{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/an-image-is-worth-1000-lies-adversarial","title":"An Image Is Worth 1000 Lies: Adversarial Transferability across Prompts on Vision-Language Models","arxiv_id":"2403.09766","date":"2024-03-14","proceeding":null,"authors":["Haochen Luo","Jindong Gu","Fengyuan Liu","Philip Torr"],"abstract":"Different from traditional task-specific vision models, recent large VLMs can readily adapt to different vision tasks by simply using different textual instructions, i.e., prompts. However, a well-known concern about traditional task-specific vision models is that they can be misled by imperceptible adversarial perturbations. Furthermore, the concern is exacerbated by the phenomenon that the same adversarial perturbations can fool different task-specific models. Given that VLMs rely on prompts to adapt to different tasks, an intriguing question emerges: Can a single adversarial image mislead all predictions of VLMs when a thousand different prompts are given? This question essentially introduces a novel perspective on adversarial transferability: cross-prompt adversarial transferability. In this work, we propose the Cross-Prompt Attack (CroPA). This proposed method updates the visual adversarial perturbation with learnable prompts, which are designed to counteract the misleading effects of the adversarial image. By doing this, CroPA significantly improves the transferability of adversarial examples across prompts. Extensive experiments are conducted to verify the strong cross-prompt adversarial transferability of CroPA with prevalent VLMs including Flamingo, BLIP-2, and InstructBLIP in various different tasks. Our source code is available at \\url{https://github.com/Haochen-Luo/CroPA}.","url_abs":"https://arxiv.org/abs/2403.09766v1","url_pdf":"https://arxiv.org/pdf/2403.09766v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"an-image-is-worth-1000-lies-adversarial","repo_url":"https://github.com/haochen-luo/cropa","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2403.09766","atlas_url":"https://app.syntology.ai/?focus=2403.09766","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2403.09766"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/Haochen-Luo/CroPA","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/haochen-luo/cropa","reach":{"status":"ok"}}],"summary":{"ran":7,"unverified":3},"by_repo_kind":{"official":{"samples":10,"ran":7,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":10,"samples":[{"code_sha256_prefix":"1adcf2d05b2faed1","entry":"get_imports","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/dynamic_module_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/dynamic_module_utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"1adcf2d05b2faed1"}},{"code_sha256_prefix":"518f6a89865f25d2","entry":"get_relative_import_files","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/dynamic_module_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/dynamic_module_utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"518f6a89865f25d2"}},{"code_sha256_prefix":"4af5faa701d0f2c9","entry":"get_relative_imports","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/dynamic_module_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/dynamic_module_utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"4af5faa701d0f2c9"}},{"code_sha256_prefix":"dd8f7751ef859581","entry":"infer_metric_tags_from_eval_results","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modelcard.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modelcard.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"dd8f7751ef859581"}},{"code_sha256_prefix":"a4491b45d19b7a39","entry":"parse_keras_history","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modelcard.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modelcard.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"a4491b45d19b7a39"}},{"code_sha256_prefix":"a66d2b78670c85e1","entry":"quick_gelu","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modeling_flax_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modeling_flax_utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"a66d2b78670c85e1"}},{"code_sha256_prefix":"30d50ff2ced6b7a3","entry":"rename_key_and_reshape_tensor","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modeling_flax_pytorch_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modeling_flax_pytorch_utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"30d50ff2ced6b7a3"}},{"code_sha256_prefix":"9d98806acb3144b7","entry":"dtype_byte_size","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modeling_flax_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modeling_flax_utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"9d98806acb3144b7"}},{"code_sha256_prefix":"e3ce70ca9258800e","entry":"flax_shard_checkpoint","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modeling_flax_utils.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modeling_flax_utils.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e3ce70ca9258800e"}},{"code_sha256_prefix":"ec7b1528a936234d","entry":"is_hf_dataset","repo":"Haochen-Luo/CroPA","repo_kind":"official","path":"transformers/modelcard.py","file_url":"https://github.com/Haochen-Luo/CroPA/blob/HEAD/transformers/modelcard.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"ec7b1528a936234d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}