日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
VLAarXiv:2609.35002

見えなくなっても、そこにある:大規模視覚言語モデルにおける圧縮起因リスクの露呈

Still There, No Longer Seen: Exposing Compression-Induced Risk in Large Vision-Language Models

シェア:XThreadsFacebookLINEはてブBluesky

視覚トークン圧縮が引き起こす敵対的失敗を「圧縮特異的失敗」として定義し、それを誘発する攻撃手法CIRAを提案した研究。

詳しい要約

1. どんなもの?

本論文は、Large Vision-Language Models (LVLMs) における visual token compression が引き起こす新たな脆弱性を扱う。 - compression-specific failure (CSF) を「full-token inference では正しいが、compression 後に失敗する adversarial input」と定義。 - これは compression-induced risk を paired failure attribution problem として捉えるもの。 - 制御された diagnostic cohort 内で counterfactuals を用い、retained-set allocation が compressed correctness を因果的に変えることを示す。 - displaced evidence における recovery と representation drift の負の関連を明らかにする。 - これに基づき CIRA (Compression-Induced Risk…

2. 先行研究と比べてどこがすごい?

従来の aggregate robustness measures では、adversarial failure が compression 由来か元モデル由来かを区別できない。 - 本論文は CSF を定義し、full-token と compressed inference の paired evaluation で risk を帰属させる点が新しい。 - 既存研究と比べ、compression 特有の失敗を切り分けて評価する枠組みを提供。 - CIRA は downstream questions や labels を必要とせず、language model、deployed compressor、exact compression budget へのアクセスも不要。 - これにより restricted access 下でも compression-specific failures が持続することを示す。

3. 技術・手法の肝は?

CIRA は vision-encoder white-box 設定で動作する。 - encoder-side objectives を通じて image perturbations を最適化。 - 複数の candidate compression budgets にわたり token priorities を操作。 - 同時に displaced evidence を保持する。 - downstream questions や labels を使用せず、language model、deployed compressor、exact compression budget にアクセスしない。 - これにより compression 後のみ失敗する adversarial input を生成する。

4. どうやって有効だと検証した?

12 の dataset-compressor 設定、4 つの budgets で評価。 - CIRA は mean CSFR 20.35% を達成しつつ、full-token attack success を 6.92% に抑制。 - 追加の LVLM families でも同様の挙動を確認。 - cross-view selection-stabilization defense が CIRA を大幅に抑制するが、Adaptive CIRA が部分的に effectiveness を回復。 - これにより compression-specific failures が restricted access 下でも持続することを示す。

5. 議論はある?

compression-specific failures は restricted access 下でも持続することが示された。 - full-token と compressed inference の paired evaluation が visual-token compression への risk 帰属を支持する。 - cross-view selection-stabilization defense は有効だが、Adaptive CIRA により部分的に回避される。 - その他の議論や限界については要旨からは不明。

6. 次に読むべき論文は?

要旨で参照/比較されている研究は明示されていない。 - 関連手法として visual token compression、adversarial attack on LVLMs、paired failure attribution の研究が挙げられる。 - 同分野の定番として Large Vision-Language Models (LVLMs) の robustness 評価や visual token compression の研究を読むべき。 - 具体的な論文名は要旨からは不明。

※ AIが要旨から生成した要約です。正確性は原文をご確認ください。

著者: Qiankun Li, Yuechen Zhang, Bowen Chen, Shilinlu Yan, Zhenhong Zhou, Kun Wang, Li Sun

分類: cs.CV, cs.AI, cs.CR

原文アブストラクト

Visual token compression reduces the inference cost of Large Vision-Language Models (LVLMs). However, aggregate robustness measures do not reveal whether a particular adversarial failure is induced by compression or inherited from the underlying model. We define a compression-specific failure (CSF) as an adversarial input that remains correct under full-token inference but fails after compression, casting compression-induced risk as a paired failure attribution problem. Within a controlled diagnostic cohort, counterfactuals show that retained-set allocation causally changes compressed correctness and reveal a negative association between recovery and representation drift in displaced evidence. Motivated by these findings, we propose CIRA, a Compression-Induced Risk Attack for Large Vision-Language Models. Under a vision-encoder white-box setting, CIRA optimizes image perturbations through encoder-side objectives that manipulate token priorities across candidate compression budgets while preserving displaced evidence. CIRA uses no downstream questions or labels and requires no access to the language model, deployed compressor, or exact compression budget. Across 12 dataset-compressor settings evaluated at four budgets, CIRA achieves a mean CSFR of 20.35% while limiting full-token attack success to 6.92%, with similar behavior on additional LVLM families. A cross-view selection-stabilization defense substantially suppresses CIRA, although Adaptive CIRA partially restores its effectiveness. These results show that compression-specific failures persist under restricted access and support paired evaluation of full-token and compressed inference for attributing risk to visual-token compression.

関連論文

PR本紙発行元 EmplifAI