Pith. sign in

Paper Citation Record · LEDGER

Transferable Adversarial Attacks on Black-Box Vision-Language Models

As of 19 August 2026, this Paper Citation Record lists 83 of 83 outbound references and 9 inbound Pith citation observations for arXiv:2505.01050.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2505.01050 v1

Coverage vector

measured 83 of 83 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-16T04:34:34.466875Z

measured 92 of 92 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 9 of 9 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-15T17:47:19.126970Z

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-07-04T00:59:21.218293Z

Reference resolution

83 of 83 outbound references displayed

  • verified exact1
  • verified fuzzy25
  • unresolved57
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation ee7b22f6-444c-4832-878a-abc3ddd21edb · outbound

This paper cites write newline.

Transferable Adversarial Attacks on Black-Box Vision-Language Models write newline

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.160872Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.160872Z digest=sha256:bb61477ea4c57d8d5e083f40df06cce1750c3d656a2c24fb64d50db0b5c78cdd

Observation c1f9d0ad-3eae-4627-81c5-c258e9542356 · outbound

This paper cites GPT-4 Technical Report.

Transferable Adversarial Attacks on Black-Box Vision-Language Models GPT-4 Technical Report

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.165708Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.165708Z digest=sha256:0fac6ae23cfdc06e16ead23818f0d4a51c00f2e3ed745207c302d6f463c5fa9d

Observation e8e6b134-43b6-48e7-b94d-596091a31889 · outbound

This paper cites Llama 3 model card.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Llama 3 model card

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.169725Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.169725Z digest=sha256:4e5148a93192f324f6633687572703d64330e5b90b873cf9840f6a1e9280c369

Observation 9130abb0-0457-4875-8965-f7b8d118eda3 · outbound

This paper cites Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreaking Leading Safety-Aligned LLMs with Simple Adaptive Attacks

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.173226Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.173226Z digest=sha256:a47f79f0e027f9ec9df3be577dfe76315beeffd238bac6f0fb60243b2851ad12

Observation 26b926a3-bd56-4dc1-81ca-fba99ae45735 · outbound

This paper cites Model card and evaluations for claude models, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Model card and evaluations for claude models, 2023

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.177020Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.177020Z digest=sha256:267327e1d739ba5758cd4cef35adfddcbe7c8c1dcd1da6e38d8d671dd42b30d5

Observation e6f7accd-9ed6-4bf5-90e0-d438fec113c9 · outbound

This paper cites The claude 3 model family: Opus, sonnet, haiku.

Transferable Adversarial Attacks on Black-Box Vision-Language Models The claude 3 model family: Opus, sonnet, haiku

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.334246Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.180461Z digest=sha256:f4016de5fb394e99d7fea6ba99055fc162f23b1ce0ecb9000d50c380ec213434

Observation 51845fca-6eda-4c25-aa77-cae82fd698f9 · outbound

This paper cites Qwen2.5-VL Technical Report.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Qwen2.5-VL Technical Report

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.183861Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.183861Z digest=sha256:d1291f26bbd64d4d9dfb36986687135c14a44457738d3c6a1e13422ece53c541

Observation 836fd2c4-9d7f-40e5-b3d4-6ada7dcd91ce · outbound

This paper cites Image Hijacks: Adversarial Images can Control Generative Models at Runtime.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Image Hijacks: Adversarial Images can Control Generative Models at Runtime

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.187704Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.187704Z digest=sha256:050fa9d8bc6a5939e544d9caf4161c11f37444f437da075717ca694aa9e1296f

Observation 4e74ba98-fd9a-46b4-bb3e-5d9664275554 · outbound

This paper cites Evasion attacks against machine learning at test time.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Evasion attacks against machine learning at test time

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.323690Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.191197Z digest=sha256:4dcb8e96a258e9f55c970548c62e11cf2418d39bfaf6362d6f98c631930ae222

Observation 39791491-56bc-4bf0-8687-8010b191d4a8 · outbound

This paper cites RT-2: Vision-Language-Action Models Transfer Web Knowledge to Robotic Control.

Transferable Adversarial Attacks on Black-Box Vision-Language Models RT-2: Vision-Language-Action Models Transfer Web Knowledge to Robotic Control

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.194529Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.194529Z digest=sha256:d8fd893c216e42720fd935b5918b2a2ccadce0c42013522a62b78a484d2bcc51

Observation 232eb64f-ff7b-4d68-9b15-2d61f3da3c31 · outbound

This paper cites Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Are aligned neural networks adversarially aligned? Advances in Neural Information Processing Systems, 36, 2023

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.313026Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.198028Z digest=sha256:a516a013d9a12e2edd3c7dd3b8d1883ce1d837cb2f2c33dcc5d23fc13a91b412

Observation 1ca1d42d-810c-4d58-91f2-90a79f8a560d · outbound

This paper cites Jailbreaking Black Box Large Language Models in Twenty Queries.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreaking Black Box Large Language Models in Twenty Queries

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.201186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.201186Z digest=sha256:dc269006bf8c9aca38462c08461a6a6683298d354666c59f602d50bd8910c5a7

Observation 807f4dd1-4a16-4aae-ad71-fb07a707204f · outbound

This paper cites Rethinking Model Ensemble in Transfer-based Adversarial Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Rethinking Model Ensemble in Transfer-based Adversarial Attacks

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.204316Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.204316Z digest=sha256:e5d1715685b9c89d47e142850cdb7ad804eca332eda4c15378d870db56cc524a

Observation 9426dbcb-d891-4347-82ca-93130fa736ae · outbound

This paper cites Red Teaming GPT-4V: Are GPT-4V Safe Against Uni/Multi-Modal Jailbreak Attacks?.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Red Teaming GPT-4V: Are GPT-4V Safe Against Uni/Multi-Modal Jailbreak Attacks?

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.207424Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.207424Z digest=sha256:f2edff35735e29a45b53d5f4edd9e3bb2f558837b1d0aa241c590810fbfe33f4

Observation d3ecb44a-bc7b-408e-8fa1-50e26bffde9f · outbound

This paper cites Certified adversarial robustness via randomized smoothing.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Certified adversarial robustness via randomized smoothing

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.302101Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.210767Z digest=sha256:9f55740fe482364f8571a36d51e7b62acb47ab3a5483dbbef9ab4d2d6307173e

Observation a52e39a9-b6c0-42c4-ba6e-9bbd402ddff1 · outbound

This paper cites Vision Transformers Need Registers.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Vision Transformers Need Registers

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.214741Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.214741Z digest=sha256:cb6fb39c455ef07ae23a19c1207cb21c4d2b07818e410d5309d7384ea53cb912

Observation 50de2276-79c0-4cee-ab66-7476e8d7afae · outbound

This paper cites Paddleocr: An easy-to-use ocr tool based on paddlepaddle.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Paddleocr: An easy-to-use ocr tool based on paddlepaddle

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.194540Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.218313Z digest=sha256:20c9d99bf156ae79f31fbecd236f104c96c676ec165fe964f1fb6c342e6ac23b

Observation 7ca23396-7e39-4883-8729-a54a7e1a16fe · outbound

This paper cites How Robust is Google's Bard to Adversarial Image Attacks?.

Transferable Adversarial Attacks on Black-Box Vision-Language Models How Robust is Google's Bard to Adversarial Image Attacks?

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.222225Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.222225Z digest=sha256:d8ab6b86b08be7f5b5ce642296a854581ea7bcc8c54d07cd35f09a4007d94d7c

Observation f1c10498-814c-4243-abb0-4f67ac295e5e · outbound

This paper cites Large language models in radiology: fundamentals, applications, ethical considerations, risks, and future directions.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Large language models in radiology: fundamentals, applications, ethical considerations, risks, and future directions

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.184607Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.226222Z digest=sha256:91872ef502b2c4b378f526cff0f5cae658f2d4e134261160a5e3fce47c379d08

Observation da38a1d0-1415-4c07-aca8-e13158d5c825 · outbound

This paper cites Robust physical-world attacks on deep learning visual classification.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Robust physical-world attacks on deep learning visual classification

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.229543Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.229543Z digest=sha256:54767e0b7d038bd3d1439a2317bfb6f7f45d336be37dff2cff5211fef2c06dd6

Observation c917b5d7-14cd-4058-acf7-ac06200894c6 · outbound

This paper cites Data Filtering Networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Data Filtering Networks

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.232849Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.232849Z digest=sha256:25a92a1cf9ac01d1d6b63ab3099df0df1d5f154cfd765d24d134e16f190e5e8e

Observation 7048848a-7e78-4c27-bd35-59cfc9c775cf · outbound

This paper cites Sharpness-Aware Minimization for Efficiently Improving Generalization.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Sharpness-Aware Minimization for Efficiently Improving Generalization

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.236251Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.236251Z digest=sha256:a1845b38c9091e96c863bb66cc4da7c84c30c2bb4b90fbce3b8b6ffa3c77c316

Observation baeb416b-e12e-4682-99b0-3df4979f8d64 · outbound

This paper cites Multimodal neurons in artificial neural networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Multimodal neurons in artificial neural networks

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.239756Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.239756Z digest=sha256:37095f3a982f16e0475bd6e45c557aeda6098cad594ec40c28218a49e87c6dbb

Observation edf5d497-06fc-4a0f-aa12-a64ea4280b78 · outbound

This paper cites Goodfellow, Jonathon Shlens, and Christian Szegedy.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Goodfellow, Jonathon Shlens, and Christian Szegedy

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.243186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.243186Z digest=sha256:9f37d27a44f81527089947927106b2cf0f390f9bd9c5a97f6b616bf4c2554ae6

Observation aecff6d5-dc7e-406e-85fa-25e26479f794 · outbound

This paper cites Regulating chatgpt and other large generative ai models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Regulating chatgpt and other large generative ai models

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.156584Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.247003Z digest=sha256:326138a181c20a234d42b0e368cd5e3a4bba5ad04ecee9618ff06afc9e1090a9

Observation e246c911-ba7e-4294-9dd0-eac34feaeae7 · outbound

This paper cites Deep residual learning for image recognition.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Deep residual learning for image recognition

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.250782Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.250782Z digest=sha256:53965f7925bec69d6abd4a539951ab66d3d9cb6e208292d4fd9a9fe60a927fb3

Observation 9f14c6a3-d17a-479d-9f35-df75d17c215e · outbound

This paper cites Deep networks with stochastic depth.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Deep networks with stochastic depth

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.140252Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.253970Z digest=sha256:b60e5fb860ae06f92a3c3b81938d1b6a9265d1b5a49a866c1f09b0ce9e6398d1

Observation cd3aeb0a-9296-4bee-a9e1-a04458abb6d5 · outbound

This paper cites Densely connected convolutional networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Densely connected convolutional networks

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.257743Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.257743Z digest=sha256:4a724da67894d99a9abf63cd28afa5a9b9eb6fc8c4309dec62140823bbf524ff

Observation cbe52011-36f5-4a70-9efc-7a6331ddbfb2 · outbound

This paper cites Averaging Weights Leads to Wider Optima and Better Generalization.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Averaging Weights Leads to Wider Optima and Better Generalization

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.261402Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.261402Z digest=sha256:8bd93dca8b3e24389a6b410f5a1e94ab686f3664d0531b9e7c7396bdbada5088

Observation 1b224d41-e382-4346-9245-fc29747c201a · outbound

This paper cites Baseline Defenses for Adversarial Attacks Against Aligned Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Baseline Defenses for Adversarial Attacks Against Aligned Language Models

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.264833Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.264833Z digest=sha256:8f6a3860850abbe635627cceebe879dda21c290baa31dc8647010d8a25bd3355

Observation 3655163f-0bf5-429b-8b3a-382f9c8e6832 · outbound

This paper cites Never Stop Learning: The Effectiveness of Fine-Tuning in Robotic Reinforcement Learning.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Never Stop Learning: The Effectiveness of Fine-Tuning in Robotic Reinforcement Learning

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.268065Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.268065Z digest=sha256:584f1367936ca06b0880788f124e7e2711558609c8b1a460804df0cb9df25e33

Observation 2871704e-3301-4862-ad25-a614fd5e33e4 · outbound

This paper cites Adversarial attacks and defences competition.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Adversarial attacks and defences competition

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.123434Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.271617Z digest=sha256:5f751782e3a53383fcc38e97dd221b8b86db35eb32577f537b433a5042ff5fc8

Observation 4312c81d-cf67-4f78-941b-c871117676aa · outbound

This paper cites Building and better understanding vision-language models: insights and future directions.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Building and better understanding vision-language models: insights and future directions

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.111904Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.274647Z digest=sha256:ad192281fa25ff017edba408865f83f43d109deec00b6f7b0deb9264c6fc6923

Observation 9cc1f752-8afe-4863-b58a-5f4a0ff6ad60 · outbound

This paper cites LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models LLaVA-NeXT-Interleave: Tackling Multi-image, Video, and 3D in Large Multimodal Models

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.278320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.278320Z digest=sha256:7ae8c1e92280692a3f6e03929624caca105902430ee5b937e033d73f3e19fbdc

Observation 9aa46f9c-67aa-45d8-85ed-081b9373d979 · outbound

This paper cites LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet.

Transferable Adversarial Attacks on Black-Box Vision-Language Models LLM Defenses Are Not Robust to Multi-Turn Human Jailbreaks Yet

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.281806Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.281806Z digest=sha256:9b964945b9d5842d476684e773c82417952fcbd77dc3fd588e5ee6e61a11de84

Observation 1eb14972-568b-4528-8915-f112ab047e13 · outbound

This paper cites CLIPA-v2: Scaling CLIP Training with 81.1% Zero-shot ImageNet Accuracy within a \$10,000 Budget; An Extra \$4,000 Unlocks 81.8% Accuracy.

Transferable Adversarial Attacks on Black-Box Vision-Language Models CLIPA-v2: Scaling CLIP Training with 81.1% Zero-shot ImageNet Accuracy within a \$10,000 Budget; An Extra \$4,000 Unlocks 81.8% Accuracy

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.285319Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.285319Z digest=sha256:ee44633ce5db67a73473d33df2f9667deee2f78c89e80527b9399a25e35e0fdb

Observation d5de2046-b404-4555-98cb-c10e2f1e9d27 · outbound

This paper cites Microsoft coco: Common objects in context.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Microsoft coco: Common objects in context

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.288730Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.288730Z digest=sha256:c163262a19a755f8709612ecbb373e1f1f0bb3b69c210aa93f610224e9b0cf06

Observation 9252b662-3bce-4a33-b020-cdf5d0e2d9cf · outbound

This paper cites Visual instruction tuning.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Visual instruction tuning

Reference 38

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.292579Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.292579Z digest=sha256:13d1ad8f128210aaba46db9ef95dc406cbc34b907be7a1b03887ca5e69faf912

Observation 80a0dc0b-8f2e-43e9-9603-5a92ea86eda5 · outbound

This paper cites AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.296596Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.296596Z digest=sha256:484e9c94cd0998845c041aee8c5328450c0961e8784b97fe37654d66bb1701bd

Observation 481d7042-6bb0-4912-8d02-81dac63c5978 · outbound

This paper cites Delving into Transferable Adversarial Examples and Black-box Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Delving into Transferable Adversarial Examples and Black-box Attacks

Reference 40

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.300807Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.300807Z digest=sha256:9ae409c7d9fd5612fa9d1b4f25b6342303e960e80de6c7876ca6c6cb076235a2

Observation 27af11fa-8c4d-498b-811b-0c7b81a84cdd · outbound

This paper cites Patchdropout: Economizing vision transformers using patch dropout.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Patchdropout: Economizing vision transformers using patch dropout

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.089645Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.304830Z digest=sha256:fa2eb0ee0f9590e09f33695318a0b9001aec9f6b69368d528147fd26af237274

Observation 11573e70-cf04-4886-be86-0cdff54478d7 · outbound

This paper cites Eureka: Human-Level Reward Design via Coding Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Eureka: Human-Level Reward Design via Coding Large Language Models

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.309778Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.309778Z digest=sha256:6ef6ef3db7889960e8362f838a2189669fba34dd41c08f82b2ae543c01565467

Observation 68622cfc-ae15-4c87-9263-e6bd30a6981e · outbound

This paper cites Dolphins: Multimodal Language Model for Driving.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Dolphins: Multimodal Language Model for Driving

Reference 43

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.313636Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.313636Z digest=sha256:eae07968930374d7ab5e478df47c1f1bf7cc209b8063eb0b58aec0681becc3e8

Observation d49c94cf-a37c-4eab-ad42-605e4f34c7d5 · outbound

This paper cites Towards Deep Learning Models Resistant to Adversarial Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Towards Deep Learning Models Resistant to Adversarial Attacks

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.317179Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.317179Z digest=sha256:7cc7fd4af764ba845295ab9955aa58d4a9fc9abff1ca9f33220cd06814d66a28

Observation c25168d4-a740-44fa-afbd-38e34691dd90 · outbound

This paper cites Understanding Zero-Shot Adversarial Robustness for Large-Scale Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Understanding Zero-Shot Adversarial Robustness for Large-Scale Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.321269Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.321269Z digest=sha256:f5331d25ac88ecef3268fb8be98881eaa6ca2266ee8886e0e98c2a486120b357

Observation aaac4266-6e2e-4a63-81a3-a2c5efbe9873 · outbound

This paper cites Harmbench: A standardized evaluation framework for automated red teaming and robust refusal, 2024.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Harmbench: A standardized evaluation framework for automated red teaming and robust refusal, 2024

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.324838Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.324838Z digest=sha256:b07d540a378020202c428ba7eec811edd1399b0d0442875491243f354008f66e

Observation e690f6c5-0185-41da-a841-e90c7a6c9afc · outbound

This paper cites Scalable Extraction of Training Data from (Production) Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Scalable Extraction of Training Data from (Production) Language Models

Reference 47

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.328770Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.328770Z digest=sha256:49b5446244b27435994a9446192745493c2134bb88b3b7f2ec22657afacdc2c7

Observation fbc5b27a-69e5-4e4a-8941-14352182ff0f · outbound

This paper cites Jailbreaking attack against multimodal large language model, 2024.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreaking attack against multimodal large language model, 2024

Reference 48

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.072486Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.332699Z digest=sha256:51a6573bca01b991fafa6a2a4ab55f313631127754dff6df158354c5d7b3c74a

Observation 6e009c27-e2dd-4a1a-b694-386043d21d7a · outbound

This paper cites Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Reading Isn't Believing: Adversarial Attacks On Multi-Modal Neurons

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.336232Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.336232Z digest=sha256:155ceb4e6d01f51104f5ce29f615d14f640a3bfb3ad13dd52c79caf7c3e1c5ad

Observation 397a5291-2ca0-459b-b322-721411ef9bf7 · outbound

This paper cites Gpt-4v(ision) system card.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Gpt-4v(ision) system card

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.061079Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.340244Z digest=sha256:fe2678387065b694105a616901ee3cce404b6331e91a51ca959bea686d391e6a

Observation e452ad34-7705-449e-8ce0-ad8e39aecbe7 · outbound

This paper cites DINOv2: Learning Robust Visual Features without Supervision.

Transferable Adversarial Attacks on Black-Box Vision-Language Models DINOv2: Learning Robust Visual Features without Supervision

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.343572Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.343572Z digest=sha256:01f20e4ccdaa759a4935506a0defaa915940746c41a7c1a9085994386c8e98da

Observation 31917675-06f1-4ff2-a576-5f522215132b · outbound

This paper cites Training language models to follow instructions with human feedback.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Training language models to follow instructions with human feedback

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.347345Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.347345Z digest=sha256:c7c44e2200dd90a09c717f5a00828818ed32c49207a4e2dfd0a5548897ca04a8

Observation d3b099a6-3c9b-46a5-95f6-3d137a42650a · outbound

This paper cites Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples

Reference 53

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.351555Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.351555Z digest=sha256:7b4e6b1cf8394960edba4cf6be5f89c36c802b0eede5301904b785788f936c91

Observation 7294eb77-a106-4f77-961d-072e8f5abf85 · outbound

This paper cites Red Teaming Language Models with Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Red Teaming Language Models with Language Models

Reference 54

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.355320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.355320Z digest=sha256:884effba78f57c9b894c4c9e623249a2be7828b165f0e773a22541fd14540af6

Observation 11478142-a000-4211-a3b5-edf8ed4033c9 · outbound

This paper cites Visual Adversarial Examples Jailbreak Aligned Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Visual Adversarial Examples Jailbreak Aligned Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.359095Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.359095Z digest=sha256:c6b912c6b44d1b9779d39bf0ccff0d0682a82d7d9df465abc8c390bbc94c1cf1

Observation 9ddc675e-172b-404b-95bb-de48503a1681 · outbound

This paper cites Visual adversarial examples jailbreak aligned large language models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Visual adversarial examples jailbreak aligned large language models

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.044476Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.362562Z digest=sha256:ef6896a5b0ef452324bac8bee4157a3c99ffca9a85d171853a69f1f07fd9b586

Observation 0d2ef145-9649-4d72-a572-8f2af5b54c4a · outbound

This paper cites Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever

Reference 57

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.365888Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.365888Z digest=sha256:d1fa308f7f1455776b54d852da00b492a46e156a9521f3ae44b893ae0c5de7c6

Observation d88ab7dc-704e-43c5-aa28-716ad2bb366d · outbound

This paper cites Differentiable jpeg: The devil is in the details.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Differentiable jpeg: The devil is in the details

Reference 58

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.027475Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.369398Z digest=sha256:aef3380be5a8d2485530417384a696b1c7ec79fe6c95f9c79a9d15f7781ed9df

Observation f9f122a6-6ec2-4f5c-a5e3-0f689f4716c7 · outbound

This paper cites Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context

Reference 59

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.372863Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.372863Z digest=sha256:891524314600e0eeab274b39c829c13862eb3b69e9b45799208cc162a86c14d1

Observation 97df4209-91f5-40e2-9329-a443e7ea1f3c · outbound

This paper cites SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.376170Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.376170Z digest=sha256:809faa50ae90649331a7fe2737556e2f004814b025b5abd324d849f8c079fb5c

Observation 3a2f6f71-4c12-4d2e-a8fe-04fb90316f91 · outbound

This paper cites Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Great, Now Write an Article About That: The Crescendo Multi-Turn LLM Jailbreak Attack

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.379800Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.379800Z digest=sha256:ac01294a86fb0d3fcbc18b6c26db95e87e2b0c1b33a0bec10c7b54549783d622

Observation ca1f1b1f-c6fe-44f6-830f-d534fcc3d422 · outbound

This paper cites On the adversarial robustness of multi-modal foundation models, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models On the adversarial robustness of multi-modal foundation models, 2023

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:35.016635Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.383530Z digest=sha256:19a3d46ae9b8c33f3cc0298ec0ecaf8102e28d145978d7f98421b24cdd773684

Observation cc0a9220-ecc6-4d3c-84af-29d5a1aa0ca9 · outbound

This paper cites AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated Prompts.

Transferable Adversarial Attacks on Black-Box Vision-Language Models AutoPrompt: Eliciting Knowledge from Language Models with Automatically Generated Prompts

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.386874Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.386874Z digest=sha256:e678809a4a0e40e8d1e1ee2baf82ee846edf8a9d6f0434f9d67e140d9346172a

Observation f70b5db4-965e-4f5b-93bf-2b3238c6176b · outbound

This paper cites Large language models encode clinical knowledge.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Large language models encode clinical knowledge

Reference 64

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.390469Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.390469Z digest=sha256:6ac4a31c145536628b1a124b41cbb8139912ddf9ce6c9618899783f67e3eec23

Observation b7aec58d-5757-46b4-b2d5-5739a65e39bd · outbound

This paper cites Intriguing properties of neural networks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Intriguing properties of neural networks

Reference 65

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.999340Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.393694Z digest=sha256:df8efed56058cb3b8c4b5e670cec3ffc1cf15d5884c1ea56de7d6bd3930ee131

Observation 59aac060-3960-4ca3-968c-105bd69d0e3c · outbound

This paper cites Gemini: A Family of Highly Capable Multimodal Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Gemini: A Family of Highly Capable Multimodal Models

Reference 67

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.402597Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.402597Z digest=sha256:ca4bb707e930c62a7c8a72bc194080fccb576b4722c3c268bc3ab803aab55a05

Observation 13566eb0-cbcb-4617-ba8a-27d344237974 · outbound

This paper cites Ocr receipts text detection - retail dataset.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Ocr receipts text detection - retail dataset

Reference 68

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.988698Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.406226Z digest=sha256:752db8fa676bbb957fb796a0ed79049cd8bef265b261366cd1355c8ec3147dc1

Observation be2e8e0e-1bd3-4924-bcb3-05519571c5a5 · outbound

This paper cites Revisiting adversarial training at scale.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Revisiting adversarial training at scale

Reference 69

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.978521Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.409854Z digest=sha256:0c2eaffd916c0ca285248b3ea45451b11082d2ba4098522190d6a393e259046f

Observation b044c04a-fc3d-4f0e-b9bc-62f58051a898 · outbound

This paper cites Jailbroken: How does llm safety training fail? Advances in Neural Information Processing Systems, 36, 2024 a.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbroken: How does llm safety training fail? Advances in Neural Information Processing Systems, 36, 2024 a

Reference 70

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.967929Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.413580Z digest=sha256:a467425c06981f1ab41852fc3801389f728140f1300d27d6242044ce4df320fa

Observation 7244f837-b6ae-4d54-ad5c-8cb269bd01e9 · outbound

This paper cites Jailbreak and guard aligned language models with only few in-context demonstrations, 2024 b.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Jailbreak and guard aligned language models with only few in-context demonstrations, 2024 b

Reference 71

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.957335Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.417198Z digest=sha256:6827f16e2252cbff27765aa886ae836f1e420590ffac13a3f7240adb7fbd95b8

Observation a68d8c79-e523-4acf-bb1e-9ec3731ab0aa · outbound

This paper cites Dissecting adversarial robustness of multimodal lm agents.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Dissecting adversarial robustness of multimodal lm agents

Reference 72

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.421120Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.421120Z digest=sha256:82000e99650f72f53fe6e2a45efc2ccd8cc730dc7744997c7999ef5576ec2b9c

Observation 670d1895-d82d-4dfd-a0fc-fe322807d972 · outbound

This paper cites Dissecting Adversarial Robustness of Multimodal LM Agents.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Dissecting Adversarial Robustness of Multimodal LM Agents

Reference 73

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.424911Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.424911Z digest=sha256:eadaa395a9464ed780120b1c7b8ce04cf1fbd746cd017377a198f2a0629507d9

Observation 8098073a-5b68-454e-a740-3086ae4f2dad · outbound

This paper cites Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Chain of Attack: On the Robustness of Vision-Language Models Against Transfer-Based Adversarial Attacks

Reference 74

Resolution
verified exact
local_arxiv, observed 2026-08-16T04:34:34.553216Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.429357Z digest=sha256:1fe6a1600dcb4ea93afed3d7988d9ee8e04a8d1b959b3720d05e46e6fdfe3a2d

Observation 72383db9-b1d3-45d9-9f47-65aa2151b5b3 · outbound

This paper cites Demystifying clip data.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Demystifying clip data

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.940263Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.433526Z digest=sha256:8f31b3cbe782b11e0361e4668b545d47c55d10f03d621ef49a7faf1bfd751589

Observation b746b0da-fa34-4596-8b86-df187c1e06ed · outbound

This paper cites SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering.

Transferable Adversarial Attacks on Black-Box Vision-Language Models SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering

Reference 76

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.437510Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.437510Z digest=sha256:983a4f7958db0519f3074652f38525da1ba2a809c520976641d0b6db469b4028

Observation 5bf8fc7b-d59a-4b8b-b7b6-9e4dc660a90e · outbound

This paper cites Vlattack: Multimodal adversarial attacks on vision-language tasks via pre-trained models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Vlattack: Multimodal adversarial attacks on vision-language tasks via pre-trained models

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.929583Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.441258Z digest=sha256:83cc481daad305c0a7fff37b4aab70b8adbfbd157024d5fc4e4f5cd42c74538b

Observation 9c16cce2-a0f2-4c45-97da-395ce6ca2154 · outbound

This paper cites Sigmoid Loss for Language Image Pre-Training.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Sigmoid Loss for Language Image Pre-Training

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.445195Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.445195Z digest=sha256:a6fb8cc1b249ddf24f5ac6879fb66e9bab4e2085bc5c65fee1495eb20e221991

Observation a43b2de4-395d-4954-ab51-ac79f180d4f1 · outbound

This paper cites Towards adversarial attack on vision-language pre-training models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Towards adversarial attack on vision-language pre-training models

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.918793Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.449121Z digest=sha256:7f984becde4c976405bf00e3ccd0da24e440169e4075b5887d9d2957072981b6

Observation 54dc0068-a54c-4b26-b7f1-045634ffd54f · outbound

This paper cites AnyAttack: Towards Large-scale Self-supervised Adversarial Attacks on Vision-language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models AnyAttack: Towards Large-scale Self-supervised Adversarial Attacks on Vision-language Models

Reference 80

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.452461Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.452461Z digest=sha256:29a910ee307bd14b31265ec0df93d0d469907c3e812c6e007ebaee151613b461

Observation 92dcd7cd-5107-40ce-b3eb-8bff966a0f68 · outbound

This paper cites On evaluating adversarial robustness of large vision-language models, 2023.

Transferable Adversarial Attacks on Black-Box Vision-Language Models On evaluating adversarial robustness of large vision-language models, 2023

Reference 81

Resolution
verified fuzzy
raw_fallback, observed 2026-08-16T04:34:34.907765Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-08-16T04:34:34.456215Z digest=sha256:bb53407ed344718bd8e783b04f02da7db5385b4dde6a0b10ee2ede16e2e13d11

Observation 0b7d4655-e1a3-445b-a6f2-bbaf08593a3a · outbound

This paper cites MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models.

Transferable Adversarial Attacks on Black-Box Vision-Language Models MiniGPT-4: Enhancing Vision-Language Understanding with Advanced Large Language Models

Reference 82

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.459651Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.459651Z digest=sha256:871100591e542a59dffd58f0a39fc083f201915013293e66af3be59d746a2d94

Observation ba8479a5-2b5a-49b7-9c2f-3f3480a5ea99 · outbound

This paper cites Zico Kolter, and Matt Fredrikson.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Zico Kolter, and Matt Fredrikson

Reference 83

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.463162Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.463162Z digest=sha256:cccdee6e04877ff1acbb5ab9b7c480db8cb32652e2d1f0e1e7c740d7dff46ed8

Observation 321b9f85-1b30-480c-aa8d-879559e90024 · outbound

This paper cites Improving Alignment and Robustness with Circuit Breakers.

Transferable Adversarial Attacks on Black-Box Vision-Language Models Improving Alignment and Robustness with Circuit Breakers

Reference 84

Resolution
unresolved
no resolver link, observed 2026-08-16T04:34:34.466875Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T04:34:34.466875Z digest=sha256:9e9612052b52071111811d3471c0e7168359caefca0dd12b7153ebbf8f620f8c

Pith citing papers

Observation 02d142aa-3a58-466f-8bc4-7634cb758e85 · inbound

AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery cites this paper.

AdInject: Real-World Black-Box Attacks on Web Agents via Advertising Delivery Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-07T13:32:46.117270Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:32:46.117270Z digest=sha256:e3677e26047a6070d2ac9ef09d825fe0cbefa35f01483590dbabfc7a45cc3f64

Observation 083f7259-0d1d-4bde-8eca-180cf529d63e · inbound

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition cites this paper.

Security Challenges in AI Agent Deployment: Insights from a Large Scale Public Competition Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 19

Resolution
unresolved
no resolver link, observed 2026-08-15T17:47:19.126970Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T17:47:19.126970Z digest=sha256:c30b2857c019e42058a30f0f12540196e2cc66d8bc74656d8622d2db2b90acec

Observation 7718ef9e-c485-457e-85e4-0f6bf281c1b3 · inbound

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models cites this paper.

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 12

Resolution
verified exact
arxiv_id, observed 2026-05-16T19:31:13.089502Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-16T19:29:43.382392Z digest=sha256:dbe360244895489831ce1f58772f8f542922a0d71468396de046baf0f465d89f

Observation b65d8d1c-3f79-4555-8cf8-0ba3c20b67c9 · inbound

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models cites this paper.

High-Entropy Tokens as Multimodal Failure Points in Vision-Language Models Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-03T14:05:23.148338Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T14:05:23.148338Z digest=sha256:328445a8905578ff162c6983c4195fcd9814685531554d89354e323c12d15cb5

Observation 2385f503-96eb-40c1-99f4-b7e947b121da · inbound

Universal Adversarial Attacks against Closed-Source MLLMs via Target-View Routed Meta Optimization cites this paper.

Universal Adversarial Attacks against Closed-Source MLLMs via Target-View Routed Meta Optimization Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 4

Resolution
verified exact
arxiv_id, observed 2026-05-16T09:27:40.991023Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-16T09:26:14.799360Z digest=sha256:acb83e040c11818183a5f17d5226e16556fc4630fd8ff066db6e724286806745

Observation 367a0044-35ea-4727-84dd-85f327c10403 · inbound

Laundering AI Authority with Adversarial Examples cites this paper.

Laundering AI Authority with Adversarial Examples Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 28

Resolution
verified exact
arxiv_id, observed 2026-05-11T17:41:08.067046Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-08T17:19:38.662062Z digest=sha256:b1bf181c5e392608cbe240527143d76361a26ae62151a74e5eaeec48cf349f0f

Observation 3f59c936-afc0-45cb-8666-d687fe540a52 · inbound

Frequency-Domain Regularized Adversarial Alignment for Transferable Attacks against Closed-Source MLLMs cites this paper.

Frequency-Domain Regularized Adversarial Alignment for Transferable Attacks against Closed-Source MLLMs Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-22T01:25:52.636726Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-22T01:25:06.528845Z digest=sha256:701ec905cff59b45f0360820df52636d1df871e6f103c49a89c1510b3546387b

Observation c377a7fd-f605-4322-af3d-26b9ebffd054 · inbound

Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks cites this paper.

Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 57

Resolution
verified exact
arxiv_id, observed 2026-07-04T00:59:21.220186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-26T20:44:41.268975Z digest=sha256:4f96a309985e9d18a1d769fce718c9fe639887ed784e07c42bec0c2957bd5403

Observation 4a2d34d4-02f9-4e9a-ac19-5bab80e8a762 · inbound

Steal the Patch Size: Adversarially Manipulate Vision-Language Models cites this paper.

Steal the Patch Size: Adversarially Manipulate Vision-Language Models Transferable Adversarial Attacks on Black-Box Vision-Language Models

Reference 28

Resolution
metadata mismatch
arxiv_id, observed 2026-07-02T19:37:18.466063Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-07-02T19:30:19.691473Z digest=sha256:0ad71d3ef0e595ed13c4defc6a3842e0e6a1567ebe20f574590670961ddbf639