Skip to content
Search
paperSeptember 2026Unreviewed

FreqDoor: A Hidden Trojan in the Frequency Domain for Backdoor Attacks on Vision-Language Models

Yasir Arafat Prodhan, Sadad Hasan, Mohammed Imamul Hassan Bhuiyan

Abstract

Vision-language models (VLMs) have recently shown excellent progress in open-ended image-to-text generation. However, their multimodal nature makes them persistently vulnerable to backdoor attacks. Existing backdoor triggers for VLMs are either spatial, textual, or bimodal, which may yield localized or recognizable trigger patterns. In this work, we explore a different attack surface and propose \ textsc {FreqDoor}, a training-time backdoor attack that implants triggers in the frequency domain.

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{prodhan2026freqdoor,
  title = {{FreqDoor: A Hidden Trojan in the Frequency Domain for Backdoor Attacks on Vision-Language Models}},
  author = {Yasir Arafat Prodhan and Sadad Hasan and Mohammed Imamul Hassan Bhuiyan},
  year = {2026},
  month = sep,
  eprint = {2609.07048},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/15ae338e8edb475cce1e45bcd3eabb628cbf098a}
}