Skip to content
Search
paperAugust 2026Unreviewed

Once Poisoned, Arbitrarily Controlled: A Programmable Backdoor in VLMs

Tao Lin, Gaojie Jin, Zongxi Liu, Peng Wu, Lijia Yu

Abstract

Existing vision-language model (VLM) backdoors are usually treated as static vulnerabilities: one-to-one and N-to-N attacks bind one or more triggers to a finite set of targets before victim training. This assumption substantially underestimates the threat. We show that a single poisoning phase can implant a programmable backdoor into a VLM, allowing an attacker to choose previously unseen target-caption semantics at inference time and synthesize corresponding stealthy triggers on demand. Unlike

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{lin2026once,
  title = {{Once Poisoned, Arbitrarily Controlled: A Programmable Backdoor in VLMs}},
  author = {Tao Lin and Gaojie Jin and Zongxi Liu and Peng Wu and Lijia Yu},
  year = {2026},
  month = aug,
  eprint = {2608.10959},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/d72f36000b19aeeb672f3fc41a15e33915bc8ca3}
}