{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T10:44:14Z","timestamp":1764585854099,"version":"3.46.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,13]]},"DOI":"10.1145\/3733800.3763269","type":"proceedings-article","created":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T10:39:10Z","timestamp":1764585550000},"page":"19-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["When Vision Fails: Text Attacks Against ViT and OCR"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5674-3730","authenticated-orcid":false,"given":"Nicholas","family":"Boucher","sequence":"first","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7470-6435","authenticated-orcid":false,"given":"Jenny","family":"Blessing","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3100-0727","authenticated-orcid":false,"given":"Ilia","family":"Shumailov","sequence":"additional","affiliation":[{"name":"University of Oxford, Oxford, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8697-5682","authenticated-orcid":false,"given":"Ross","family":"Anderson","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, United Kingdom and University of Edinburgh, Edinburgh, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5078-7233","authenticated-orcid":false,"given":"Nicolas","family":"Papernot","sequence":"additional","affiliation":[{"name":"University of Toronto, Toronto, Canada and Vector Institute, Toronto, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,12]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"crossref","unstructured":"Moustafa Alzantot Yash Sharma Ahmed Elgohary Bo-Jhang Ho Mani Srivastava and Kai-Wei Chang. 2018. Generating natural language adversarial examples. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1804.07998 (2018).","DOI":"10.18653\/v1\/D18-1316"},{"key":"e_1_3_3_1_3_2","first-page":"284","volume-title":"International conference on machine learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesizing robust adversarial examples. In International conference on machine learning. PMLR, 284\u2013293."},{"key":"e_1_3_3_1_4_2","unstructured":"Silky Azad and Kiran Jain. 2013. Captcha: Attacks and weaknesses against OCR technology. Global Journal of Computer Science and Technology (2013)."},{"key":"e_1_3_3_1_5_2","unstructured":"Yonatan Belinkov and Yonatan Bisk. 2017. Synthetic and natural noise both break neural machine translation. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1711.02173 (2017)."},{"key":"e_1_3_3_1_6_2","volume-title":"International Conference on Learning Representations","author":"Belinkov Yonatan","year":"2018","unstructured":"Yonatan Belinkov and Yonatan Bisk. 2018. Synthetic and Natural Noise Both Break Neural Machine Translation. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BJ8vJebC-"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833641"},{"key":"e_1_3_3_1_9_2","unstructured":"Lu Chen Jiao Sun and Wei Xu. 2020. FAWA: Fast Adversarial Watermark Attack on Optical Character Recognition (OCR) Systems. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2012.08096 (2020)."},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"publisher","unstructured":"Jonathan\u00a0H. Clark Dan Garrette Iulia Turc and John Wieting. 2022. Canine: Pre-training an Efficient Tokenization-Free Encoder for Language Representation. Transactions of the Association for Computational Linguistics 10 (2022) 73\u201391. 10.1162\/tacla00448","DOI":"10.1162\/tacla00448"},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_3_3_1_12_2","unstructured":"Ian\u00a0J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1412.6572 (2014)."},{"key":"e_1_3_3_1_13_2","unstructured":"Google. 2021. Perspective API. https:\/\/www.perspectiveapi.com\/"},{"key":"e_1_3_3_1_14_2","unstructured":"Hossein Hosseini Sreeram Kannan Baosen Zhang and Radha Poovendran. 2017. Deceiving Google\u2019s Perspective API Built for Detecting Toxic Comments. arxiv:https:\/\/arXiv.org\/abs\/1702.08138\u00a0[cs.LG]"},{"key":"e_1_3_3_1_15_2","unstructured":"Jeff Hsu. 2022. Splend1dchan\/canine-s-squad. https:\/\/huggingface.co\/Splend1dchan\/canine-s-squad"},{"key":"e_1_3_3_1_16_2","unstructured":"IBM. 2020. Toxic Comment Classifier. https:\/\/github.com\/IBM\/MAX-Toxic-Comment-Classifier"},{"key":"e_1_3_3_1_17_2","unstructured":"Huda Khayrallah and Philipp Koehn. 2018. On the impact of various types of noise on neural machine translation. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1805.12282 (2018)."},{"key":"e_1_3_3_1_18_2","unstructured":"Keita Kurita Anna Belova and Antonios Anastasopoulos. 2019. Towards robust toxic content classification. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1912.06872 (2019)."},{"key":"e_1_3_3_1_19_2","unstructured":"Jinfeng Li Shouling Ji Tianyu Du Bo Li and Ting Wang. 2018. Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1812.05271 (2018)."},{"key":"e_1_3_3_1_20_2","unstructured":"Minghao Li Tengchao Lv Lei Cui Yijuan Lu Dinei Florencio Cha Zhang Zhoujun Li and Furu Wei. 2021. TrOCR: Transformer-based Optical Character Recognition with Pre-trained Models. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2109.10282 (2021)."},{"key":"e_1_3_3_1_21_2","first-page":"688","volume-title":"Proceedings of the Fifth Conference on Machine Translation","author":"Mathur Nitika","year":"2020","unstructured":"Nitika Mathur, Johnny Wei, Markus Freitag, Qingsong Ma, and Ond\u0159ej Bojar. 2020. Results of the WMT20 Metrics Shared Task. In Proceedings of the Fifth Conference on Machine Translation. Association for Computational Linguistics, Online, 688\u2013725. https:\/\/aclanthology.org\/2020.wmt-1.77"},{"key":"e_1_3_3_1_22_2","unstructured":"Microsoft. 2021. Arial Unicode MS font family. https:\/\/www.unicode.org\/charts\/PDF\/UFE20.pdf"},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-4009"},{"key":"e_1_3_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-6301"},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00023"},{"key":"e_1_3_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W15-3049"},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-6319"},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D16-1264"},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-1216-2_4"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.576"},{"key":"e_1_3_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00024"},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"publisher","unstructured":"Rainer Storn and Kenneth Price. 1997. Differential Evolution \u2013 A Simple and Efficient Heuristic for global Optimization over Continuous Spaces. Journal of Global Optimization 11 4 (Dec. 1997) 341\u2013359. 10.1023\/A:1008202821328","DOI":"10.1023\/A:1008202821328"},{"key":"e_1_3_3_1_33_2","volume-title":"The Second International Conference on Learning Representations","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In The Second International Conference on Learning Representations. ICLR."},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"publisher","unstructured":"Nithum Thain Lucas Dixon and Ellery Wulczyn. 2017. Wikipedia Talk Labels: Toxicity. 10.6084\/m9.figshare.4563973.v2","DOI":"10.6084\/m9.figshare.4563973.v2"},{"key":"e_1_3_3_1_35_2","unstructured":"The Unicode Consortium. 2021. Combining Diacritical Marks. https:\/\/www.unicode.org\/charts\/PDF\/U0300.pdf"},{"key":"e_1_3_3_1_36_2","unstructured":"The Unicode Consortium. 2021. Combining Diacritical Marks Extended. https:\/\/www.unicode.org\/charts\/PDF\/U1AB0.pdf"},{"key":"e_1_3_3_1_37_2","unstructured":"The Unicode Consortium. 2021. Combining Diacritical Marks for Symbols. https:\/\/www.unicode.org\/charts\/PDF\/U20D0.pdf"},{"key":"e_1_3_3_1_38_2","unstructured":"The Unicode Consortium. 2021. Combining Diacritical Marks Supplement. https:\/\/www.unicode.org\/charts\/PDF\/U1DC0.pdf"},{"key":"e_1_3_3_1_39_2","unstructured":"The Unicode Consortium. 2021. Combining Half Marks. https:\/\/www.unicode.org\/charts\/PDF\/UFE20.pdf"},{"key":"e_1_3_3_1_40_2","unstructured":"The Unicode Consortium. 2021. The Unicode Standard Version 14.0. https:\/\/www.unicode.org\/versions\/Unicode14.0.0"},{"key":"e_1_3_3_1_41_2","unstructured":"Florian Tram\u00e8r Jens Behrmann Nicholas Carlini Nicolas Papernot and J\u00f6rn-Henrik Jacobsen. 2020. Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations. arxiv:https:\/\/arXiv.org\/abs\/2002.04599\u00a0[cs.LG]"},{"key":"e_1_3_3_1_42_2","unstructured":"United States Postal Service. 2023. Proper Delivery Address Placement. https:\/\/about.usps.com\/publications\/pub25\/pub25_ch1_006.htm"},{"key":"e_1_3_3_1_43_2","first-page":"5998","volume-title":"Advances in neural information processing systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan\u00a0N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. In Advances in neural information processing systems. 5998\u20136008."},{"key":"e_1_3_3_1_44_2","unstructured":"Alex Warstadt Amanpreet Singh and Samuel\u00a0R Bowman. 2018. Neural Network Acceptability Judgments. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1805.12471 (2018)."},{"key":"e_1_3_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.47"},{"key":"e_1_3_3_1_46_2","unstructured":"Wei Zou Shujian Huang Jun Xie Xinyu Dai and Jiajun Chen. 2019. A reinforced generation of adversarial examples for neural machine translation. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1911.03677 (2019)."}],"event":{"name":"LAMPS '25: Proceedings of the 2025 Workshop on Large AI Systems and Models with Privacy and Security Analysis","location":"Taipei Taiwan","acronym":"LAMPS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 Workshop on Large AI Systems and Models with Privacy and Security Analysis"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3733800.3763269","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T10:39:39Z","timestamp":1764585579000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3733800.3763269"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":45,"alternative-id":["10.1145\/3733800.3763269","10.1145\/3733800"],"URL":"https:\/\/doi.org\/10.1145\/3733800.3763269","relation":{},"subject":[],"published":{"date-parts":[[2025,10,13]]},"assertion":[{"value":"2025-12-01","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}