Spa-VLM: Stealthy Poisoning Attacks on RAG-based VLM
Lei Yu, Yechao Zhang, Ziqi Zhou, Yang Wu, Wei Wan, Minghui Li, Shengshan Hu, Pei Xiaobing, Jing Wang

TL;DR
This paper introduces Spa-VLM, a stealthy poisoning attack on RAG-based Vision-Language Models, demonstrating high success rates with minimal malicious data injection and exposing vulnerabilities in existing defenses.
Contribution
We propose Spa-VLM, a novel poisoning attack method that effectively injects malicious knowledge into RAG-based VLMs, revealing significant security vulnerabilities.
Findings
High attack success rate (>0.8) with only 5 malicious entries
Outperforms existing poisoning attacks in stealthiness and effectiveness
Existing defenses are ineffective against Spa-VLM
Abstract
With the rapid development of the Vision-Language Model (VLM), significant progress has been made in Visual Question Answering (VQA) tasks. However, existing VLM often generate inaccurate answers due to a lack of up-to-date knowledge. To address this issue, recent research has introduced Retrieval-Augmented Generation (RAG) techniques, commonly used in Large Language Models (LLM), into VLM, incorporating external multi-modal knowledge to enhance the accuracy and practicality of VLM systems. Nevertheless, the RAG in LLM may be susceptible to data poisoning attacks. RAG-based VLM may also face the threat of this attack. This paper first reveals the vulnerabilities of the RAG-based large model under poisoning attack, showing that existing single-modal RAG poisoning attacks have a 100\% failure rate in multi-modal RAG scenarios. To address this gap, we propose Spa-VLM (Stealthy Poisoning…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsOptical Network Technologies · Advanced Fiber Optic Sensors · Advanced Fiber Laser Technologies
