Vis-Poison: Poisoning Visual Knowledge in Multimodal Retrieval-Augmented Generation
Vis-Poison:多模态检索增强生成中的视觉知识投毒攻击
机构 * Southwestern University of Finance and Economics(西南财经大学) ; Nanjing University of Science and Technology(南京理工大学)
专题命中 其他VLM :MLLM(summary_cn,abstract);multimodal large language model(abstract);分类 cs.CV、cs.AI
AI总结 本文提出Vis-Poison攻击,通过自动化多智能体方法构建视觉合理的被投毒图像,在黑盒设置下对多模态RAG系统实现40.16%-65.40%的攻击成功率,且对仅依赖参数知识的MLLM平均成功率超60%。
Comments Findings of EMNLP, 2026