{"id":"https://openalex.org/W4403346140","doi":"https://doi.org/10.48550/arxiv.2410.05346","title":"AnyAttack: Towards Large-scale Self-supervised Generation of Targeted\n Adversarial Examples for Vision-Language Models","display_name":"AnyAttack: Towards Large-scale Self-supervised Generation of Targeted\n Adversarial Examples for Vision-Language Models","publication_year":2024,"publication_date":"2024-10-07","ids":{"openalex":"https://openalex.org/W4403346140","doi":"https://doi.org/10.48550/arxiv.2410.05346"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.05346","pdf_url":"http://arxiv.org/pdf/2410.05346","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://arxiv.org/pdf/2410.05346","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100453782","display_name":"Jiaming Zhang","orcid":"https://orcid.org/0000-0003-0991-7109"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Jiaming","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002681649","display_name":"Junhong Ye","orcid":"https://orcid.org/0000-0003-0948-5115"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ye, Junhong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078711649","display_name":"Xingjun Ma","orcid":"https://orcid.org/0000-0003-2099-4973"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ma, Xingjun","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101879293","display_name":"Yige Li","orcid":"https://orcid.org/0000-0002-9904-3611"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Yige","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100314060","display_name":"Yunfan Yang","orcid":"https://orcid.org/0000-0002-4307-5569"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yang, Yunfan","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023834030","display_name":"Jitao Sang","orcid":"https://orcid.org/0000-0002-0699-3205"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sang, Jitao","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5073139380","display_name":"Dit\u2010Yan Yeung","orcid":"https://orcid.org/0000-0003-3716-8125"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yeung, Dit-Yan","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":77},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9923,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9923,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11714","display_name":"Multimodal Machine Learning Applications","score":0.9758,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9723,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.83026373},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.62180424},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5733369},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.50525004},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.41359234},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.39738858},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.3513876},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.33885312},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.12614438},{"id":"https://openalex.org/C58640448","wikidata":"https://www.wikidata.org/wiki/Q42515","display_name":"Cartography","level":1,"score":0.098370105}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.05346","pdf_url":"http://arxiv.org/pdf/2410.05346","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2410.05346","pdf_url":"http://arxiv.org/pdf/2410.05346","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4310988119","https://openalex.org/W4297672492","https://openalex.org/W4288019534","https://openalex.org/W4285226279","https://openalex.org/W4246396837","https://openalex.org/W3191453585","https://openalex.org/W3126451824","https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W1561927205"],"abstract_inverted_index":{"Due":[0],"to":[1,25,37,53,90,181,199],"their":[2,60],"multimodal":[3,161,165],"capabilities,":[4],"Vision-Language":[5],"Models":[6],"(VLMs)":[7],"have":[8,19],"found":[9],"numerous":[10],"impactful":[11],"applications":[12],"in":[13],"real-world":[14],"scenarios.":[15],"However,":[16],"recent":[17],"studies":[18],"revealed":[20],"that":[21,33,77,105,114],"VLMs":[22,83,152],"are":[23],"vulnerable":[24],"image-based":[26],"adversarial":[27,31,56,80,129],"attacks,":[28,57],"particularly":[29],"targeted":[30,55,79,128],"images":[32,81],"manipulate":[34],"the":[35,43,96,100,171,202],"model":[36],"generate":[38],"harmful":[39],"content":[40],"specified":[41],"by":[42],"adversary.":[44],"Current":[45],"attack":[46],"methods":[47,104],"rely":[48],"on":[49,118,148],"predefined":[50],"target":[51,94],"labels":[52],"create":[54],"which":[58],"limits":[59],"scalability":[61],"and":[62,157,167,190],"applicability":[63],"for":[64,82,95,126,204],"large-scale":[65,120,132],"robustness":[66],"evaluations.":[67],"In":[68],"this":[69],"paper,":[70],"we":[71,109,177],"propose":[72],"AnyAttack,":[73],"a":[74,93,111,116,119,141],"self-supervised":[75],"framework":[76],"generates":[78],"without":[84],"label":[85,107],"supervision,":[86,108],"allowing":[87],"any":[88],"image":[89,122,168],"serve":[91],"as":[92],"attack.":[97,175],"To":[98],"address":[99],"limitation":[101],"of":[102,144,173],"existing":[103],"require":[106],"introduce":[110],"contrastive":[112],"loss":[113],"trains":[115],"generator":[117],"unlabeled":[121],"dataset,":[123,125],"LAION-400M":[124],"generating":[127],"noise.":[130],"This":[131],"pre-training":[133],"endows":[134],"our":[135,174],"method":[136],"with":[137],"powerful":[138],"transferability":[139],"across":[140,159],"wide":[142],"range":[143],"VLMs.":[145],"Extensive":[146],"experiments":[147],"five":[149],"mainstream":[150],"open-source":[151],"(CLIP,":[153],"BLIP,":[154],"BLIP2,":[155],"InstructBLIP,":[156],"MiniGPT-4)":[158],"three":[160],"tasks":[162],"(image-text":[163],"retrieval,":[164],"classification,":[166],"captioning)":[169],"demonstrate":[170],"effectiveness":[172],"Additionally,":[176],"successfully":[178],"transfer":[179],"AnyAttack":[180],"multiple":[182],"commercial":[183],"VLMs,":[184,200],"including":[185],"Google's":[186],"Gemini,":[187],"Claude's":[188],"Sonnet,":[189],"Microsoft's":[191],"Copilot.":[192],"These":[193],"results":[194],"reveal":[195],"an":[196],"unprecedented":[197],"risk":[198],"highlighting":[201],"need":[203],"effective":[205],"countermeasures.":[206]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4403346140","counts_by_year":[],"updated_date":"2025-04-23T18:09:43.630969","created_date":"2024-10-12"}