English

A Two-Stage Globally-Diverse Adversarial Attack for Vision-Language Pre-training Models

Computer Vision and Pattern Recognition 2026-01-21 v1 Artificial Intelligence

Abstract

Vision-language pre-training (VLP) models are vulnerable to adversarial examples, particularly in black-box scenarios. Existing multimodal attacks often suffer from limited perturbation diversity and unstable multi-stage pipelines. To address these challenges, we propose 2S-GDA, a two-stage globally-diverse attack framework. The proposed method first introduces textual perturbations through a globally-diverse strategy by combining candidate text expansion with globally-aware replacement. To enhance visual diversity, image-level perturbations are generated using multi-scale resizing and block-shuffle rotation. Extensive experiments on VLP models demonstrate that 2S-GDA consistently improves attack success rates over state-of-the-art methods, with gains of up to 11.17\% in black-box settings. Our framework is modular and can be easily combined with existing methods to further enhance adversarial transferability.

Keywords

Cite

@article{arxiv.2601.12304,
  title  = {A Two-Stage Globally-Diverse Adversarial Attack for Vision-Language Pre-training Models},
  author = {Wutao Chen and Huaqin Zou and Chen Wan and Lifeng Huang},
  journal= {arXiv preprint arXiv:2601.12304},
  year   = {2026}
}

Comments

Accepted to ICASSP 2026

R2 v1 2026-07-01T09:09:20.518Z