{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T06:19:49Z","timestamp":1778048389128,"version":"3.51.4"},"reference-count":76,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T00:00:00Z","timestamp":1772755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T00:00:00Z","timestamp":1772755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,3,6]]},"DOI":"10.1109\/wacv61042.2026.00455","type":"proceedings-article","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T19:59:32Z","timestamp":1778011172000},"page":"4682-4692","source":"Crossref","is-referenced-by-count":0,"title":["Safe Vision-Language Models via Unsafe Weights Manipulation"],"prefix":"10.1109","author":[{"given":"Moreno","family":"D\u2019Inc\u00e0","sequence":"first","affiliation":[{"name":"University of Trento"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elia","family":"Peruzzo","sequence":"additional","affiliation":[{"name":"University of Trento"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xingqian","family":"Xu","sequence":"additional","affiliation":[{"name":"NVIDIA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Humphrey","family":"Shi","sequence":"additional","affiliation":[{"name":"Georgia Tech"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicu","family":"Sebe","sequence":"additional","affiliation":[{"name":"University of Trento"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Massimiliano","family":"Mancini","sequence":"additional","affiliation":[{"name":"University of Trento"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Prospect pruning: Finding trainable weights at initialization using meta-gradients","author":"Alizadeh","year":"2022"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.140"},{"key":"ref3","article-title":"METEOR: An automatic metric for MT evaluation with improved correlation with human judgments","volume-title":"Proceedings of the ACL Workshop on Intrinsic and Extrinsic Evaluation Measures for Machine Translation and\/or Summarization","author":"Banerjee"},{"key":"ref4","article-title":"Multimodal datasets: misogyny, pornography, and malignant stereotypes","author":"Birhane","year":"2021"},{"key":"ref5","article-title":"On the opportunities and risks of foundation models","author":"Bommasani","year":"2021"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10599-4_29"},{"key":"ref7","article-title":"Language models are few-shot learners","author":"Brown","year":"2020"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-emnlp.574"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.461"},{"key":"ref10","article-title":"Beyond size: How gradients shape pruning decisions in large language models","author":"Das","year":"2023"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01162"},{"key":"ref13","article-title":"Learning to prune deep neural networks via layer-wise optimal brain surgeon","volume-title":"NeurIPS","author":"Dong"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01532"},{"key":"ref15","doi-asserted-by":"crossref","DOI":"10.1016\/j.cviu.2005.09.012","article-title":"Learning generative visual models from few training examples: An incremental bayesian approach tested on 101 object categories","volume-title":"CVPR-WS","author":"Fei-Fei"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1162\/coli_a_00524"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00230"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00503"},{"key":"ref19","article-title":"An empirical investigation of catastrophic forgetting in gradient-based neural networks","volume-title":"ICLR","author":"Goodfellow"},{"key":"ref20","article-title":"Deep compression: Compressing deep neural networks with pruning, trained quantization and huffman coding","author":"Han","year":"2015"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JSTARS.2019.2918242"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00823"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01501"},{"key":"ref24","article-title":"Safe loRA: The silver lining of reducing safety risks when finetuning large language models","volume-title":"NeurIPS","author":"Hsu"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2013.77"},{"key":"ref26","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref27","article-title":"Layer-adaptive sparsity for the magnitude-based pruning","author":"Lee","year":"2020"},{"key":"ref28","article-title":"Snip: Single-shot network pruning based on connection sensitivity","author":"Lee","year":"2018"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539147"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.198"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2773081"},{"key":"ref32","article-title":"ROUGE: A package for automatic evaluation of summaries","author":"Lin","year":"2004","journal-title":"Text Summarization Branches Out"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1516"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73347-5_6"},{"key":"ref35","article-title":"AutoDAN: Generating stealthy jailbreak prompts on aligned large language models","volume-title":"ICLR","author":"Liu"},{"key":"ref36","article-title":"Cones: Concept neurons in diffusion models for customized generation","volume-title":"ICML","author":"Liu"},{"key":"ref37","article-title":"Llm-pruner: On the structural pruning of large language models","volume-title":"NeurIPS","author":"Ma"},{"key":"ref38","article-title":"Fine-grained visual classification of aircraft","author":"Maji","year":"2013"},{"key":"ref39","article-title":"Tree of attacks: Jailbreaking black-box llms automatically","volume-title":"NeurIPS","author":"Mehrotra"},{"key":"ref40","article-title":"Locating and editing factual associations in gpt","volume-title":"NeurIPS","author":"Meng"},{"key":"ref41","article-title":"Mass-editing memory in a transformer","author":"Meng","year":"2022"},{"key":"ref42","article-title":"Fast model editing at scale","volume-title":"ICLR","author":"Mitchell"},{"key":"ref43","article-title":"Memory-based model editing at scale","volume-title":"ICML","author":"Mitchell"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00649"},{"key":"ref46","doi-asserted-by":"crossref","DOI":"10.3115\/1073083.1073135","article-title":"Bleu: a method for automatic evaluation of machine translation","volume-title":"Proceedings of the 40th Annual Meeting of the Association for Computational Linguistics","author":"Papineni"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248092"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.225"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73668-1_20"},{"key":"ref50","article-title":"Large datasets: A pyrrhic win for computer vision","volume-title":"Institute of Electrical and Electronics Engineers\/Computer Vision Foundation Conference on Applications of Computer Vision","author":"Prabhu"},{"key":"ref51","article-title":"Learning transferable visual models from natural language supervision","volume-title":"ICML","author":"Radford"},{"issue":"2","key":"ref52","first-page":"3","article-title":"Hierarchical text-conditional image generation with clip latents","volume":"1","author":"Ramesh","year":"2022"},{"key":"ref53","article-title":"Do imagenet classifiers generalize to imagenet?","volume-title":"International conference on machine learning","author":"Recht"},{"key":"ref54","article-title":"High-resolution image synthesis with latent diffusion models. 2022 ieee","volume-title":"CVPR","author":"Rombach"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533192"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02157"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670388"},{"key":"ref58","article-title":"Upop: Unified and progressive pruning for compressing vision-language transformers","volume-title":"ICML","author":"Shi"},{"key":"ref59","article-title":"Ucf101: A dataset of 101 human actions classes from videos in the wild","author":"Soomro","year":"2012"},{"key":"ref60","article-title":"A simple and effective pruning approach for large language models","author":"Sun","year":"2023"},{"key":"ref61","article-title":"The llama 3 herd of models","year":"2024"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00517"},{"key":"ref63","article-title":"Llama: Open and efficient foundation language models","author":"Touvron","year":"2023"},{"key":"ref64","article-title":"Ring-a-bell! how reliable are concept removal methods for diffusion models?","volume-title":"ICLR","author":"Tsai"},{"key":"ref65","article-title":"Picking winning tickets before training by preserving gradient flow","author":"Wang","year":"2020"},{"key":"ref66","article-title":"Learning robust global representations by penalizing local predictive power","author":"Wang","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3698590"},{"key":"ref68","article-title":"Jailbroken: How does llm safety training fail?","volume-title":"NeurIPS","author":"Wei"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2010.5539970"},{"key":"ref70","article-title":"BESA: Pruning large language models with blockwise parameter-efficient sparsity allocation","volume-title":"ICLR","author":"Xu"},{"key":"ref71","article-title":"Coca: Contrastive captioners are image-text foundation models","author":"Yu","year":"2022"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.acl-long.158"},{"key":"ref73","article-title":"GPT-4 is too smart to be safe: Stealthy chat with LLMs via cipher","volume-title":"ICLR","author":"Yuan"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01100"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72998-0_22"},{"key":"ref76","article-title":"Universal and transferable adversarial attacks on aligned language models","author":"Zou","year":"2023"}],"event":{"name":"2026 IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)","location":"Tucson, AZ, USA","start":{"date-parts":[[2026,3,6]]},"end":{"date-parts":[[2026,3,10]]}},"container-title":["2026 IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11491838\/11491925\/11492678.pdf?arnumber=11492678","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T06:00:01Z","timestamp":1778047201000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11492678\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,6]]},"references-count":76,"URL":"https:\/\/doi.org\/10.1109\/wacv61042.2026.00455","relation":{},"subject":[],"published":{"date-parts":[[2026,3,6]]}}}