🧪 Test?View on arXiv
It Takes Little to Rewrite Perception: Targeted Semantic Substitution in Vision-Language Models at $\epsilon \leq 4/255$
Author1, Author2, Author3, Author4, Author5
adversarial attacksvision-language modelssemantic substitutionrobustness
2609.38298
Builder Relevance
1h ago70%
Abstract
This paper investigates the vulnerability of Vision Language Models to targeted semantic substitutions through adversarial perturbations.
Reality Card
Core Claim
Targeted semantic substitution in Vision Language Models can succeed at perturbation levels as low as $\varepsilon = 2/255$.
Method / Result
Complete semantic replacement in images reaches 38% success at $\varepsilon = 4/255$.
Limitations
The study operates under a white-box threat model, which may limit generalizability to black-box scenarios.
Paper to code
Verified implementation resources so builders can test the paper’s claims instead of stopping at the abstract.
No verified implementation link has been attached yet. AIBuzzHub will keep this panel separate from unverified search results.