{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:15:51Z","timestamp":1777889751660,"version":"3.51.4"},"reference-count":39,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00105","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"1048-1057","source":"Crossref","is-referenced-by-count":0,"title":["Web Artifact Attacks Disrupt Vision Language Models"],"prefix":"10.1109","author":[{"given":"Maan","family":"Qraitem","sequence":"first","affiliation":[{"name":"Boston University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Piotr","family":"Teterwak","sequence":"additional","affiliation":[{"name":"Boston University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kate","family":"Saenko","sequence":"additional","affiliation":[{"name":"Boston University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bryan A.","family":"Plummer","sequence":"additional","affiliation":[{"name":"Boston University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Evaluating clip: towards characterization of broader capabilities and downstream implications","author":"Agarwal","year":"2021","journal-title":"arXiv preprint"},{"key":"ref2","article-title":"Jaided AI","volume-title":"EasyOCR: Ready-to-use ocr with 80+ supported languages and growing","year":"2020"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW60793.2023.00392"},{"key":"ref4","article-title":"Abusing images and sounds for indirect instruction injection in multi-modal 11 ms","author":"Bagdasaryan","year":"2023","journal-title":"arXiv preprint"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-50396-2_24"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr46437.2021.00356"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3033291"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73202-7_11"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref10","article-title":"Query-efficient meta attack to deep neural networks","author":"Du","journal-title":"arXiv preprint"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1179"},{"key":"ref12","article-title":"Vision-language models performing zeroshot tasks exhibit gender-based disparities","author":"Hall","year":"2023","journal-title":"arXiv preprint"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.eacl-main.126"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/WACV48630.2021.00159"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01922"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72946-1_21"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1516"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref21","article-title":"Fine-grained visual classification of aircraft","author":"Maji","year":"2013","journal-title":"arXiv preprint"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01592"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/iccv51070.2023.01851"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01945"},{"key":"ref26","article-title":"Vision-llms can fool themselves with self-generated typographic attacks","author":"Qraitem","year":"2024","journal-title":"arXiv preprint"},{"key":"ref27","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"International conference on machine learning","author":"Radford","year":"2021"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00764"},{"key":"ref29","article-title":"Laion- 400 m: Open dataset of clip-filtered 400 million image-text pairs","author":"Schuhmann","year":"2021","journal-title":"arXiv preprint"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1833"},{"key":"ref31","article-title":"Jailbreak in pieces: Compositional adversarial attacks on multimodal language models","author":"Shayegani","year":"2023","journal-title":"arXiv preprint"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/2812802"},{"key":"ref33","article-title":"Ravl: Discovering and mitigating spurious correlations in fine-tuned vision-language models","author":"Varma","year":"2024","journal-title":"arXiv preprint"},{"key":"ref34","article-title":"A sober look at the robustness of clips to spurious features","volume-title":"The Thirty-eighth Annual Conference on Neural Information Processing Systems","author":"Wang","year":"2024"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00765"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01100"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.aacl-main.40"},{"key":"ref38","article-title":"Minigpt-4: Enhancing vision-language understanding with advanced large language models","author":"Zhu","year":"2023","journal-title":"arXiv preprint"},{"key":"ref39","first-page":"12868","article-title":"Sparse and imperceptible adversarial attack via a homotopy algorithm","volume-title":"International Conference on Machine Learning","author":"Zhu","year":"2021"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11443392.pdf?arnumber=11443392","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:16:38Z","timestamp":1777612598000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11443392\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":39,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00105","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}