AI

Vis-Poison: Poisoning Visual Knowledge in Multimodal Retrieval-Augmented Generation

Researchers have developed a new attack method called Vis-Poison that can compromise multimodal large language models (MLLMs) by introducing poisoned visual evidence. Unlike previous attacks that alter textual metadata, Vis-Poison manipulates the images themselves to deceive the model. The authors evaluated Vis-Poison across multiple MLLMs and found it to be effective in compromising their performance, with an average success rate of over 60%. This raises concerns about the s
Researchers have developed a new attack method called Vis-Poison that can compromise multimodal large language models (MLLMs) by introducing poisoned visual evidence. Unlike previous attacks that alter textual metadata, Vis-Poison manipulates the images themselves to deceive the model. The authors evaluated Vis-Poison across multiple MLLMs and found it to be effective in compromising their performance, with an average success rate of over 60%. This raises concerns about the security of MLLMs that rely on visual knowledge sources. --- Why it matters: This matters because multimodal large language models are increasingly being used in applications where accuracy is critical, such as search engines and recommendation systems. A successful attack like Vis-Poison could compromise their performance and lead to incorrect or misleading results. Source: https://arxiv.org/abs/2608.20756

This article was originally published at: https://arxiv.org/abs/2608.20756