---
格式版本: 2
标题: "Breaking the weakest link to evade vision language models"
原文链接: "https://arxiv.org/abs/2608.18938"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 19 Aug 2026 14:06:31 UTC (6,116 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:21:00+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:18:01+08:00"
入库时间: "2026-08-20T07:21:00.710Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=deployment&searchtype=all"
匹配关键词:
  - "deployment"
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 12
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为视觉语言模型对抗攻击，与超节点/AI Rack/机柜级AI基础设施完全无关，仅命中deployment一词。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:23:14+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 5
AI技术细节: 2
AI商业部署信号: 0
AI完整性: 5
AI摘要: "研究者提出一种仅优化视觉编码器的梯度攻击方法，能高效生成对抗样本，使Qwen2.5-VL、Granite-Vision、FastVLM和Phi-3.5-Vision等视觉语言模型在微小不可见扰动下输出被篡改的文本解释；"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:19:43.508Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.18938"
---

## Computer Science > Artificial Intelligence

## Title:Breaking the weakest link to evade vision language models

Authors:[Ilan Zini](https://arxiv.org/search/cs?searchtype=author&query=Zini,+I), [Boussad Addad](https://arxiv.org/search/cs?searchtype=author&query=Addad,+B), [Katarzyna Kapusta](https://arxiv.org/search/cs?searchtype=author&query=Kapusta,+K)

[View PDF](https://arxiv.org/pdf/2608.18938) [HTML (experimental)](https://arxiv.org/html/2608.18938v1)

> Abstract:Vision Language Models (VLMs) have recently emerged as a critical component of multimodal AI systems, enabling joint reasoning over visual and textual inputs in real-world and safety-critical applications. Despite their growing deployment, the robustness of VLMs against adversarial threats remains insufficiently explored, particularly in the context of evasion attacks targeting multimodal alignment. In this work, we investigate the vulnerability of VLMs to adversarial perturbations applied to visual inputs and study two attack settings: untargeted attacks, where the goal is to disrupt the model's interpretation of the original image, and targeted attacks, where the adversary aims to force the model to generate a specific semantic description unrelated to the original image. To efficiently generate adversarial examples, we propose a gradient-based attack method that performs optimization exclusively on the vision encoder of the VLM rather than on the entire multimodal architecture. This design significantly reduces the computational cost and resource requirements of the attack while maintaining strong effectiveness. We evaluate our approach on several open-source VLMs, including Qwen2.5-VL, Granite-Vision, FastVLM, and Phi-3.5-Vision, and show that small, human-imperceptible perturbations can substantially alter the textual interpretation produced by the models. Our findings highlight the vulnerability of modern VLMs to adversarial manipulation and emphasize the need for improved robustness and security mechanisms in multimodal AI systems.

| Comments: |  |
| --- | --- |
| Subjects: | Artificial Intelligence (cs.AI); Machine Learning (cs.LG) |
| Cite as: | [arXiv:2608.18938](https://arxiv.org/abs/2608.18938) \[cs.AI\] |
|  | (or [arXiv:2608.18938v1](https://arxiv.org/abs/2608.18938v1) \[cs.AI\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.18938](https://doi.org/10.48550/arXiv.2608.18938) |

## Submission history

From: Boussad Addad \[[view email](https://arxiv.org/show-email/23d2d035/2608.18938)\]  
**\[v1\]** Wed, 19 Aug 2026 14:06:31 UTC (6,116 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.18938) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
