Pith. sign in

Paper Citation Record · LEDGER

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks

As of 22 August 2026, this Paper Citation Record lists 57 of 57 outbound references and 1 inbound Pith citation observation for arXiv:2411.15720.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2411.15720 v1

Coverage vector

measured 57 of 57 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-12T14:04:45.533578Z

measured 58 of 58 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-22T06:32:14.747728+00:00

measured 1 of 1 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-16T04:34:34.429357Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: pith, observed 2026-08-16T04:34:34.547389Z

Reference resolution

57 of 57 outbound references displayed

  • verified exact2
  • verified fuzzy25
  • unresolved30
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 9465c12d-16e0-42fd-9df6-635c937d8f8d · outbound

This paper cites GPT-4 Technical Report.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks GPT-4 Technical Report

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.265930Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.265930Z digest=sha256:cc111159006a42d534cca79649c9ff8cbb98ee41fb4d4e547b9bd902b7c8a0b8

Observation 278eacc9-6bb0-4c15-91c4-0d24191c39dc · outbound

This paper cites Flamingo: a visual language model for few-shot learning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Flamingo: a visual language model for few-shot learning

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.271659Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.271659Z digest=sha256:e6084cdb65a3cd44c2b4f95617e06d8c1ddd0c81d77fb214010cad81197b0988

Observation 724168eb-2f27-4764-901e-b5c6e2853967 · outbound

This paper cites Image Hijacks: Adversarial Images can Control Generative Models at Runtime.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.276730Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.276730Z digest=sha256:e463f14a707948474d383e784d6ad403d51988dc6c7349621f2a9e3eedd1e0b7

Observation 0f3c50c8-331c-400d-bcb1-1a28d6f2a09e · outbound

This paper cites One transformer fits all distributions in multi-modal diffu- sion at scale.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks One transformer fits all distributions in multi-modal diffu- sion at scale

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.510234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.281986Z digest=sha256:0d838aae3fdf45f73312d6baa38703c85dfb62046061bc6d5e4ba89e54076fa9

Observation dca4f61e-f790-474d-bd4b-140f50cfccbc · outbound

This paper cites On the Opportunities and Risks of Foundation Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On the Opportunities and Risks of Foundation Models

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.286960Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.286960Z digest=sha256:3713e802dba0b84453889bc9ac25824364434cb57fc7aabaced004b10b17bb96

Observation 2a3d54cd-5d13-4f8c-9179-1262e0056135 · outbound

This paper cites On Evaluating Adversarial Robustness.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On Evaluating Adversarial Robustness

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.291956Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.291956Z digest=sha256:fa2739ae143593431c09a9378c589ea905b11140b6408e4e55fc965a5f2f279e

Observation ac2367b1-b2ed-4d99-a166-27d6df747aaf · outbound

This paper cites Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2024.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2024

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.494925Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.297408Z digest=sha256:03bb6c99e3d8b8dd0fe462016981c62b0de7e66682ef2c2a38399b4ff3de9bcc

Observation def00373-d365-4270-8781-2a5121f04642 · outbound

This paper cites Attacking Visual Language Grounding with Adversarial Examples: A Case Study on Neural Image Captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Attacking Visual Language Grounding with Adversarial Examples: A Case Study on Neural Image Captioning

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.302110Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.302110Z digest=sha256:ea6b72eedb3c66a1f060a2d14327c275322f0dca9c9f8de0ed053f53bb5875a3

Observation ef3077b2-2aa8-405b-a459-109a278f3a35 · outbound

This paper cites Rethinking Model Ensemble in Transfer-based Adversarial Attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Rethinking Model Ensemble in Transfer-based Adversarial Attacks

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.307991Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.307991Z digest=sha256:0b245867bb435e3e0465e9d9ad60c998fe9972d9725eda252caaaed0e3227c8a

Observation d5b04198-9e4d-49f2-a807-185ac811989b · outbound

This paper cites Visualgpt: Data-efficient adaptation of pretrained language models for image captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Visualgpt: Data-efficient adaptation of pretrained language models for image captioning

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.479746Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.313248Z digest=sha256:de6950ec88d005fc7e35fd2d4180bec97497ca6b53092133330c5f4a8a859a23

Observation 1a00a7c4-09f5-4230-afbd-962ed25caae8 · outbound

This paper cites Microsoft COCO Captions: Data Collection and Evaluation Server.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Microsoft COCO Captions: Data Collection and Evaluation Server

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.317956Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.317956Z digest=sha256:d697860b00050abbf25ed58de1a60e25375b2f525fba90384c414bc6215911e3

Observation 2c4dbad5-255b-498f-b98e-6f7ea2be4121 · outbound

This paper cites Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Vicuna: An open-source chatbot impressing gpt-4 with 90%* chatgpt quality

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.322630Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.322630Z digest=sha256:a9580b9fb565257063d6243bf8c9685e0354fcd887d8b7d2279d45c5cd7ea901

Observation cb4aeab9-d8a7-4d16-8e41-98e7d221a17e · outbound

This paper cites On the robustness of large multimodal mod- els against image adversarial attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On the robustness of large multimodal mod- els against image adversarial attacks

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.453752Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.327198Z digest=sha256:23619a9c17704bd43f04d18ebd023ee09c7554325c9aea15309ad054385e1048

Observation b4684860-9ea8-47c9-85af-bd2b360debb7 · outbound

This paper cites Imagenet: A large-scale hierarchical image database.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Imagenet: A large-scale hierarchical image database

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.437420Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.331657Z digest=sha256:da751154f351c48e6ee898b204512f62218b51f65eda3a5e57f4b6404dd66f76

Observation 5722d0ba-873b-4a86-9fed-4a897f2f0db7 · outbound

This paper cites Boosting adversarial at- tacks with momentum.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Boosting adversarial at- tacks with momentum

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.421440Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.336219Z digest=sha256:6ef0bf6598f4374c09229005043b57581592b8120eeeca89fd342259fc96fd02

Observation eff8c265-d324-4f9f-888e-83c2eb789aab · outbound

This paper cites Query-efficient black-box adversarial attacks guided by a transfer-based prior.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Query-efficient black-box adversarial attacks guided by a transfer-based prior

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.406233Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.340730Z digest=sha256:edc6c96162312436a468ad7ad518a4690dddf8daba438a888e461a8f0dff065d

Observation b305d782-bd03-4cc6-9574-69ebd0f8cdd0 · outbound

This paper cites How Robust is Google's Bard to Adversarial Image Attacks?.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks How Robust is Google's Bard to Adversarial Image Attacks?

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.345445Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.345445Z digest=sha256:9eac5c6734f5a367ace201dbe841f15d716fc0fd8e6ad5bef2de8e8812156716

Observation 2527124c-5dab-42b9-ba28-354b1739f51a · outbound

This paper cites An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.350159Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.350159Z digest=sha256:19179dc1e1f919a4fcd4f97d07148691f5d10ebe53870159a10e982d9748a50b

Observation 0dc6c3e0-3019-4a23-9054-092bfa50da79 · outbound

This paper cites Transferable decoding with visual entities for zero-shot image captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Transferable decoding with visual entities for zero-shot image captioning

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.389920Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.354889Z digest=sha256:a719a5b2a0be0e4735df24eb7d13e76f13af6c5da50bbce81674aefc7231e3ab

Observation d99fc87f-5a8e-416b-bb9a-3951d919900d · outbound

This paper cites Misusing Tools in Large Language Models With Visual Adversarial Examples.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Misusing Tools in Large Language Models With Visual Adversarial Examples

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.359652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.359652Z digest=sha256:320713cc4f2d71045c355e87b1edc7071050509c37f92a7409093190590a70fd

Observation 455e54ab-a27b-4814-8c6b-0ccdb3868698 · outbound

This paper cites FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks FigStep: Jailbreaking Large Vision-Language Models via Typographic Visual Prompts

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.364618Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.364618Z digest=sha256:7b6d8b052e5646f149659c450e0de67b371e2a6894334e4748db22494be5ff5e

Observation eb0c1066-5b28-4eb1-98e9-a7599193977c · outbound

This paper cites Explaining and Harnessing Adversarial Examples.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Explaining and Harnessing Adversarial Examples

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.369843Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.369843Z digest=sha256:549669d42c282db2dc1d20ca8a138057d70a054481acd27c0b86336273954471

Observation 23b15a9f-03a8-420a-9193-10ce65785e56 · outbound

This paper cites Simple black-box adversar- ial attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Simple black-box adversar- ial attacks

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.373846Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.374370Z digest=sha256:638e8d3a082bcdee293c3cd578a5d715116b14fa03b0410ae98e16fb9b058f9c

Observation d9f44e4a-fcfb-46a5-837f-3629ed15c53c · outbound

This paper cites Deep residual learning for image recognition.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Deep residual learning for image recognition

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.378882Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.378882Z digest=sha256:b6c289c339711b993a8618d0b11de452b18d81cdf83c68d549046a4180155439

Observation 260eec44-4f03-47d9-829d-eff3209d306b · outbound

This paper cites Enhancing adversarial example transferability with an intermediate level attack.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Enhancing adversarial example transferability with an intermediate level attack

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.347680Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.383684Z digest=sha256:1c6f5662fa234c70fd706d2465697bebf5a9721939f0c86ab73c856d1b2733ee

Observation 0e744330-1374-4afe-b196-5bcdd9791f62 · outbound

This paper cites Black-box adversarial attacks with limited queries and information.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Black-box adversarial attacks with limited queries and information

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.331922Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.388510Z digest=sha256:9971fe470ebe435a3772bb2a76f5f2a35cb72af5e92f1a39750a16ddf47c7f6f

Observation 57ac0a62-e22f-4c7b-ae8f-71f2b98b55be · outbound

This paper cites Jailbreakzoo: Survey, landscapes, and horizons in jailbreaking large language and vision-language models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Jailbreakzoo: Survey, landscapes, and horizons in jailbreaking large language and vision-language models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.394023Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.394023Z digest=sha256:8666c9c5e2e2ed0db94c0122e76e756c31b9924596be0dd64d29e5ebcd08c73f

Observation 6eb0efc9-d3b0-458d-b9e8-be1d4452e1ff · outbound

This paper cites Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.399083Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.399083Z digest=sha256:6c32f14e0e69d2015f81d99941d4a079cf8dd7eed62f62a46fd320fd8036fe1e

Observation 8809e5a4-2b83-48e4-81de-90f8229468ee · outbound

This paper cites Improved baselines with visual instruction tuning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Improved baselines with visual instruction tuning

Reference 29

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.306412Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.403338Z digest=sha256:4407772ce67873fb2873b182acea98d4239d7a565a2c620bdd6afcb3dbb70e89

Observation ae9cf933-1803-4760-a0d3-924c70bc902d · outbound

This paper cites Visual instruction tuning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Visual instruction tuning

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.291322Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.407508Z digest=sha256:171f9e1d9dce2ed5467327d9698490512aa29f72841a1ecf010337b975d559fd

Observation f529ce5c-d849-4d9c-8f6b-8ede1a60fba4 · outbound

This paper cites Delving into Transferable Adversarial Examples and Black-box Attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Delving into Transferable Adversarial Examples and Black-box Attacks

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.412014Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.412014Z digest=sha256:8dc9a7db08e55c967a044cd23d7153700725419811e9d793e0ff21cd2f384143

Observation 11626c42-057c-481f-8623-7e7c4cb46010 · outbound

This paper cites Delving into transferable adversarial examples and black- box attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Delving into transferable adversarial examples and black- box attacks

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.275318Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.416609Z digest=sha256:227989cdb683358b55647c736944907a9ab739352583f8af80222214f3469418

Observation c9a7b32e-17ad-4556-a584-f33a14cf35f0 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.421221Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.421221Z digest=sha256:72e9c2d6eb73bf2f88ae9ab5ef87732335521c05d21102581f66eedff8f14735

Observation db831ca2-61dd-425b-977f-52846b6be8fe · outbound

This paper cites ClipCap: CLIP Prefix for Image Captioning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks ClipCap: CLIP Prefix for Image Captioning

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.425894Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.425894Z digest=sha256:a65972dc19282ea1ee50f527829ea21bf7448dc5c0be7df54fb865b9beb2c2a1

Observation 3a583908-46da-47a4-8df0-be3535eab082 · outbound

This paper cites Deep neural networks are easily fooled: High confidence predictions for unrecognizable images.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Deep neural networks are easily fooled: High confidence predictions for unrecognizable images

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.430441Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.430441Z digest=sha256:b1f3257122f2b6bd3a485503842a478a9456efaf23528c70d5ff04dd42c1d157

Observation aabf837b-6f64-4191-ae19-f3ce9c8c758c · outbound

This paper cites Practi- cal black-box attacks against machine learning.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Practi- cal black-box attacks against machine learning

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.249927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.434999Z digest=sha256:c48d83bae5731dd395de6cc6ad1be6c5d66ce67aeab95c5fe2148fce03aa077e

Observation 68c7a997-5a37-4ed7-a343-df167c9bab1b · outbound

This paper cites Red Teaming Language Models with Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Red Teaming Language Models with Language Models

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.439661Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.439661Z digest=sha256:90f868c7fb8a2e5ac8c3c68aa728a975fcfdd4565b45747a73a754694b82ac27

Observation 131bc890-ff1a-4462-9df5-d54cb3533721 · outbound

This paper cites Visual Adversarial Examples Jailbreak Aligned Large Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Visual Adversarial Examples Jailbreak Aligned Large Language Models

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.445238Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.445238Z digest=sha256:0ac103fc70e3fba6bad3788e6579a0a3dc25d170209fcac2dca2b41065b20c93

Observation 0dffcf7f-c20d-452f-b7cc-3a0407f56fdb · outbound

This paper cites Boosting the transferability of ad- versarial attacks with reverse adversarial perturbation.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Boosting the transferability of ad- versarial attacks with reverse adversarial perturbation

Reference 39

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.234182Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.450171Z digest=sha256:ed5a599ac1f58fd4c33c292e44113fac6c91f5739f76ab45926e5f8fd6549d5a

Observation ee143442-8368-488e-ab7b-81699295b20b · outbound

This paper cites Language models are unsu- pervised multitask learners.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Language models are unsu- pervised multitask learners

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.454674Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.454674Z digest=sha256:c182442fa75ff2544018784d2ee4101a10f4d4d57387f88c4743d76f22b7929a

Observation f4571ce6-ad84-41da-8b59-415926b0dbf1 · outbound

This paper cites Learning transferable visual models from natural language supervi- sion.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Learning transferable visual models from natural language supervi- sion

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.208805Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.459263Z digest=sha256:fbc1fffcdec4963f360f15b45a709bee346548307f6de59f64463fd8e879db59

Observation 32d7222d-9524-403b-897f-02f3b6ae6d1e · outbound

This paper cites Smallcap: lightweight image captioning prompted with retrieval augmentation.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Smallcap: lightweight image captioning prompted with retrieval augmentation

Reference 42

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.191362Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.463657Z digest=sha256:acd9afaed9f682c87424c5c2a85ba84b46ea15642b3839b86cd49277fcb3f027

Observation e6be4645-f99b-4a08-a473-f920a359b44b · outbound

This paper cites Red-Teaming the Stable Diffusion Safety Filter.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Red-Teaming the Stable Diffusion Safety Filter

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.468299Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.468299Z digest=sha256:1555e24e81af3acfb422e858999ed8bc9b7c61c5ed87123e099cc61e796393ac

Observation 04091d0e-6ac4-47c8-a029-93a8bad3915a · outbound

This paper cites High-resolution image synthesis with latent diffusion models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks High-resolution image synthesis with latent diffusion models

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.175234Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.472955Z digest=sha256:1a39cba0c412a64113418e3f18b6bf5332add56124de726b7ec4318ec973abe5

Observation e7ef2b3d-079c-4fc7-afe2-6f4c17489b54 · outbound

This paper cites LLaMA: Open and Efficient Foundation Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks LLaMA: Open and Efficient Foundation Language Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.477320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.477320Z digest=sha256:3e77ee676622a52026f4ef3f819463e6d52b4bc36c4a3527583040918a265b2d

Observation 819d6954-93ba-49d1-a469-f2e347f8677b · outbound

This paper cites Llama 2: Open Foundation and Fine-Tuned Chat Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Llama 2: Open Foundation and Fine-Tuned Chat Models

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.482107Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.482107Z digest=sha256:850f58fcb486b7da134cfe5554ead8808c1d9d190c1704689421af304638c28c

Observation fac32d46-9ac9-47b8-86bf-1126fdaf3be9 · outbound

This paper cites How many unicorns are in this image a safety evaluation benchmark for vision llms.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks How many unicorns are in this image a safety evaluation benchmark for vision llms

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.159394Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.486582Z digest=sha256:0074ee049bae3b7a73bd74ad741090b029e150e9b922b8b30f8d3615707a0496

Observation 87f9dc7d-f8f0-4b69-aecc-f2dd709e3b53 · outbound

This paper cites Decodingtrust: A com- prehensive assessment of trustworthiness in gpt models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Decodingtrust: A com- prehensive assessment of trustworthiness in gpt models

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.143484Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.490762Z digest=sha256:7bfa02779001832cdaff92ceb2f4ac002880ac13d343083d82bb3879cd37191e

Observation 73c3d2fd-7404-4b75-aaf8-ce54a53d3172 · outbound

This paper cites Exact adversarial attack to image captioning via structured output learning with la- tent variables.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Exact adversarial attack to image captioning via structured output learning with la- tent variables

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.127179Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.495218Z digest=sha256:cef3de95f60403c8ce8bbbf3c2813d7b9b27b9a53e933166f413813c6bbc694a

Observation 9fc0d42a-727c-4fea-b7c7-6fcd83068a03 · outbound

This paper cites Adversarial Attacks of Vision Tasks in the Past 10 Years: A Survey.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Adversarial Attacks of Vision Tasks in the Past 10 Years: A Survey

Reference 50

Resolution
verified exact
local_arxiv, observed 2026-08-12T14:04:45.637508Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.499682Z digest=sha256:601c523e1a2d46cf86142d87b8dc7e925a3c694851d8bf62c559c09284361c02

Observation e242e9b5-987b-4cbf-9a31-9a194fc82351 · outbound

This paper cites The unreasonable effectiveness of deep features as a perceptual metric.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks The unreasonable effectiveness of deep features as a perceptual metric

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.504498Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.504498Z digest=sha256:7d50a20335039658103ec6a9c5069d6cb913bcf79e5142911b6c8ec4af3fa1ae

Observation 5bd67aec-a927-4b0a-b458-4f204a7d0253 · outbound

This paper cites A Review of Adversarial Attacks in Computer Vision.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks A Review of Adversarial Attacks in Computer Vision

Reference 52

Resolution
verified exact
local_arxiv, observed 2026-08-12T14:04:45.614774Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.509333Z digest=sha256:0047c69bddc8bee5ce39ce3e5eb6d9f9202487342161d6aa7d43ab0a5f9c4724

Observation f62fb484-f36f-4296-a72d-05ee7d4f33ed · outbound

This paper cites A Recipe for Watermarking Diffusion Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks A Recipe for Watermarking Diffusion Models

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.513954Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.513954Z digest=sha256:a7c9e0bc95d268d6e29f640deddaa3457980c95a6f0399a8293a0efafa0bae9b

Observation 44e1525b-a63d-4526-afd9-50c78ff60cc9 · outbound

This paper cites On evaluating adversarial robustness of large vision-language models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks On evaluating adversarial robustness of large vision-language models

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.101716Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.519480Z digest=sha256:9cc7b3b9e7cd6f3af32950dc97323b66ec204daae6aef5e6eadc5c724815f426

Observation 8447102d-4c56-4706-9e50-36519ca91265 · outbound

This paper cites Transferable ad- versarial perturbations.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks Transferable ad- versarial perturbations

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.084878Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.524051Z digest=sha256:5b9db925a83955462bf994dc396092bbccc79bef2b6c1bbeb3657c404fcfa499

Observation cf23132f-9ad5-4d51-9356-af7bce5250f5 · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 56

Resolution
unresolved
no resolver link, observed 2026-08-12T14:04:45.528550Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T14:04:45.528550Z digest=sha256:1e83250c33536e2af015edc609e9cf0a410109faacbf92f11f74266e242483ac

Observation deaa29fd-bdcf-41e4-bd4a-0cbfb48337c2 · outbound

This paper cites How do you think of this image?.

Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks How do you think of this image?

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-12T14:04:46.068676Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=pdf_text observed=2026-08-12T14:04:45.533578Z digest=sha256:debe0736d5daaff015e366e6bb8d4b40d3b26970eadd37fb3c45d2ac7c95462c

Pith citing papers

Observation 8098073a-5b68-454e-a740-3086ae4f2dad · inbound

Transferable Adversarial Attacks on Black-Box Vision-Language Models cites this paper.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks

Reference 74

Resolution
verified exact
local_arxiv, observed 2026-08-16T04:34:34.553216Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-22T06:32:14.747728+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.429357Z digest=sha256:c2689e1d065bb3457999ec979c05637aab31442e3c2c74b92b3d99b049c144bf