构建首个大规模真实字体攻击数据集,揭示多模态模型的视觉文字漏洞。
SCAM: A Real-World Typographic Robustness Evaluation for Multimodal Foundation Models

- 构建包含1162张图像的实拍字体攻击数据集,覆盖数百类别
- 顶尖多模态模型在攻击下性能显著下降,视觉编码器越脆弱越易受攻
- 大语言模型主干可降低风险,合成攻击可替代真实攻击研究
字体攻击利用多模态基础模型中文本与视觉内容的交互,当误导性文本嵌入图像时引发误分类。现有数据集规模小、多样性不足,难以深入研究此类漏洞。本文提出SCAM,目前最大最多样化的现实世界字体攻击图像数据集,包含1162张图像,覆盖数百个物体类别和攻击词汇。在SCAM上对视觉-语言模型进行广泛基准测试表明,字体攻击会显著降低模型性能,并发现训练数据与模型架构影响其脆弱性。研究显示,即使最先进的大视觉-语言模型仍易受攻击,尤其那些使用对字体攻击敏感的视觉编码器的模型。然而,采用更大的大语言模型主干可减少脆弱性,同时提升对字体内容的理解能力。此外,我们验证了合成攻击与真实手写攻击高度相似,支持其在研究中的有效性。本文公开发布数据集及评估代码,网址:www.bliss.berlin/research/scam,为构建更鲁棒、可信的多模态AI系统提供全面资源与实证洞察。
原文摘要 · Abstract (English)
Typographic attacks exploit the interplay between text and visual content in multimodal foundation models, causing misclassifications when misleading text is embedded within images. Existing datasets are limited in size and diversity, making it difficult to study such vulnerabilities. In this paper, we introduce SCAM, the largest and most diverse dataset of real-world typographic attack images to date, containing 1162 images across hundreds of object categories and attack words. Through extensive benchmarking of Vision-Language Models on SCAM, we demonstrate that typographic attacks significantly degrade performance, and identify that training data and model architecture influence the susceptibility to these attacks. Our findings indicate that typographic attacks remain effective against state-of-the-art Large Vision-Language Models, especially those employing vision encoders inherently vulnerable to such attacks. However, employing larger Large Language Model backbones reduces this vulnerability while simultaneously enhancing typographic understanding. Additionally, we demonstrate that synthetic attacks closely resemble real-world (handwritten) attacks, validating their use in research. Our work provides a comprehensive resource and empirical insights to facilitate future research toward robust and trustworthy multimodal AI systems. Finally, we publicly release the datasets introduced in this paper, along with the code for evaluations under www.bliss.berlin/research/scam.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。