{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T18:14:19Z","timestamp":1764785659738,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":33,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,7,13]]},"DOI":"10.1145\/3726302.3730056","type":"proceedings-article","created":{"date-parts":[[2025,7,14]],"date-time":"2025-07-14T01:21:38Z","timestamp":1752456098000},"page":"414-423","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Document Screenshot Retrievers are Vulnerable to Pixel Poisoning Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6711-0955","authenticated-orcid":false,"given":"Shengyao","family":"Zhuang","sequence":"first","affiliation":[{"name":"CSIRO, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7531-4491","authenticated-orcid":false,"given":"Ekaterina","family":"Khramtsova","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3430-4910","authenticated-orcid":false,"given":"Xueguang","family":"Ma","sequence":"additional","affiliation":[{"name":"University of Waterloo, Waterloo, ON, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5577-3391","authenticated-orcid":false,"given":"Bevan","family":"Koopman","sequence":"additional","affiliation":[{"name":"CSIRO, Brisbane, QLD, Australia and The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0661-7189","authenticated-orcid":false,"given":"Jimmy","family":"Lin","sequence":"additional","affiliation":[{"name":"University of Waterloo, Waterloo, ON, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0271-5563","authenticated-orcid":false,"given":"Guido","family":"Zuccon","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,7,13]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"377","volume-title":"Foundations and Trends\u00ae in Information Retrieval","volume":"4","author":"Castillo Carlos","year":"2011","unstructured":"Carlos Castillo, Brian D Davison, et al., 2011. Adversarial Web Search. Foundations and Trends\u00ae in Information Retrieval, Vol. 4, 5 (2011), 377-486."},{"key":"e_1_3_2_1_2_1","unstructured":"Jaemin Cho Debanjan Mahata Ozan Irsoy Yujie He and Mohit Bansal. 2024. M3DocRAG: Multi-modal Retrieval is What You Need for Multi-page Multi-document Understanding. arxiv:2411.04952 [cs.CV] https:\/\/arxiv.org\/abs\/2411.04952"},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the 36th International Conference on Neural Information Processing Systems (NIPS '22)","author":"Dao Tri","year":"2022","unstructured":"Tri Dao, Daniel Y. Fu, Stefano Ermon, Atri Rudra, and Christopher R\u00e9. 2022. FlashAttention: Fast and Memory-Efficient Exact Attention with IO-Awareness. In Proceedings of the 36th International Conference on Neural Information Processing Systems (NIPS '22). Curran Associates Inc., Article 1189, 16 pages."},{"key":"e_1_3_2_1_4_1","volume-title":"Security and Privacy Challenges of Large Language Models: A Survey. Comput. Surveys","author":"Das Badhan Chandra","year":"2024","unstructured":"Badhan Chandra Das, M Hadi Amini, and Yanzhao Wu. 2024. Security and Privacy Challenges of Large Language Models: A Survey. Comput. Surveys (2024)."},{"key":"e_1_3_2_1_5_1","first-page":"9185","volume-title":"Proceedings of the 31st IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2017","author":"Dong Yinpeng","year":"2017","unstructured":"Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li. 2017. Boosting Adversarial Attacks with Momentum. Proceedings of the 31st IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2017), 9185-9193. https:\/\/api.semanticscholar.org\/CorpusID:4119221"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_3_2_1_7_1","unstructured":"Manuel Faysse Hugues Sibille Tony Wu Bilel Omrani Gautier Viaud C\u00e9line Hudelot and Pierre Colombo. 2025. ColPali: Efficient Document Retrieval with Vision Language Models. arxiv:2407.01449 [cs.IR] https:\/\/arxiv.org\/abs\/2407.01449"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591805"},{"key":"e_1_3_2_1_9_1","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. arxiv:1412.6572 [stat.ML] https:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_1_10_1","unstructured":"Sanghyun Hong Varun Chandrasekaran Yigitcan Kaya Tudor Dumitra\u00fb and Nicolas Papernot. 2020. On the Effectiveness of Mitigating Data Poisoning Attacks with Gradient Shaping. arxiv:2002.11497 [cs.CR] https:\/\/arxiv.org\/abs\/2002.11497"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401075"},{"key":"e_1_3_2_1_12_1","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2017. Adversarial Examples in the Physical World. arxiv:1607.02533 [cs.CV] https:\/\/arxiv.org\/abs\/1607.02533"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00276"},{"key":"e_1_3_2_1_14_1","unstructured":"Yongkang Li Panagiotis Eustratiadis and Evangelos Kanoulas. 2025. Reproducing HotFlip for Corpus Poisoning Attacks in Dense Retrieval. arxiv:2501.04802 [cs.IR] https:\/\/arxiv.org\/abs\/2501.04802"},{"volume-title":"Proceedings of the International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=SJlHwkBYDH","author":"Lin Jiadong","key":"e_1_3_2_1_15_1","unstructured":"Jiadong Lin, Chuanbiao Song, Kun He, Liwei Wang, and John E. Hopcroft. 2020. Nesterov Accelerated Gradient and Scale Invariance for Adversarial Attacks. In Proceedings of the International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=SJlHwkBYDH"},{"key":"e_1_3_2_1_16_1","unstructured":"Yu-An Liu Ruqing Zhang Jiafeng Guo Maarten de Rijke Yixing Fan and Xueqi Cheng. 2024. Robust Neural Information Retrieval: An Adversarial and Out-of-distribution Perspective. arxiv:2407.06992 [cs.IR] https:\/\/arxiv.org\/abs\/2407.06992"},{"key":"e_1_3_2_1_17_1","unstructured":"Quanyu Long Yue Deng LeiLei Gan Wenya Wang and Sinno Jialin Pan. 2024. Whispers in Grammars: Injecting Covert Backdoors to Compromise Dense Retrieval Systems. arxiv:2402.13532 [cs.CL] https:\/\/arxiv.org\/abs\/2402.13532"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00369"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.emnlp-main.373"},{"key":"e_1_3_2_1_20_1","volume-title":"VISA: Retrieval Augmented Generation with Visual Source Attribution. arxiv:2412.14457 [cs.IR] https:\/\/arxiv.org\/abs\/2412.14457","author":"Ma Xueguang","year":"2024","unstructured":"Xueguang Ma, Shengyao Zhuang, Bevan Koopman, Guido Zuccon, Wenhu Chen, and Jimmy Lin. 2024b. VISA: Retrieval Augmented Generation with Visual Source Attribution. arxiv:2412.14457 [cs.IR] https:\/\/arxiv.org\/abs\/2412.14457"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.765"},{"key":"e_1_3_2_1_22_1","volume-title":"Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever.","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever. 2021. Learning Transferable Visual Models From Natural Language Supervision. arxiv:2103.00020 [cs.CV] https:\/\/arxiv.org\/abs\/2103.00020"},{"key":"e_1_3_2_1_23_1","volume-title":"Beyond Text: Optimizing RAG with Multimodal Inputs for Industrial Applications. arxiv:2410.21943 [cs.CL] https:\/\/arxiv.org\/abs\/2410.21943","author":"Riedler Monica","year":"2024","unstructured":"Monica Riedler and Stefan Langer. 2024. Beyond Text: Optimizing RAG with Multimodal Inputs for Industrial Applications. arxiv:2410.21943 [cs.CL] https:\/\/arxiv.org\/abs\/2410.21943"},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of the 31th International Conference on Neural Information Processing Systems (NIPS '17)","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang. 2017. Certified Defenses for Data Poisoning Attacks. In Proceedings of the 31th International Conference on Neural Information Processing Systems (NIPS '17). Curran Associates, Inc."},{"key":"e_1_3_2_1_25_1","first-page":"1","article-title":"A Comprehensive Survey on Poisoning Attacks and Countermeasures in Machine","volume":"55","author":"Tian Zhiyi","year":"2022","unstructured":"Zhiyi Tian, Lei Cui, Jie Liang, and Shui Yu. 2022. A Comprehensive Survey on Poisoning Attacks and Countermeasures in Machine Learning. Comput. Surveys, Vol. 55, 8 (2022), 1-35.","journal-title":"Learning. Comput. Surveys"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3538707","article-title":"Threats to Training","volume":"55","author":"Wang Zhibo","year":"2022","unstructured":"Zhibo Wang, Jingjing Ma, Xue Wang, Jiahui Hu, Zhan Qin, and Kui Ren. 2022. Threats to Training: A Survey of Poisoning Attacks and Defenses on Machine Learning Systems. Comput. Surveys, Vol. 55, 7 (2022), 1-36.","journal-title":"Comput. Surveys"},{"key":"e_1_3_2_1_28_1","volume-title":"MMed-RAG: Versatile Multimodal RAG System for Medical Vision Language Models. In NeurIPS Safe Generative AI Workshop.","author":"Xia Peng","year":"2024","unstructured":"Peng Xia, Kangyu Zhu, Haoran Li, Tianze Wang, Weijia Shi, Sheng Wang, Linjun Zhang, James Zou, and Huaxiu Yao. 2024. MMed-RAG: Versatile Multimodal RAG System for Medical Vision Language Models. In NeurIPS Safe Generative AI Workshop."},{"key":"e_1_3_2_1_29_1","unstructured":"Shi Yu Chaoyue Tang Bokai Xu Junbo Cui Junhao Ran Yukun Yan Zhenghao Liu Shuo Wang Xu Han Zhiyuan Liu and Maosong Sun. 2025. VisRAG: Vision-based Retrieval-augmented Generation on Multi-modality Documents. arxiv:2410.10594 [cs.IR] https:\/\/arxiv.org\/abs\/2410.10594"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637870"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.849"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3673791.3698414"},{"key":"e_1_3_2_1_33_1","unstructured":"Shengyao Zhuang Bevan Koopman and Guido Zuccon. 2024a. Does Vec2Text Pose a New Corpus Poisoning Threat? arxiv:2410.06628 [cs.IR] https:\/\/arxiv.org\/abs\/2410.06628"}],"event":{"name":"SIGIR '25: The 48th International ACM SIGIR Conference on Research and Development in Information Retrieval","sponsor":["SIGIR ACM Special Interest Group on Information Retrieval"],"location":"Padua Italy","acronym":"SIGIR '25"},"container-title":["Proceedings of the 48th International ACM SIGIR Conference on Research and Development in Information Retrieval"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3726302.3730056","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T10:01:43Z","timestamp":1755856903000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3726302.3730056"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,13]]},"references-count":33,"alternative-id":["10.1145\/3726302.3730056","10.1145\/3726302"],"URL":"https:\/\/doi.org\/10.1145\/3726302.3730056","relation":{},"subject":[],"published":{"date-parts":[[2025,7,13]]},"assertion":[{"value":"2025-07-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}