通过诱导数值不稳定性,小改动图像就能让多模态大模型严重失效。
Induced Numerical Instability: Hidden Costs in Multimodal Large Language Models
- 设计新损失函数,专门在推理阶段放大模型数值不稳定性。
- 微小图像改动使多个主流模型在多个数据集上性能大幅下降。
- 揭示了不同于对抗攻击的新故障模式,对模型安全有重要启示。
多模态大语言模型的应用日益广泛,研究其故障机制变得至关重要。本文揭示了一种新型故障模式:通过优化一个旨在最大化模型推理阶段数值不稳定的损失项,构造特定图像,使多模态大模型在输入时产生显著性能退化。我们在最新模型(LLaVa-v1.5-7B、Idefics3-8B、SmolVLM-2B-Instruct)上验证该现象,使用标准数据集(Flickr30k、MMVet、TextVQA、VQAv2、POPE、COCO),发现仅需微小的图像变化,模型性能即出现显著下降,远超基线表现。该结果揭示了一种此前未被对抗扰动捕捉的根本性性能退化路径。
原文摘要 · Abstract (English)
The use of multimodal large language models has become widespread, and as such the study of these models and their failure points has become of utmost importance. We study a novel mode of failure that causes degradation in performance indirectly by optimizing a loss term that seeks to maximize numerical instability in the inference stage of these models. We apply this loss term as the optimization target to construct images that, when used on multimodal large language models, cause significant degradation in the output. We validate our hypothesis on state of the art models large vision language models (LLaVa-v1.5-7B, Idefics3-8B, SmolVLM-2B-Instruct) against standard datasets (Flickr30k, MMVet, TextVQA, VQAv2, POPE, COCO) and show that performance degrades significantly, even with a very small change to the input image, compared to baselines. Our results uncover a fundamentally different vector of performance degradation, highlighting a failure mode not captured by adversarial perturbations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。