July 2026Unreviewed
Image-embedded prompt injection vulnerability of vision-language models in dental radiology: a cross-vendor attack–defense evaluation
Babak Saravi, Daman Deep Singh, Lara Schorn, Andreas Vollmer, Christoph Sproll, Norbert Kübler, Felix Schrader
Abstract
Abstract Image-embedded prompt injection — adversarial text rendered into the pixel data of medical images — is an emerging threat to vision-language models (VLMs) used in clinical decision support. We systematically evaluated this vulnerability across four production-tier VLMs (GPT-4o, Gemini 2.5 Flash, Claude Sonnet 4.5, MedGemma 4B) on 270 dental panoramic radiographs from the DenTeX dataset under four attack classes (8 variants per image), comprising 9,720 baseline and 48,600 defense inferen
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{saravi2026imageembedded,
title = {{Image-embedded prompt injection vulnerability of vision-language models in dental radiology: a cross-vendor attack–defense evaluation}},
author = {Babak Saravi and Daman Deep Singh and Lara Schorn and Andreas Vollmer and Christoph Sproll and Norbert Kübler and Felix Schrader},
year = {2026},
month = jul,
doi = {10.21203/rs.3.rs-9932271/v1},
url = {https://doi.org/10.21203/rs.3.rs-9932271/v1}
}