arXiv Machine Learning

MemCatalyst: Amplifying Data Auditing on Vision-Language Models via Data Poisoning

MemCatalyst is a set of data poisoning tools designed to improve data auditing for Vision‑Language Models (VLMs). It introduces two poisoning strategies—Poisoning Text and Poisoning Image—to force VLMs to over‑learn inconsistencies between image features and textual semantics, thereby increasing their vulnerability to membership inference attacks. Experiments on two prominent VLMs show that MemCatalyst significantly boosts MI AUC scores with a small number of poisoned samples while barely affecting overall model performance.

arXiv AI
Aug 24

Vis-Poison: Poisoning Visual Knowledge in Multimodal Retrieval-Augmented Generation

Vis-Poison is a novel attack that poisons multimodal retrieval-augmented generation systems by inserting attacker-controlled images as visual evidence, without altering any textual metadata. The attack uses an automated multi-agent approach to create visually plausible poisoned images and has been tested on two multimodal RAG pipelines, four embedding models, and six generation models. In black-box settings, Vis-Poison achieves an end-to-end success rate between 40.16% and 65.40% against 30,000-entry knowledge bases, and remains effective against various multimodal large language models with an average success rate above 60%.

By Rujin Liang, Zhongpu Chen, Yuhao Lei, Xin Miao
arXiv AI
Jun 26

MMGist: A Comprehensive Multimodal Benchmark for 2027

arXiv:2606. 22437v2 Announce Type: replace-cross Abstract: We conduct a systematic study of 18 widely used vision-language benchmarks and identify three major issues: 1) many items do not rely on visual cues and therefore fail to effectively measure multimodal understanding; 2) many items are already close to performance saturation for current LVLMs, which limits their discriminative power; 3) a small number of anomalous items affect the reliability of evaluation results.

By Wenzhen Yuan, Jiacheng Ruan, Wutao Xiong, Chengping Zhao, Ting Liu, Yuzhuo Fu
arXiv AI
Sep 18

Fingerprinting Multimodal Large Language Models

The paper introduces AttnPrint, a white‑box fingerprinting method that extracts low‑frequency components of cross‑modal attention distributions to identify multimodal large language models (MLLMs). It also presents DistillTrace, a black‑box auditing tool that uses hypothesis testing of MLLM outputs to detect potential model infringement. Experiments on 154 model instances across 19 architectures show that AttnPrint effectively detects derivative models and remains robust to downstream modifications, while DistillTrace reveals distillation relationships under various techniques.

By Chao Huang, Meng Tong, Kejiang Chen
arXiv Machine Learning
Jul 16

When T2I Synthetic Data Backfires: Amplified Privacy Risks in Real-Synthetic Mix Training

arXiv:2607. 13541v1 Announce Type: cross Abstract: To overcome data scarcity and privacy constraints in data collection, it has become standard practice across academia and industry to augment real training data with text-to-image (T2I)-generated synthetic data, a paradigm we term Real-Synthetic Mix-Training (RSMT).

By Na Li, Boyu Kuang, Hongsheng Hu, Liquan Chen, Hyoungshick Kim, Yansong Gao, Anmin Fu