{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:4Z2C6JZ43JA3G4GZCG6ZWU4EXZ","short_pith_number":"pith:4Z2C6JZ4","schema_version":"1.0","canonical_sha256":"e6742f273cda41b370d911bd9b5384be67126482607c826ec09e42793e86463a","source":{"kind":"arxiv","id":"2309.11751","version":2},"attestation_state":"computed","paper":{"title":"How Robust is Google's Bard to Adversarial Image Attacks?","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.LG"],"primary_cat":"cs.CV","authors_text":"Hang Su, Huanran Chen, Jiawei Chen, Jun Zhu, Xiao Yang, Yichi Zhang, Yinpeng Dong, Yu Tian, Zhengwei Fang","submitted_at":"2023-09-21T03:24:30Z","abstract_excerpt":"Multimodal Large Language Models (MLLMs) that integrate text and other modalities (especially vision) have achieved unprecedented performance in various multimodal tasks. However, due to the unsolved adversarial robustness problem of vision models, MLLMs can have more severe safety and security risks by introducing the vision inputs. In this work, we study the adversarial robustness of Google's Bard, a competitive chatbot to ChatGPT that released its multimodal capability recently, to better understand the vulnerabilities of commercial MLLMs. By attacking white-box surrogate vision encoders or"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2309.11751","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CV","submitted_at":"2023-09-21T03:24:30Z","cross_cats_sorted":["cs.AI","cs.CR","cs.LG"],"title_canon_sha256":"ef85f94575b4e9f6164251b701bdebd547fa8ac34bedcaa7c996acaa73c48e96","abstract_canon_sha256":"8be5842a28f877ee7288a88fd396905c4172d3cddd1a085b4770034df4fb718f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:01:05.787530Z","signature_b64":"k2bUTNqdqWVrLJLNdauSIbiciSMdk1N4IoDogjVVn1AcBNzsFTeMA8aJVvD5QNd+oUawBeVJ/oVfy2In3j8KBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e6742f273cda41b370d911bd9b5384be67126482607c826ec09e42793e86463a","last_reissued_at":"2026-07-05T07:01:05.787039Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:01:05.787039Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"How Robust is Google's Bard to Adversarial Image Attacks?","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.LG"],"primary_cat":"cs.CV","authors_text":"Hang Su, Huanran Chen, Jiawei Chen, Jun Zhu, Xiao Yang, Yichi Zhang, Yinpeng Dong, Yu Tian, Zhengwei Fang","submitted_at":"2023-09-21T03:24:30Z","abstract_excerpt":"Multimodal Large Language Models (MLLMs) that integrate text and other modalities (especially vision) have achieved unprecedented performance in various multimodal tasks. However, due to the unsolved adversarial robustness problem of vision models, MLLMs can have more severe safety and security risks by introducing the vision inputs. In this work, we study the adversarial robustness of Google's Bard, a competitive chatbot to ChatGPT that released its multimodal capability recently, to better understand the vulnerabilities of commercial MLLMs. By attacking white-box surrogate vision encoders or"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2309.11751","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2309.11751/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2309.11751","created_at":"2026-07-05T07:01:05.787096+00:00"},{"alias_kind":"arxiv_version","alias_value":"2309.11751v2","created_at":"2026-07-05T07:01:05.787096+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2309.11751","created_at":"2026-07-05T07:01:05.787096+00:00"},{"alias_kind":"pith_short_12","alias_value":"4Z2C6JZ43JA3","created_at":"2026-07-05T07:01:05.787096+00:00"},{"alias_kind":"pith_short_16","alias_value":"4Z2C6JZ43JA3G4GZ","created_at":"2026-07-05T07:01:05.787096+00:00"},{"alias_kind":"pith_short_8","alias_value":"4Z2C6JZ4","created_at":"2026-07-05T07:01:05.787096+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":24,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.07375","citing_title":"On Adversarial Vulnerability of Vision-Language Models through the Lens of Intermediate Spectral Subspaces","ref_index":13,"is_internal_anchor":true},{"citing_arxiv_id":"2606.23892","citing_title":"REALM: A Unified Red-Teaming Benchmark for Physical-World VLMs","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09125","citing_title":"Unveiling Privacy Risks in Multi-modal Large Language Models: Task-specific Vulnerabilities and Mitigation Challenges","ref_index":84,"is_internal_anchor":false},{"citing_arxiv_id":"2607.00174","citing_title":"Steal the Patch Size: Adversarially Manipulate Vision-Language Models","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26501","citing_title":"Unveiling the Fragility of Vision-Language Models: Multi-Modal Adversarial Synergy via Texture-Constrained Perturbations and Cross-Modal Optimization","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2606.07706","citing_title":"MLingualFC: Evaluating Jailbreak Vulnerabilities in Multilingual Vision-Language Models","ref_index":102,"is_internal_anchor":false},{"citing_arxiv_id":"2408.12935","citing_title":"AI Safety Landscape for Large Language Models: Taxonomy, State-of-the-art, and Future Directions","ref_index":183,"is_internal_anchor":false},{"citing_arxiv_id":"2412.14113","citing_title":"Adversarial Hubness in Multi-Modal Retrieval","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21541","citing_title":"Frequency-Domain Regularized Adversarial Alignment for Transferable Attacks against Closed-Source MLLMs","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.20654","citing_title":"REFLECTOR: Internalizing Step-wise Reflection against Indirect Jailbreak","ref_index":50,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18868","citing_title":"DarkLLM: Learning Language-Driven Adversarial Attacks with Large Language Models","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17310","citing_title":"Attention Hijacking: Response Manipulation Across Queries in Vision-Language Models","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18915","citing_title":"DMN: A Compositional Framework for Jailbreaking Multimodal LLMs with Multi-Image Inputs","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2601.23179","citing_title":"Universal Adversarial Attacks against Closed-Source MLLMs via Target-View Routed Meta Optimization","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2602.07892","citing_title":"Safety Alignment as Continual Learning: Mitigating the Alignment Tax via Orthogonal Gradient Projection","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09574","citing_title":"Turing Test on Screen: A Benchmark for Mobile GUI Agent Humanization","ref_index":42,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01758","citing_title":"Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11716","citing_title":"SafeSteer: A Decoding-level Defense Mechanism for Multimodal Large Language Models","ref_index":15,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10582","citing_title":"Guaranteed Jailbreaking Defense via Disrupt-and-Rectify Smoothing","ref_index":46,"is_internal_anchor":false},{"citing_arxiv_id":"2604.25102","citing_title":"One Perturbation, Two Failure Modes: Probing VLM Safety via Embedding-Guided Typographic Perturbations","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01758","citing_title":"Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01758","citing_title":"Catching the Infection Before It Spreads: Foresight-Guided Defense in Multi-Agent Systems","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07250","citing_title":"Hard to Read, Easy to Jailbreak: How Visual Degradation Bypasses MLLM Safety Alignment","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04473","citing_title":"Beyond Standard Benchmarks: A Systematic Audit of Vision-Language Model's Robustness to Natural Semantic Variation Across Diverse Tasks","ref_index":9,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ","json":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ.json","graph_json":"https://pith.science/api/pith-number/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/graph.json","events_json":"https://pith.science/api/pith-number/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/events.json","paper":"https://pith.science/paper/4Z2C6JZ4"},"agent_actions":{"view_html":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ","download_json":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ.json","view_paper":"https://pith.science/paper/4Z2C6JZ4","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2309.11751&json=true","fetch_graph":"https://pith.science/api/pith-number/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/graph.json","fetch_events":"https://pith.science/api/pith-number/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/action/storage_attestation","attest_author":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/action/author_attestation","sign_citation":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/action/citation_signature","submit_replication":"https://pith.science/pith/4Z2C6JZ43JA3G4GZCG6ZWU4EXZ/action/replication_record"}},"created_at":"2026-07-05T07:01:05.787096+00:00","updated_at":"2026-07-05T07:01:05.787096+00:00"}