Skip to content
Search
paperMarch 2026Unreviewed

Hidden Ads: Behavior Triggered Semantic Backdoors for Advertisement Injection in Vision Language Models

Duanyi Yao, Changyue Li, Zhicong Huang, Cheng Hong, Songze Li

Abstract

Vision-Language Models (VLMs) are increasingly deployed in consumer applications where users seek recommendations about products, dining, and services. We introduce Hidden Ads, a new class of backdoor attacks that exploit this recommendation-seeking behavior to inject unauthorized advertisements. Unlike traditional pattern-triggered backdoors that rely on artificial triggers such as pixel patches or special tokens, Hidden Ads activates on natural user behaviors: when users upload images containi

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{yao2026hidden,
  title = {{Hidden Ads: Behavior Triggered Semantic Backdoors for Advertisement Injection in Vision Language Models}},
  author = {Duanyi Yao and Changyue Li and Zhicong Huang and Cheng Hong and Songze Li},
  year = {2026},
  month = mar,
  eprint = {2603.27522},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2603.27522}
}