{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:EVKK4TPG2ST3N7AIVFICRU3373","short_pith_number":"pith:EVKK4TPG","schema_version":"1.0","canonical_sha256":"2554ae4de6d4a7b6fc08a95028d37bfef72055650c65eb855a3d1cfb46be8e26","source":{"kind":"arxiv","id":"2402.08577","version":1},"attestation_state":"computed","paper":{"title":"Test-Time Backdoor Attacks on Multimodal Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG","cs.MM"],"primary_cat":"cs.CL","authors_text":"Chao Du, Dong Lu, Min Lin, Qian Liu, Tianyu Pang, Xianjun Yang","submitted_at":"2024-02-13T16:28:28Z","abstract_excerpt":"Backdoor attacks are commonly executed by contaminating training data, such that a trigger can activate predetermined harmful effects during the test phase. In this work, we present AnyDoor, a test-time backdoor attack against multimodal large language models (MLLMs), which involves injecting the backdoor into the textual modality using adversarial test images (sharing the same universal perturbation), without requiring access to or modification of the training data. AnyDoor employs similar techniques used in universal adversarial attacks, but distinguishes itself by its ability to decouple th"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2402.08577","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2024-02-13T16:28:28Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG","cs.MM"],"title_canon_sha256":"8f85d2dfa6fc77cb74c6d1ef93331a4997775644c05dea7eb7461ae1ab49b58d","abstract_canon_sha256":"1a2d39b2275e3f7dff7a0eb8b434a7e203438cbd246d643ef1d46044a8a5bb2c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:44:48.458308Z","signature_b64":"Tyox27oVADjEliDWEMZdx6nepdekai3h4Iita4K6sfXJtvUlGpZYUMb6HR3DJeXyEmQ/8fIL4V5mjQrpLrimAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2554ae4de6d4a7b6fc08a95028d37bfef72055650c65eb855a3d1cfb46be8e26","last_reissued_at":"2026-07-05T07:44:48.457756Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:44:48.457756Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Test-Time Backdoor Attacks on Multimodal Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG","cs.MM"],"primary_cat":"cs.CL","authors_text":"Chao Du, Dong Lu, Min Lin, Qian Liu, Tianyu Pang, Xianjun Yang","submitted_at":"2024-02-13T16:28:28Z","abstract_excerpt":"Backdoor attacks are commonly executed by contaminating training data, such that a trigger can activate predetermined harmful effects during the test phase. In this work, we present AnyDoor, a test-time backdoor attack against multimodal large language models (MLLMs), which involves injecting the backdoor into the textual modality using adversarial test images (sharing the same universal perturbation), without requiring access to or modification of the training data. AnyDoor employs similar techniques used in universal adversarial attacks, but distinguishes itself by its ability to decouple th"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2402.08577","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2402.08577/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2402.08577","created_at":"2026-07-05T07:44:48.457834+00:00"},{"alias_kind":"arxiv_version","alias_value":"2402.08577v1","created_at":"2026-07-05T07:44:48.457834+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2402.08577","created_at":"2026-07-05T07:44:48.457834+00:00"},{"alias_kind":"pith_short_12","alias_value":"EVKK4TPG2ST3","created_at":"2026-07-05T07:44:48.457834+00:00"},{"alias_kind":"pith_short_16","alias_value":"EVKK4TPG2ST3N7AI","created_at":"2026-07-05T07:44:48.457834+00:00"},{"alias_kind":"pith_short_8","alias_value":"EVKK4TPG","created_at":"2026-07-05T07:44:48.457834+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":8,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.12586","citing_title":"Beyond Attack Success Rate: Examining Trigger Leakage in Vision-Language Agentic Systems","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2607.00361","citing_title":"ReShift: Aha-Moment-Driven Reasoning-Level Backdoor Attacks on Vision-Language Models","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2606.02947","citing_title":"BYORn: Bootstrap Your Own Responses to Defend Large Vision-Language Models Against Backdoor Attacks","ref_index":48,"is_internal_anchor":false},{"citing_arxiv_id":"2502.05206","citing_title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","ref_index":296,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15711","citing_title":"EntropyScan: Towards Model-level Backdoor Detection in LVLMs via Visual Attention Entropy","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19083","citing_title":"ProjLens: Unveiling the Role of Projectors in Multimodal Model Safety","ref_index":162,"is_internal_anchor":false},{"citing_arxiv_id":"2604.08395","citing_title":"Phantasia: Context-Adaptive Backdoors in Vision Language Models","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04630","citing_title":"Multimodal Backdoor Attack on VLMs for Autonomous Driving via Graffiti and Cross-Lingual Triggers","ref_index":50,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373","json":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373.json","graph_json":"https://pith.science/api/pith-number/EVKK4TPG2ST3N7AIVFICRU3373/graph.json","events_json":"https://pith.science/api/pith-number/EVKK4TPG2ST3N7AIVFICRU3373/events.json","paper":"https://pith.science/paper/EVKK4TPG"},"agent_actions":{"view_html":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373","download_json":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373.json","view_paper":"https://pith.science/paper/EVKK4TPG","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2402.08577&json=true","fetch_graph":"https://pith.science/api/pith-number/EVKK4TPG2ST3N7AIVFICRU3373/graph.json","fetch_events":"https://pith.science/api/pith-number/EVKK4TPG2ST3N7AIVFICRU3373/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373/action/timestamp_anchor","attest_storage":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373/action/storage_attestation","attest_author":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373/action/author_attestation","sign_citation":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373/action/citation_signature","submit_replication":"https://pith.science/pith/EVKK4TPG2ST3N7AIVFICRU3373/action/replication_record"}},"created_at":"2026-07-05T07:44:48.457834+00:00","updated_at":"2026-07-05T07:44:48.457834+00:00"}