{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T14:36:05Z","timestamp":1784644565294,"version":"3.55.0"},"reference-count":82,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFC2508704"],"award-info":[{"award-number":["2023YFC2508704"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62236008"],"award-info":[{"award-number":["62236008"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62022083"],"award-info":[{"award-number":["62022083"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21B2038"],"award-info":[{"award-number":["U21B2038"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3586430","type":"journal-article","created":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T13:48:26Z","timestamp":1751896106000},"page":"7091-7105","source":"Crossref","is-referenced-by-count":4,"title":["Enhancing the Robustness of Vision-Language Foundation Models by Alignment Perturbation"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5269-7749","authenticated-orcid":false,"given":"Cong","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Intelligence Science and Technology, University of Science and Technology Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5931-0527","authenticated-orcid":false,"given":"Shuhui","family":"Wang","sequence":"additional","affiliation":[{"name":"Chinese Academy of Sciences, Institute of Computing Technology, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5025-4805","authenticated-orcid":false,"given":"Xiaodan","family":"Li","sequence":"additional","affiliation":[{"name":"Alibaba Group, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0991-1970","authenticated-orcid":false,"given":"Yao","family":"Zhu","sequence":"additional","affiliation":[{"name":"Department of Automation, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7947-1491","authenticated-orcid":false,"given":"Honggang","family":"Qi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7542-296X","authenticated-orcid":false,"given":"Qingming","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Frozen transformers in language models are effective visual encoder layers","volume-title":"Proc. 12th Int. Conf. Learn. Represent.","author":"Pang"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01457"},{"key":"ref3","article-title":"Meta-transformer: A unified framework for multimodal learning","author":"Zhang","year":"2023","journal-title":"arXiv:2307.10802"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01046"},{"key":"ref5","article-title":"DiagGPT: An LLM-based and multi-agent dialogue system with automatic topic management for flexible task-oriented dialogue","author":"Cao","year":"2023","journal-title":"arXiv:2308.08043"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3435138"},{"key":"ref7","article-title":"Making LLaMA SEE and draw with SEED tokenizer","author":"Ge","year":"2023","journal-title":"arXiv:2310.01218"},{"key":"ref8","article-title":"Planting a SEED of vision in large language model","author":"Ge","year":"2023","journal-title":"arXiv:2307.08041"},{"key":"ref9","article-title":"Qwen-VL: A versatile vision-language model for understanding, localization, text reading, and beyond","author":"Bai","year":"2023","journal-title":"arXiv:2308.12966"},{"key":"ref10","first-page":"19730","article-title":"BLIP-2: Bootstrapping language-image pre-training with frozen image encoders and large language models","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Li"},{"key":"ref11","first-page":"34892","article-title":"Visual instruction tuning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Liu"},{"key":"ref12","article-title":"PandaGPT: One model to instruction-follow them all","author":"Su","year":"2023","journal-title":"arXiv:2305.16355"},{"key":"ref13","article-title":"NExT-GPT: Any-to-any multimodal LLM","author":"Wu","year":"2023","journal-title":"arXiv:2309.05519"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00022"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01165"},{"key":"ref16","article-title":"Evaluating the susceptibility of pre-trained language models via handcrafted adversarial examples","author":"Branch","year":"2022","journal-title":"arXiv:2209.02128"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW60793.2023.00395"},{"key":"ref18","first-page":"54111","article-title":"On evaluating adversarial robustness of large vision-language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Zhao"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02306"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02327"},{"key":"ref21","article-title":"LLM lies: Hallucinations are not bugs, but features as adversarial examples","author":"Yao","year":"2023","journal-title":"arXiv:2310.01469"},{"key":"ref22","article-title":"How robust is Google\u2019s bard to adversarial image attacks?","author":"Dong","year":"2023","journal-title":"arXiv:2309.11751"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref24","article-title":"DeCo: Decoupling token compression from semantic abstraction in multimodal large language models","author":"Yao","year":"2024","journal-title":"arXiv:2405.20985"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00020"},{"key":"ref26","first-page":"27140","article-title":"Improving out-of-distribution generalization by adversarial training with structured priors","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Wang"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01306"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01305"},{"key":"ref29","first-page":"32897","article-title":"VLMo: Unified vision-language pre-training with mixture-of-modality-experts","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"35","author":"Wang"},{"key":"ref30","article-title":"CogVLM: Visual expert for pretrained language models","author":"Wang","year":"2023","journal-title":"arXiv:2311.03079"},{"key":"ref31","first-page":"1","article-title":"On the road with GPT-4V(ision): Explorations of utilizing visual-language model as autonomous driving agent","volume-title":"Proc. ICLR Workshop Large Lang. Model (LLM) Agents","author":"Wen"},{"key":"ref32","volume-title":"From Images to Textual Prompts: Zero-shot VQA With Frozen Large Language Models","author":"Guo","year":"2023"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.findings-emnlp.67"},{"key":"ref34","article-title":"Shikra: Unleashing multimodal LLM\u2019s referential dialogue magic","author":"Chen","year":"2023","journal-title":"arXiv:2306.15195"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.488"},{"key":"ref36","first-page":"1","article-title":"Ferret: Refer and ground anything anywhere at any granularity","volume-title":"Proc. 12th Int. Conf. Learn. Represent. (ICLR)","author":"You"},{"key":"ref37","first-page":"23716","article-title":"Flamingo: A visual language model for few-shot learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Alayrac"},{"key":"ref38","first-page":"1","article-title":"MiniGPT-4: Enhancing vision-language understanding with advanced large language models","volume-title":"Proc. 12th Int. Conf. Learn. Represent. (ICLR)","author":"Zhu"},{"key":"ref39","article-title":"MiniGPT-5: Interleaved vision-and-language generation via generative vokens","author":"Zheng","year":"2023","journal-title":"arXiv:2310.02239"},{"key":"ref40","first-page":"1","article-title":"InstructBLIP: Towards general-purpose vision-language models with instruction tuning","volume-title":"Proc. 27th Conf. Neural Inf. Process. Syst.","author":"Dai"},{"key":"ref41","volume-title":"Internlm: A Multilingual Language Model With Progressively Enhanced Capabilities","year":"2023"},{"key":"ref42","first-page":"1","article-title":"ChatGPT asks, BLIP-2 answers: Automatic questioning towards enriched visual descriptions","volume-title":"Proc. Trans. Mach. Learn. Res.","author":"Zhu"},{"key":"ref43","first-page":"57","article-title":"Bootstrapping vision-language learning with decoupled language pre-training","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Jian"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3421273"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3427432"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3436508"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3422923"},{"key":"ref48","article-title":"MultiTrust: A comprehensive benchmark towards trustworthy multimodal large language models","author":"Zhang","year":"2024","journal-title":"arXiv:2406.07057"},{"key":"ref49","article-title":"Towards trustworthy AI: A review of ethical and robust large language models","author":"Meftahul Ferdaus","year":"2024","journal-title":"arXiv:2407.13934"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.338"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3386058"},{"key":"ref52","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023","journal-title":"arXiv:2307.15043"},{"key":"ref53","article-title":"On the multi-modal vulnerability of diffusion models","author":"Yang","year":"2024","journal-title":"arXiv:2402.01369"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02288"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30150"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.00739"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3681092"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3547801"},{"key":"ref59","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"139","author":"Radford"},{"key":"ref60","first-page":"9694","article-title":"Align before fuse: Vision and language representation learning with momentum distillation","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Li"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02325"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref63","first-page":"12888","article-title":"BLIP: Bootstrapping language-image pre-training for unified vision-language understanding and generation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref64","volume-title":"Bard","year":"2023"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_32"},{"key":"ref66","article-title":"Rethinking model ensemble in transfer-based adversarial attacks","author":"Chen","year":"2023","journal-title":"arXiv:2303.09105"},{"key":"ref67","article-title":"Safety fine-tuning at (Almost) no cost: A baseline for vision large language models","author":"Zong","year":"2024","journal-title":"arXiv:2402.02207"},{"key":"ref68","first-page":"1","article-title":"Understanding zero-shot adversarial robustness for large-scale models","volume-title":"Proc. 11th Int. Conf. Learn. Represent.","author":"Mao"},{"key":"ref69","article-title":"Defending against unforeseen failure modes with latent adversarial training","author":"Casper","year":"2024","journal-title":"arXiv:2403.05030"},{"key":"ref70","article-title":"Vaccine: Perturbation-aware alignment for large language models against harmful fine-tuning attack","author":"Huang","year":"2024","journal-title":"arXiv:2402.01109"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref72","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019","journal-title":"arXiv:1902.06705"},{"key":"ref73","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023","journal-title":"arXiv:2307.09288"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.670"},{"key":"ref75","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00426"},{"key":"ref78","article-title":"OPT: Open pre-trained transformer language models","author":"Zhang","year":"2022","journal-title":"arXiv:2205.01068"},{"key":"ref79","first-page":"1","article-title":"Judging LLM-as-a-judge with MT-bench and chatbot arena","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Zheng"},{"issue":"2","key":"ref80","first-page":"1","article-title":"LoRA: Low-rank adaptation of large language models","volume-title":"Proc. ICLR","volume":"1","author":"Hu"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.301"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1145\/3703155"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11072221.pdf?arnumber=11072221","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,15]],"date-time":"2025-07-15T17:41:55Z","timestamp":1752601315000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11072221\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":82,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3586430","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}