Fine-Tuning in Robotic Reinforcement Learning

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.268065Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.268065Z digest=sha256:af8d93cb87020e264834b8b8584e05ea31af4b8d698a575056c73a2db171c19c

Observation 2871704e-3301-4862-ad25-a614fd5e33e4 · outbound

This paper cites Adversarial attacks and defences competition.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Adversarial attacks and defences competition

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.123434Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.271617Z digest=sha256:dc5585d4b7618db09d929aa84fc49aabad29d920d07a46e58d5ff7af4f576fc4

Observation 4312c81d-cf67-4f78-941b-c871117676aa · outbound

This paper cites Building and better understanding vision-language models: insights and future directions.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Building and better understanding vision-language models: insights and future directions

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.111904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.274647Z digest=sha256:083d602fcfdd1dca2458ad8ef07cba2148ae19a306cf93dcdeefa9af3a7fa120

Observation 9cc1f752-8afe-4863-b58a-5f4a0ff6ad60 · outbound

This paper cites LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.278320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.278320Z digest=sha256:694c05653f92ada55af1fd593f13ebb101a0d7cff833cb901d90ee65584c74a2

Observation 9aa46f9c-67aa-45d8-85ed-081b9373d979 · outbound

This paper cites LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet.

Transferable Adversarial Attacks on Black-Box Vision-Language Models LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.281806Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.281806Z digest=sha256:d2565efde38d6f2f9c77e651dfb9bed0d9f40c8b1196a68230d39498e96b7bd8

Observation 1eb14972-568b-4528-8915-f112ab047e13 · outbound

This paper cites CLIPA-v2: Scaling CLIP Training with 81.1% Zero-shot ImageNet Accuracy within a \$10,000 Budget; An Extra \$4,000 Unlocks 81.8% Accuracy.

Transferable Adversarial Attacks on Black-Box Vision-Language Models CLIPA-v2: Scaling CLIP Training with 81.1% Zero-shot ImageNet Accuracy within a \$10,000 Budget; An Extra \$4,000 Unlocks 81.8% Accuracy

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.285319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.285319Z digest=sha256:5c61453127997c8327569328bf8b05e49bcb59fd659f5ba25e52515cf7f45143

Observation d5de2046-b404-4555-98cb-c10e2f1e9d27 · outbound

This paper cites Microsoft coco: Common objects in context.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Microsoft coco: Common objects in context

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.288730Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.288730Z digest=sha256:32c11ffa5a30d1ddbdca4efeddc119f619d4c413fb4af40e6e2b578e5d718752

Observation 9252b662-3bce-4a33-b020-cdf5d0e2d9cf · outbound

This paper cites Visual instruction tuning.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Visual instruction tuning

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.292579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.292579Z digest=sha256:8632c498e075b4145e68e4b84c74a6a2cf2ecb5072764dcd0fd21f89b16deb18

Observation 80a0dc0b-8f2e-43e9-9603-5a92ea86eda5 · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.296596Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.296596Z digest=sha256:72e8251c15748f8130c95484d61a9cf930e358d7aa3d5c564df77c8030ced640

Observation 481d7042-6bb0-4912-8d02-81dac63c5978 · outbound

This paper cites Delving into Transferable Adversarial Examples and Black-box Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Delving into Transferable Adversarial Examples and Black-box Attacks

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.300807Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.300807Z digest=sha256:12bc90eb2064b131bc6f641c085b133fbefaf5ba87fdad7f47edce0d40bd570c

Observation 27af11fa-8c4d-498b-811b-0c7b81a84cdd · outbound

This paper cites Patchdropout: Economizing vision transformers using patch dropout.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Patchdropout: Economizing vision transformers using patch dropout

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.089645Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.304830Z digest=sha256:f61ef5192bd7c6aba32bb469ed9775af4d8571fd987c499e791c7ff45ac43d30

Observation 11573e70-cf04-4886-be86-0cdff54478d7 · outbound

This paper cites Eureka: Human-Level Reward Design via Coding Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Eureka: Human-Level Reward Design via Coding Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.309778Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.309778Z digest=sha256:dfcd107e23a83cd126eb19dd03199646d6855e404caf677197f13d95bbffc5ed

Observation 68622cfc-ae15-4c87-9263-e6bd30a6981e · outbound

This paper cites Dolphins: Multimodal Language Model for Driving.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Dolphins: Multimodal Language Model for Driving

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.313636Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.313636Z digest=sha256:0f4e7a06a9fafcec0fa885258eb33e91e3c7ce3f570be9db7753f7aa2420ed14

Observation d49c94cf-a37c-4eab-ad42-605e4f34c7d5 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.317179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.317179Z digest=sha256:28338daf43770dde662d13bf389345cabb39312263c8acf6bdc748e2028e4ffd

Observation c25168d4-a740-44fa-afbd-38e34691dd90 · outbound

This paper cites Understanding Zero-Shot Adversarial Robustness for Large-Scale Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Understanding Zero-Shot Adversarial Robustness for Large-Scale Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.321269Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.321269Z digest=sha256:52e031cc89cf67069f436b643f3856bb9645326921b6f1fb453554bbef0256a3

Observation aaac4266-6e2e-4a63-81a3-a2c5efbe9873 · outbound

This paper cites Harmbench: A standardized evaluation framework for automated red teaming and robust refusal, 2024.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Harmbench: A standardized evaluation framework for automated red teaming and robust refusal, 2024

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.324838Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.324838Z digest=sha256:0823c3aef751c348631604d43367f04bc962a286129b035fce62a560c8933dca

Observation e690f6c5-0185-41da-a841-e90c7a6c9afc · outbound

This paper cites Scalable Extraction of Training Data from (Production) Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Scalable Extraction of Training Data from (Production) Language Models

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.328770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.328770Z digest=sha256:28e7f33132c83553272ae0a0b53fa7caeac3024f956bfa6a88d3437b164ec951

Observation fbc5b27a-69e5-4e4a-8941-14352182ff0f · outbound

This paper cites Jailbreaking attack against multimodal large language model, 2024.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreaking attack against multimodal large language model, 2024

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.072486Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.332699Z digest=sha256:bc41dd87a5c4d451f6101be835b3595cdbfd008136df8eb27c3e7312fea3fc93

Observation 6e009c27-e2dd-4a1a-b694-386043d21d7a · outbound

This paper cites Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.336232Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.336232Z digest=sha256:0caeef3d1ed5d270ad302697b3c64ca7b591e0ad9ea755acd36aea55d611f3c5

Observation 397a5291-2ca0-459b-b322-721411ef9bf7 · outbound

This paper cites Gpt-4v(ision) system card.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Gpt-4v(ision) system card

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.061079Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.340244Z digest=sha256:6c17ffbdccd8e29a3d951aec684faee7ffff00bc31a54c95ca5fab8ba95da236

Observation e452ad34-7705-449e-8ce0-ad8e39aecbe7 · outbound

This paper cites DINOv2: Learning Robust Visual Features without Supervision.

Transferable Adversarial Attacks on Black-Box Vision-Language Models DINOv2: Learning Robust Visual Features without Supervision

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.343572Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.343572Z digest=sha256:d4d5724da20ea83ea1378a7da19ac2fd807cba079ff3c988b7bc411f0e015f67

Observation 31917675-06f1-4ff2-a576-5f522215132b · outbound

This paper cites Training language models to follow instructions with human feedback.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Training language models to follow instructions with human feedback

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.347345Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.347345Z digest=sha256:bc9aac1ca7f31e06ff36c5b7601de5e3414d6addf84c76f648f766466d2f833e

Observation d3b099a6-3c9b-46a5-95f6-3d137a42650a · outbound

This paper cites Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.351555Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.351555Z digest=sha256:4919a8d96b1338f018471d04621754b3b42493aeb0bc580e7c2b5c2282ceda33

Observation 7294eb77-a106-4f77-961d-072e8f5abf85 · outbound

This paper cites Red Teaming Language Models with Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Red Teaming Language Models with Language Models

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.355320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.355320Z digest=sha256:623db5292eb631c8b74530832d3765e293590a7b3edfe202289b7a476784172e

Observation 11478142-a000-4211-a3b5-edf8ed4033c9 · outbound

This paper cites Visual Adversarial Examples Jailbreak Aligned Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Visual Adversarial Examples Jailbreak Aligned Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.359095Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.359095Z digest=sha256:88eb1c5931e1ad0c19441df0b5d713b89282ba2f54d13281002b8b055d19714e

Observation 9ddc675e-172b-404b-95bb-de48503a1681 · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Visual adversarial examples jailbreak aligned large language models

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.044476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.362562Z digest=sha256:d61ce9b534f971a54bbfe57ffbfd6f48caeceda445879b55dac394e2e4ffcd56

Observation 0d2ef145-9649-4d72-a572-8f2af5b54c4a · outbound

This paper cites Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.365888Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.365888Z digest=sha256:0c7a0049aebea622d9a32844bb37ebb478d65e98f0c9d78bbdc50dc9f7635f4d

Observation d88ab7dc-704e-43c5-aa28-716ad2bb366d · outbound

This paper cites Differentiable jpeg: The devil is in the details.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Differentiable jpeg: The devil is in the details

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.027475Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.369398Z digest=sha256:2fb1d003d99678cd5bdf94d93d1d40058e3c32f45c34fe2af0c9fa10a69dbd4d

Observation f9f122a6-6ec2-4f5c-a5e3-0f689f4716c7 · outbound

This paper cites Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.372863Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.372863Z digest=sha256:bd37b93a81bcbe7d2bf373aadb93e59ccbcd563e4ad6c79336922c4f4eecef3c

Observation 97df4209-91f5-40e2-9329-a443e7ea1f3c · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.376170Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.376170Z digest=sha256:f011d04691173f138140fc856add864e9cc79dbec9948411ed41a18251b7969c

Observation 3a2f6f71-4c12-4d2e-a8fe-04fb90316f91 · outbound

This paper cites Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.379800Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.379800Z digest=sha256:60d9d3e1fb2c3c10cfbb42fcfc8411e4937719abc2fb2fd1b6a28d82703a1d65

Observation ca1f1b1f-c6fe-44f6-830f-d534fcc3d422 · outbound

This paper cites On the adversarial robustness of multi-modal foundation models, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models On the adversarial robustness of multi-modal foundation models, 2023

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.016635Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.383530Z digest=sha256:cc8dd1de0bc67d36888281c67cd29f1447d2ef3bfdfb689faeba5e6a97e0c973

Observation cc0a9220-ecc6-4d3c-84af-29d5a1aa0ca9 · outbound

This paper cites AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated Prompts.

Transferable Adversarial Attacks on Black-Box Vision-Language Models AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated Prompts

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.386874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.386874Z digest=sha256:d460573de9a5a22c367aee9dca74d6c4c92491250a164bdcddb2ea60a72a5579

Observation f70b5db4-965e-4f5b-93bf-2b3238c6176b · outbound

This paper cites Large language models encode clinical knowledge.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Large language models encode clinical knowledge

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.390469Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.390469Z digest=sha256:234aea5d50e688bc1788938ccd8e618d49975847edc5668f86b91460fcf24af7

Observation b7aec58d-5757-46b4-b2d5-5739a65e39bd · outbound

This paper cites Intriguing properties of neural networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Intriguing properties of neural networks

Reference 65

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.999340Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.393694Z digest=sha256:5b6d3d928e0d2810c62d2e4b540d4008bf3bb6d3abe992f7e7a9ea1d93520edb

Observation 59aac060-3960-4ca3-968c-105bd69d0e3c · outbound

This paper cites Gemini: A Family of Highly Capable Multimodal Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Gemini: A Family of Highly Capable Multimodal Models

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.402597Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.402597Z digest=sha256:3e8a93f4533753b004080e6ee3289e4cccdb902578beb45ace48c37f3b1383dd

Observation 13566eb0-cbcb-4617-ba8a-27d344237974 · outbound

This paper cites Ocr receipts text detection - retail dataset.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Ocr receipts text detection - retail dataset

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.988698Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.406226Z digest=sha256:0ec6b79e76ab84e127d67a9bf21f0662084e3b61bb234d3d4b964cb9961ce6ff

Observation be2e8e0e-1bd3-4924-bcb3-05519571c5a5 · outbound

This paper cites Revisiting adversarial training at scale.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Revisiting adversarial training at scale

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.978521Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.409854Z digest=sha256:ff760b1bce018dc5e738f71149e9c1333b13114cfb2d0226d099705bacfc20f8

Observation b044c04a-fc3d-4f0e-b9bc-62f58051a898 · outbound

This paper cites Jailbroken: How does llm safety training fail? Advances in Neural Information Processing Systems, 36, 2024 a.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbroken: How does llm safety training fail? Advances in Neural Information Processing Systems, 36, 2024 a

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.967929Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.413580Z digest=sha256:228c12420fca69aa66933c86f8a6476a67be21d1294b6eeb93a4cb1f9f8008e9

Observation 7244f837-b6ae-4d54-ad5c-8cb269bd01e9 · outbound

This paper cites Jailbreak and guard aligned language models with only few in-context demonstrations, 2024 b.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreak and guard aligned language models with only few in-context demonstrations, 2024 b

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.957335Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.417198Z digest=sha256:e53c8f8494ae0f066cce417516f55664619aa60e4e80b53cde15729c3471f664

Observation a68d8c79-e523-4acf-bb1e-9ec3731ab0aa · outbound

This paper cites Dissecting adversarial robustness of multimodal lm agents.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Dissecting adversarial robustness of multimodal lm agents

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.421120Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.421120Z digest=sha256:a4f565048803be5cbec778289a6b72f83b86784cd7584286399f2c104acd4574

Observation 670d1895-d82d-4dfd-a0fc-fe322807d972 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.424911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.424911Z digest=sha256:3655f4acb87604b459c681ee5bb4496f90e5dfce87c5c0d5724015d37245d3c2

Observation 8098073a-5b68-454e-a740-3086ae4f2dad · outbound

This paper cites Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks

Reference 74

Resolution
verified exact
local_arxiv, observed 2026-08-16T04:34:34.553216Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.429357Z digest=sha256:cbbb48a6bc0e4e52229ab666d2f9ef9855bc3cf4e1adcf1aca9bcd2183e1bc15

Observation 72383db9-b1d3-45d9-9f47-65aa2151b5b3 · outbound

This paper cites Demystifying clip data.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Demystifying clip data

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.940263Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.433526Z digest=sha256:93007bf51e4b9358e639c0d8d00fd2d3d8133a30b40f8b8cb708e88284887261

Observation b746b0da-fa34-4596-8b86-df187c1e06ed · outbound

This paper cites SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering.

Transferable Adversarial Attacks on Black-Box Vision-Language Models SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.437510Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.437510Z digest=sha256:b92f146d487e29bde9f4253cc08d01a1da16609c2cddb33623628ec3c3100276

Observation 5bf8fc7b-d59a-4b8b-b7b6-9e4dc660a90e · outbound

This paper cites Vlattack: Multimodal adversarial attacks on vision-language tasks via pre-trained models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Vlattack: Multimodal adversarial attacks on vision-language tasks via pre-trained models

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.929583Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.441258Z digest=sha256:7a319da08b7487162eb5233f17437ee553e782e7222129e009e7a0f8aea67997

Observation 9c16cce2-a0f2-4c45-97da-395ce6ca2154 · outbound

This paper cites Sigmoid Loss for Language Image Pre-Training.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Sigmoid Loss for Language Image Pre-Training

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.445195Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.445195Z digest=sha256:598443da9a63e5b378d29731085bc6997bf9276b144ae5916e336bdc66fb0127

Observation a43b2de4-395d-4954-ab51-ac79f180d4f1 · outbound

This paper cites Towards adversarial attack on vision-language pre-training models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Towards adversarial attack on vision-language pre-training models

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.918793Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.449121Z digest=sha256:b4ab01a7c80591cafd00e60e7c622b2647c40fff64c812aa553072ff71f881d3

Observation 54dc0068-a54c-4b26-b7f1-045634ffd54f · outbound

This paper cites AnyAttack: Towards Large-scale Self-supervised Adversarial Attacks on Vision-language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models AnyAttack: Towards Large-scale Self-supervised Adversarial Attacks on Vision-language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.452461Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.452461Z digest=sha256:f95fd67c67e1adcef4a7d6cb24179815c4ed4e75438d0e150cacb14a71dfcc36

Observation 92dcd7cd-5107-40ce-b3eb-8bff966a0f68 · outbound

This paper cites On evaluating adversarial robustness of large vision-language models, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models On evaluating adversarial robustness of large vision-language models, 2023

Reference 81

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.907765Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.456215Z digest=sha256:07890b77e17640235aab22c87a045efe4cee9bea09d3e77151f337b0e23dc047

Observation 0b7d4655-e1a3-445b-a6f2-bbaf08593a3a · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.459651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.459651Z digest=sha256:029631335057c0ac59e95ed48389f133fdc718dabfc71b79a6d000672e8cf403

Observation ba8479a5-2b5a-49b7-9c2f-3f3480a5ea99 · outbound

This paper cites Zico Kolter, and Matt Fredrikson.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Zico Kolter, and Matt Fredrikson

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.463162Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.463162Z digest=sha256:4bcc2ea6c8c85eb252c4261f172341b5cf659929851fcb09a3149381dbdb7036

Observation 321b9f85-1b30-480c-aa8d-879559e90024 · outbound

This paper cites Improving Alignment and Robustness with Circuit Breakers.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Improving Alignment and Robustness with Circuit Breakers

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.466875Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.466875Z digest=sha256:75e21974df8953202d2b2d1ee352442a41b57fb5df54822d6ded64c402943be4

Pith citing papers

Observation 02d142aa-3a58-466f-8bc4-7634cb758e85 · inbound

AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery cites this paper.

AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T13:32:46.117270Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:32:46.117270Z digest=sha256:c6940801f8bb505295f64e2ea9d0b2bf674ab88c6830db1e4ceb834f3bbc976e

Observation 083f7259-0d1d-4bde-8eca-180cf529d63e · inbound

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition cites this paper.

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-15T17:47:19.126970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T17:47:19.126970Z digest=sha256:92564696f8f50cf466955668c154ee19c565a856c883077eb38759295bceb911

Observation 7718ef9e-c485-457e-85e4-0f6bf281c1b3 · inbound

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models cites this paper.

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-16T19:31:13.089502Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-05-16T19:29:43.382392Z digest=sha256:c8ed2920b18509f2bc54b4c21487ce2bec31f9205ab8ffc538c7d1fc8f95b639

Observation b65d8d1c-3f79-4555-8cf8-0ba3c20b67c9 · inbound

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models cites this paper.

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-03T14:05:23.148338Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T14:05:23.148338Z digest=sha256:ef15628eda2fd8f217ad632249aec824b2d7d48ca166c2082c80986e0023f14f

Observation 2385f503-96eb-40c1-99f4-b7e947b121da · inbound

Universal Adversarial Attacks against Closed-Source MLLMs via Target-View Routed Meta Optimization cites this paper.

Universal Adversarial Attacks against Closed-Source MLLMs via Target-View Routed Meta Optimization Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-16T09:27:40.991023Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-05-16T09:26:14.799360Z digest=sha256:4a1b18d7dc57d8e8efe85dad2aff47db5b6b7ea011ca9dfbeb3ff7f126e9d312

Observation 367a0044-35ea-4727-84dd-85f327c10403 · inbound

Laundering AI Authority with Adversarial Examples cites this paper.

Laundering AI Authority with Adversarial Examples Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-11T17:41:08.067046Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-05-08T17:19:38.662062Z digest=sha256:7c2d73a3c3b181b904b0ebcfb83145854b23fc1a2abf47c461475b9fe3d0b9aa

Observation 3f59c936-afc0-45cb-8666-d687fe540a52 · inbound

Frequency-Domain Regularized Adversarial Alignment for Transferable Attacks against Closed-Source MLLMs cites this paper.

Frequency-Domain Regularized Adversarial Alignment for Transferable Attacks against Closed-Source MLLMs Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-22T01:25:52.636726Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-05-22T01:25:06.528845Z digest=sha256:965ac40c09e2732b368c0132520dbdbf49602f750d496f8d55e52a7b051a1bbd

Observation c377a7fd-f605-4322-af3d-26b9ebffd054 · inbound

Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks cites this paper.

Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 57

Resolution
verified exact
arxiv_id, observed 2026-07-04T00:59:21.220186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=pdf_text observed=2026-06-26T20:44:41.268975Z digest=sha256:4b69a4e3cca6eb0384cafd0a290f6fdcd2f37b207ab83d30a4d2d92849f7eea9

Observation 4a2d34d4-02f9-4e9a-ac19-5bab80e8a762 · inbound

Steal the Patch Size: Adversarially Manipulate Vision-Language Models cites this paper.

Steal the Patch Size: Adversarially Manipulate Vision-Language Models Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 28

Resolution
metadata mismatch
arxiv_id, observed 2026-07-02T19:37:18.466063Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-16T06:30:59.297886+00:00.

source=arxiv_source observed=2026-07-02T19:30:19.691473Z digest=sha256:72a19bfe2a7027c6e941e648cfd40829ede870e077ab9d6a5d5ddbfa0a970cd3