{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:WZBEJ4K2METCVXOBTGTGTPQMG5","short_pith_number":"pith:WZBEJ4K2","schema_version":"1.0","canonical_sha256":"b64244f15a61262addc199a669be0c3740ed5033c8135a928eee49644cf5038e","source":{"kind":"arxiv","id":"2603.29418","version":2},"attestation_state":"computed","paper":{"title":"Covert Visual Prompt Injection against Commercial Multimodal Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CV","authors_text":"Chenqi Kong, Meiwen Ding, Song Xia, Xudong Jiang","submitted_at":"2026-03-31T08:22:07Z","abstract_excerpt":"Although multimodal large language models (MLLMs) are increasingly deployed in real-world applications, their instruction-following behavior leaves them vulnerable to prompt injection attacks. Existing prompt injection methods predominantly rely on textual prompts or perceptible visual prompts that are observable by human users. In this work, we study imperceptible visual prompt injection against powerful closed-source MLLMs, where adversarial instructions are embedded in the visual modality. Our method adaptively embeds the malicious prompt into the input image via a bounded text overlay to p"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2603.29418","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2026-03-31T08:22:07Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"8ff9bbb4274a4238a6c418635004e9f69f151b980f0bc8ce748fb0f3717db353","abstract_canon_sha256":"87f48a36cdc74a39d22dd727d77eae16350f251fc59b19671b958a417d361a3e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-08-12T01:24:19.237270Z","signature_b64":"tP0uP+oUXUa9CwZHekIa/hyNT0cBJSL2jtQAypWRFof42WquouxeF9Fh2rAhFJC/9mjpk2Tc/cLEMgvKEiJCBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b64244f15a61262addc199a669be0c3740ed5033c8135a928eee49644cf5038e","last_reissued_at":"2026-08-12T01:24:19.235326Z","signature_status":"signed_v1","first_computed_at":"2026-08-12T01:24:19.235326Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Covert Visual Prompt Injection against Commercial Multimodal Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CV","authors_text":"Chenqi Kong, Meiwen Ding, Song Xia, Xudong Jiang","submitted_at":"2026-03-31T08:22:07Z","abstract_excerpt":"Although multimodal large language models (MLLMs) are increasingly deployed in real-world applications, their instruction-following behavior leaves them vulnerable to prompt injection attacks. Existing prompt injection methods predominantly rely on textual prompts or perceptible visual prompts that are observable by human users. In this work, we study imperceptible visual prompt injection against powerful closed-source MLLMs, where adversarial instructions are embedded in the visual modality. Our method adaptively embeds the malicious prompt into the input image via a bounded text overlay to p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.29418","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2603.29418/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2603.29418","created_at":"2026-08-12T01:24:19.239208+00:00"},{"alias_kind":"arxiv_version","alias_value":"2603.29418v2","created_at":"2026-08-12T01:24:19.239208+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.29418","created_at":"2026-08-12T01:24:19.239208+00:00"},{"alias_kind":"pith_short_12","alias_value":"WZBEJ4K2METC","created_at":"2026-08-12T01:24:19.239208+00:00"},{"alias_kind":"pith_short_16","alias_value":"WZBEJ4K2METCVXOB","created_at":"2026-08-12T01:24:19.239208+00:00"},{"alias_kind":"pith_short_8","alias_value":"WZBEJ4K2","created_at":"2026-08-12T01:24:19.239208+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"2606.10742","citing_title":"MemVenom: Triggered Poisoning of Multimodal Memories in Web Agents","ref_index":8,"is_internal_anchor":true},{"citing_arxiv_id":"2603.28013","citing_title":"Kill-Chain Canaries: Stage-Level Tracking of Prompt Injection Across Attack Surfaces and Model Safety Tiers","ref_index":13,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5","json":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5.json","graph_json":"https://pith.science/api/pith-number/WZBEJ4K2METCVXOBTGTGTPQMG5/graph.json","events_json":"https://pith.science/api/pith-number/WZBEJ4K2METCVXOBTGTGTPQMG5/events.json","paper":"https://pith.science/paper/WZBEJ4K2"},"agent_actions":{"view_html":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5","download_json":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5.json","view_paper":"https://pith.science/paper/WZBEJ4K2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2603.29418&json=true","fetch_graph":"https://pith.science/api/pith-number/WZBEJ4K2METCVXOBTGTGTPQMG5/graph.json","fetch_events":"https://pith.science/api/pith-number/WZBEJ4K2METCVXOBTGTGTPQMG5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5/action/storage_attestation","attest_author":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5/action/author_attestation","sign_citation":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5/action/citation_signature","submit_replication":"https://pith.science/pith/WZBEJ4K2METCVXOBTGTGTPQMG5/action/replication_record"}},"created_at":"2026-08-12T01:24:19.239208+00:00","updated_at":"2026-08-12T01:24:19.239208+00:00"}