发现视觉语言模型对细微改动极不稳健,稳定预测更可能正确。
Questioning the Stability of Visual Question Answering
- 系统测试了图像和文本的微小变化对模型影响
- 多数样本在几像素偏移或简单改写后答案就变了
- 模型稳定性可预测大模型正确性,适合评估可靠性
视觉语言模型虽进步显著,但对微小、语义不变的输入变化仍缺乏可靠性理解。本文首次开展大规模系统性研究,考察模型对像素级移动、轻量几何变换、填充缩放、同义改写及多语言重述等良性扰动的鲁棒性。在多个模型与数据集上,现代视觉语言模型表现出高度敏感性:大量样本在任一扰动下预测结果均发生变化。我们分析了不同扰动类型、问题类别和模型间的不稳定性差异,发现即使最先进的系统(如 GPT-4o、Gemini 2.0 Flash)在仅几像素位移或无害改写下也频繁出错。进一步发现,样本级稳定性是正确性的强指标:稳定预测的样本远更可能答对。基于此,我们证明小型开源模型的稳定性模式可高精度预测大型闭源模型的正确性。研究揭示当前VLM存在根本性脆弱性,呼吁超越对抗性扰动,关注应具备的内在不变性评估。
原文摘要 · Abstract (English)
Visual Language Models (VLMs) have achieved remarkable progress, yet their reliability under small, meaning-preserving input changes remains poorly understood. We present the first large-scale, systematic study of VLM robustness to benign visual and textual perturbations: pixel-level shifts, light geometric transformations, padded rescaling, paraphrasing, and multilingual rewrites that do not alter the underlying semantics of an image-question pair. Across a broad set of models and datasets, we find that modern VLMs are highly sensitive to such minor perturbations: a substantial fraction of samples change their predicted answer under at least one visual or textual modification. We characterize how this instability varies across perturbation types, question categories, and models, revealing that even state-of-the-art systems (e.g., GPT-4o, Gemini 2.0 Flash) frequently fail under shifts as small as a few pixels or harmless rephrasings. We further show that sample-level stability serves as a strong indicator of correctness: stable samples are consistently far more likely to be answered correctly. Leveraging this, we demonstrate that the stability patterns of small, accessible open-source models can be used to predict the correctness of much larger closed-source models with high precision. Our findings expose a fundamental fragility in current VLMs and highlight the need for robustness evaluations that go beyond adversarial perturbations, focusing instead on invariances that models should reliably uphold.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。