July 2026Unreviewed
Architectural Backdoors in Vision-Language Model Supply Chains via Representation Steering
Maria Rosaria Briglia, Igor Maljkovic, Antonio Emanuele Cinà, Luca Oneto, Iacopo Masi, Fabio Roli
Abstract
Vision--Language Models (VLMs) are increasingly deployed through a model supply chain in which pretrained checkpoints, architecture definitions, text encoders, and exported computation graphs are distributed by third parties and reused across downstream services. This reuse model creates a security-critical trust boundary: VLM deployments inherit not only learned parameters but also executable behavior encoded in shared model artifacts. In this paper, we show that a malicious provider can exploi
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM03Supply Chain
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0010AI Supply Chain Compromise
- AML.T0020Poison Training Data
Suggested from the entry's categories.
Cite
@misc{briglia2026architectural,
title = {{Architectural Backdoors in Vision-Language Model Supply Chains via Representation Steering}},
author = {Maria Rosaria Briglia and Igor Maljkovic and Antonio Emanuele Cinà and Luca Oneto and Iacopo Masi and Fabio Roli},
year = {2026},
month = jul,
eprint = {2607.25479},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.25479}
}