Skip to content
Search
paperJuly 2026Unreviewed

Architectural Backdoors in Vision-Language Model Supply Chains via Representation Steering

Maria Rosaria Briglia, Igor Maljkovic, Antonio Emanuele Cinà, Luca Oneto, Iacopo Masi, Fabio Roli

Abstract

Vision--Language Models (VLMs) are increasingly deployed through a model supply chain in which pretrained checkpoints, architecture definitions, text encoders, and exported computation graphs are distributed by third parties and reused across downstream services. This reuse model creates a security-critical trust boundary: VLM deployments inherit not only learned parameters but also executable behavior encoded in shared model artifacts. In this paper, we show that a malicious provider can exploi

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM03Supply Chain
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0010AI Supply Chain Compromise
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{briglia2026architectural,
  title = {{Architectural Backdoors in Vision-Language Model Supply Chains via Representation Steering}},
  author = {Maria Rosaria Briglia and Igor Maljkovic and Antonio Emanuele Cinà and Luca Oneto and Iacopo Masi and Fabio Roli},
  year = {2026},
  month = jul,
  eprint = {2607.25479},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.25479}
}