Skip to content
Search
paperJuly 2026Unreviewed

Image-embedded prompt injection vulnerability of vision-language models in dental radiology: a cross-vendor attack–defense evaluation

Babak Saravi, Daman Deep Singh, Lara Schorn, Andreas Vollmer, Christoph Sproll, Norbert Kübler, Felix Schrader

Abstract

Abstract Image-embedded prompt injection — adversarial text rendered into the pixel data of medical images — is an emerging threat to vision-language models (VLMs) used in clinical decision support. We systematically evaluated this vulnerability across four production-tier VLMs (GPT-4o, Gemini 2.5 Flash, Claude Sonnet 4.5, MedGemma 4B) on 270 dental panoramic radiographs from the DenTeX dataset under four attack classes (8 variants per image), comprising 9,720 baseline and 48,600 defense inferen

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{saravi2026imageembedded,
  title = {{Image-embedded prompt injection vulnerability of vision-language models in dental radiology: a cross-vendor attack–defense evaluation}},
  author = {Babak Saravi and Daman Deep Singh and Lara Schorn and Andreas Vollmer and Christoph Sproll and Norbert Kübler and Felix Schrader},
  year = {2026},
  month = jul,
  doi = {10.21203/rs.3.rs-9932271/v1},
  url = {https://doi.org/10.21203/rs.3.rs-9932271/v1}
}